{
  "day": "2026-06-04",
  "boundary": "UTC calendar day",
  "published_count": 624,
  "by_severity": {
    "CRITICAL": 74,
    "HIGH": 263,
    "MEDIUM": 262,
    "LOW": 25
  },
  "kev_count": 0,
  "exploit_reference_count": 8,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-42824",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0764,
      "epss_percentile": 0.94076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Copilot",
      "cwe": "CWE-77",
      "title": "M365 Copilot Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42824"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2024-27890",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0443,
      "epss_percentile": 0.90599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-306",
      "title": "On affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected (No SSL Profiles Enabled).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-27890"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-10873",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.02695,
      "epss_percentile": 0.84704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shibby",
      "product": "Tomato",
      "cwe": "CWE-77",
      "title": "Shibby Tomato Web UI rstats rstats_path os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10873"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-10872",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.02635,
      "epss_percentile": 0.84335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shibby",
      "product": "Tomato",
      "cwe": "CWE-77",
      "title": "Shibby Tomato Web UI rc start_vpnserver os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10872"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-10870",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.02199,
      "epss_percentile": 0.81094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shibby",
      "product": "Tomato",
      "cwe": "CWE-77",
      "title": "Shibby Tomato Web UI rc start_dhcpc os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10870"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-10871",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.02199,
      "epss_percentile": 0.81094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shibby",
      "product": "Tomato",
      "cwe": "CWE-77",
      "title": "Shibby Tomato Web UI rc start_6rd_tunnel os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10871"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-48567",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01034,
      "epss_percentile": 0.61153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure HorizonDB",
      "cwe": "CWE-290",
      "title": "Azure HorizonDB Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48567"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2025-67447",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01026,
      "epss_percentile": 0.60886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command injection. The application does not properly sanitize user input in the IP address field before passing it to the system's ping command. An attacker can inject arbitrary OS commands, which will be executed with the privileges of the web server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67447"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-48579",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01015,
      "epss_percentile": 0.60531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Online",
      "cwe": "CWE-285",
      "title": "Microsoft Exchange Online Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48579"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-10973",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00985,
      "epss_percentile": 0.596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10973"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2019-25734",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00887,
      "epss_percentile": 0.56477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Web-Dorado",
      "product": "Contact Form Maker",
      "cwe": "CWE-22",
      "title": "Contact Form by WD 1.13.1 CSRF to Local File Inclusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25734"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-47655",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00756,
      "epss_percentile": 0.52307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Graph",
      "cwe": "CWE-200",
      "title": "Microsoft Graph Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47655"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-41283",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00733,
      "epss_percentile": 0.51536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Mistral",
      "cwe": "CWE-863",
      "title": "OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41283"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-47644",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00732,
      "epss_percentile": 0.51511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Copilot Chat (Microsoft Edge)",
      "cwe": "CWE-74",
      "title": "Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47644"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-25550",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00729,
      "epss_percentile": 0.5138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Seagull Software, LLC.",
      "product": "BarTender 2010",
      "cwe": "CWE-306",
      "title": "Seagull Software BarTender Unauthenticated RCE via .NET Remoting Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25550"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-50206",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0072,
      "epss_percentile": 0.5107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-78",
      "title": "VPN Command Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50206"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2019-25741",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00638,
      "epss_percentile": 0.47835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mobatek",
      "product": "Mobatek MobaXterm",
      "cwe": "CWE-120",
      "title": "Mobatek MobaXterm 12.1 Buffer Overflow via Sessions File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25741"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-48681",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00601,
      "epss_percentile": 0.4613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Ironic",
      "cwe": "CWE-23",
      "title": "OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted ISO image.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48681"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-7774",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00598,
      "epss_percentile": 0.46028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Software Foundation",
      "product": "CPython",
      "cwe": "CWE-22",
      "title": "tarfile.data_filter path traversal bypass allows writing outside the extraction directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7774"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-35904",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00547,
      "epss_percentile": 0.43511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 allows unauthorized attackers to enable the Telnet service via sending a crafted request to a vulnerable CGI component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35904"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-50076",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0052,
      "epss_percentile": 0.42016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Fory",
      "cwe": "CWE-502",
      "title": "Apache Fory: Java ReplaceResolverSerializer deserialization checks bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50076"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-10903",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00493,
      "epss_percentile": 0.40335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10903"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-10943",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00493,
      "epss_percentile": 0.40336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10943"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-10947",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00493,
      "epss_percentile": 0.40335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10947"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-10948",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00493,
      "epss_percentile": 0.40336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10948"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-10882",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00467,
      "epss_percentile": 0.387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10882"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-35906",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00466,
      "epss_percentile": 0.38599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated attackers to execute arbitrary system commands as root via supplying a crafted HTTP query string.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35906"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2025-69755",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00464,
      "epss_percentile": 0.38504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted command to the at_command.asp interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69755"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-10796",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00464,
      "epss_percentile": 0.38503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nvm-sh",
      "product": "nvm",
      "cwe": "CWE-78",
      "title": "nvm executes commands from a malicious Node.js mirror's version strings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10796"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2019-25727",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0046,
      "epss_percentile": 0.38273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ad-manager-wd",
      "product": "Ad Manager WD",
      "cwe": "CWE-22",
      "title": "WordPress Plugin ad manager wd 1.0.11 Arbitrary File Download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25727"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-10939",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00456,
      "epss_percentile": 0.38006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10939"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-10975",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00456,
      "epss_percentile": 0.38006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10975"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-10982",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00456,
      "epss_percentile": 0.38006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebXR in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10982"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-11003",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00456,
      "epss_percentile": 0.38006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11003"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2025-67446",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00454,
      "epss_percentile": 0.37864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-384",
      "title": "Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cookie value for authentication. By modifying the cookie value (e.g., setting it to \"admin\"), an attacker can bypass the authentication schema and gain unauthorized access to admin functionalities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67446"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-45497",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00452,
      "epss_percentile": 0.37735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Copilot",
      "cwe": "CWE-77",
      "title": "Microsoft M365 Copilot Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45497"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-10737",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0045,
      "epss_percentile": 0.37607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smartypants",
      "product": "SP Project & Document Manager",
      "cwe": "CWE-862",
      "title": "SP Project & Document Manager <= 4.71 - Missing Authorization to Unauthenticated Arbitrary File Information Disclosure via view_file() Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10737"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-10880",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00436,
      "epss_percentile": 0.36524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Osnexus",
      "product": "QuantaStor",
      "cwe": "CWE-89",
      "title": "Unauthenticated SQL Injection in Osnexus Quantastor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10880"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-41065",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00434,
      "epss_percentile": 0.36331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tautulli",
      "product": "Tautulli",
      "cwe": "CWE-1336",
      "title": "Tautulli Vulnerable to Unauthenticated/Authenticated Remote Code Execution via Newsletter Custom Template Directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41065"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-41249",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00433,
      "epss_percentile": 0.36265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coreshop",
      "product": "CoreShop",
      "cwe": "CWE-94",
      "title": "CoreShop Vulnerable to Remote Code Execution (RCE) via Insecure `pull_request_target` Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41249"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-50589",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00433,
      "epss_percentile": 0.36265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Ironic",
      "cwe": "CWE-770",
      "title": "In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50589"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-49190",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00426,
      "epss_percentile": 0.35702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-78",
      "title": "Missing Per-Instruction Authorization Checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49190"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-10910",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00425,
      "epss_percentile": 0.35636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10910"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-35905",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00421,
      "epss_percentile": 0.35335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-259",
      "title": "T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded password for root access under the \"superadmin\" account.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35905"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-10941",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00419,
      "epss_percentile": 0.35093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds memory access in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10941"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-47707",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00417,
      "epss_percentile": 0.34972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strawberry-graphql",
      "product": "strawberry",
      "cwe": "CWE-400",
      "title": "Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL Alias Amplification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47707"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-10904",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10904"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-10928",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-94",
      "title": "Script injection in Headless in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10928"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-8829",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00408,
      "epss_percentile": 0.3417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OALDERS",
      "product": "HTML::Entities",
      "cwe": "CWE-416",
      "title": "HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8829"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-10887",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chromoting in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10887"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-10935",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10935"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-10936",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10936"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-10962",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10962"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-10881",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0039,
      "epss_percentile": 0.32331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10881"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-10883",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0039,
      "epss_percentile": 0.32331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10883"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-10895",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0039,
      "epss_percentile": 0.32287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10895"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-10902",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0039,
      "epss_percentile": 0.32287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10902"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-10913",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0039,
      "epss_percentile": 0.32286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10913"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-10914",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0039,
      "epss_percentile": 0.32286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10914"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-10954",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0039,
      "epss_percentile": 0.32287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10954"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-10956",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0039,
      "epss_percentile": 0.32286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in MimeHandlerView in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10956"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-45431",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00388,
      "epss_percentile": 0.32131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GX INDIA",
      "product": "GX Earth 2022",
      "cwe": "CWE-78",
      "title": "Command Injection Vulnerability in GX Earth ONT Models",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45431"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-49185",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00387,
      "epss_percentile": 0.31999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-78",
      "title": "Instruction Injection via FieldX MDM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49185"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-11118",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00387,
      "epss_percentile": 0.32001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11118"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-11102",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-474",
      "title": "Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a malicious file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11102"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2025-8873",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-1286",
      "title": "Arista EOS Dataplane Denial of Service via Malformed IPsec Packet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-8873"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2025-71316",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00384,
      "epss_percentile": 0.31761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SQLite",
      "product": "sqldiff",
      "cwe": "CWE-176",
      "title": "SQLite sqldiff remote code execution via argument injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71316"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-10955",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00381,
      "epss_percentile": 0.31402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10955"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-10885",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00374,
      "epss_percentile": 0.30694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10885"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-10896",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00374,
      "epss_percentile": 0.30694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10896"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-10946",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00374,
      "epss_percentile": 0.30724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10946"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-3820",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.3023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SMCI",
      "product": "AS-2115HS-TNR",
      "cwe": "CWE-78",
      "title": "Supermicro BMC's SMTP service contains a command injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3820"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-40898",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00367,
      "epss_percentile": 0.29922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quic-go",
      "product": "quic-go",
      "cwe": "CWE-770",
      "title": "quic-go: HTTP/3 QPACK Trailer Expansion Memory Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40898"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-41236",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.2986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "froxlor",
      "product": "froxlor",
      "cwe": "CWE-59",
      "title": "Froxlor has privilege escalation in SSH key synchronization via symlinked `authorized_keys` path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41236"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-10957",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10957"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-10958",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10958"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-10959",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Input in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10959"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-10963",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10963"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-10964",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10964"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-10965",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10965"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-10987",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10987"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-10991",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10991"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-11000",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Fonts in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11000"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-11028",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Media in Google Chrome on Linux and ChromeOS prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11028"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-11046",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11046"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-10893",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.29199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10893"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-10945",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.29199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10945"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-11054",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.28721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11054"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-11068",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.2872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebSockets in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11068"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-11074",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.2872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebRTC in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11074"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-11147",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebML in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11147"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-10995",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10995"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-11024",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-121",
      "title": "Stack buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11024"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-10923",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebAppInstalls in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to execute arbitrary code via a malicious file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10923"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-10938",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0035,
      "epss_percentile": 0.28213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10938"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2019-25738",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00347,
      "epss_percentile": 0.27887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "framework-y",
      "product": "Hybrid Composer",
      "cwe": "CWE-306",
      "title": "WordPress Hybrid Composer 1.4.6 Unauthenticated Settings Change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25738"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-10886",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00345,
      "epss_percentile": 0.277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10886"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-45433",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GX INDIA",
      "product": "GX Earth 2022",
      "cwe": "CWE-321",
      "title": "Hardcoded Cryptographic Key Vulnerability in GX Earth ONT Models",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45433"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-10901",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Passwords in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10901"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-10976",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00336,
      "epss_percentile": 0.26597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10976"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-10977",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.26597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10977"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-10994",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.26597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10994"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-10978",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00333,
      "epss_percentile": 0.26305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10978"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-10986",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00333,
      "epss_percentile": 0.26305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a malicious file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10986"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-10993",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00333,
      "epss_percentile": 0.26292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10993"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-10898",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-121",
      "title": "Stack buffer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10898"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-49941",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RRWO",
      "product": "Net::CIDR::Set",
      "cwe": "CWE-674",
      "title": "Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49941"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-10843",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4",
      "cwe": "CWE-250",
      "title": "Cloud-credential-operator: cco mint-mode credentialsrequest manifests grant account-wide iam access beyond cluster scope on aws",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10843"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-10980",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10980"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-36499",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-770",
      "title": "A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB write access to request an excessive number of handler or revalidation threads. This can cause a denial of service (DoS) via resource exhaustion.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36499"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-10877",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Ship Ferry Ticket Reservation System",
      "cwe": "CWE-74",
      "title": "SourceCodester Ship Ferry Ticket Reservation System Admin Login login.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10877"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2025-46638",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "BSAFE SSL-J",
      "cwe": "CWE-770",
      "title": "Dell BSAFE SSL-J contains an allocation of resources without limits or throttling vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to a Denial of Service (DoS).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-46638"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2019-25740",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomsky",
      "product": "JS Jobs",
      "cwe": "CWE-22",
      "title": "Joomla com_jsjobs 1.2.6 Arbitrary File Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25740"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-10906",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.25548,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebAuthentication in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10906"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-10892",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00325,
      "epss_percentile": 0.25479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10892"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-10931",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00325,
      "epss_percentile": 0.25477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10931"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-10972",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00325,
      "epss_percentile": 0.25477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10972"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-10974",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00325,
      "epss_percentile": 0.2548,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10974"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-10983",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00325,
      "epss_percentile": 0.25478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10983"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-11009",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00325,
      "epss_percentile": 0.2548,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in USB in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11009"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-11021",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00325,
      "epss_percentile": 0.25476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11021"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-11065",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00325,
      "epss_percentile": 0.25477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11065"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-10891",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in GFX in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10891"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-10897",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Inappropriate implementation in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10897"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-10907",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10907"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-10988",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10988"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-10989",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10989"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-10971",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00324,
      "epss_percentile": 0.25344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10971"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-11322",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nesquena",
      "product": "Hermes WebUI",
      "cwe": "CWE-59",
      "title": "Hermes WebUI before 0.51.221 Path Traversal via Symlink Workspace Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11322"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-5066",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject-rtos",
      "product": "Zephyr",
      "cwe": "CWE-787",
      "title": "net: sockets: tls: Potential out-of-bounds write/read in socket_op_vtable::connect function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5066"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-49186",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-287",
      "title": "Lack of MQTT Broker Topic Access Control Lists",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49186"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-49188",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-489",
      "title": "Elevated Root Command Execution via ai_cmd Sockets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49188"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2023-5502",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-287",
      "title": "On affected platforms running Arista EOS with 802.1x authentication configured on the access/trunk ports, a malicious supplicant may bypass authentication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-5502"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-11088",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00316,
      "epss_percentile": 0.24445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11088"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-10930",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10930"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-11015",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in WebGPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11015"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-50292",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "freedesktop",
      "product": "libinput",
      "cwe": "CWE-93",
      "title": "In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50292"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-10951",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.24046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10951"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-10952",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.24046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10952"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-11076",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.2404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11076"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-49942",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.23956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RRWO",
      "product": "Net::CIDR::Set",
      "cwe": "CWE-1289",
      "title": "Net::CIDR::Set versions through 0.20 for Perl did not validate network masks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49942"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-10929",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in ANGLE in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10929"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-10949",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in Video in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10949"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-11011",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11011"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-10802",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0031,
      "epss_percentile": 0.23728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "keystonejs",
      "product": "keystone",
      "cwe": "CWE-400",
      "title": "keystonejs keystone GraphQL API Endpoint output-field.ts resource consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10802"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-49771",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10Web",
      "product": "Photo Gallery by 10Web",
      "cwe": "CWE-89",
      "title": "WordPress Photo Gallery by 10Web plugin <= 1.8.41 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49771"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-10968",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Dawn in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10968"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-10979",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10979"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-10985",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10985"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-10992",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient data validation in Animation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10992"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-11006",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11006"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-11007",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11007"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-11008",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11008"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-11013",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11013"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-11117",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00306,
      "epss_percentile": 0.23311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11117"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-10911",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10911"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-10917",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10917"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-10920",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebShare in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10920"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-10990",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00304,
      "epss_percentile": 0.23076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10990"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-11002",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00304,
      "epss_percentile": 0.23076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11002"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-10922",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass same origin policy via malicious network traffic. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10922"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-40605",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00303,
      "epss_percentile": 0.23033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tautulli",
      "product": "Tautulli",
      "cwe": "CWE-22",
      "title": "Tautulli Vulnerable to Authenticated Path Traversal in Cache Deletion API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40605"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-10874",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00303,
      "epss_percentile": 0.22981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "projectworlds",
      "product": "Online Art Gallery Shop Project",
      "cwe": "CWE-74",
      "title": "projectworlds Online Art Gallery Shop Project adminHome.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10874"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-10875",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00303,
      "epss_percentile": 0.22981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "projectworlds",
      "product": "Online Art Gallery Shop Project",
      "cwe": "CWE-74",
      "title": "projectworlds Online Art Gallery Shop Project adminHome.ph sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10875"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-4104",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00302,
      "epss_percentile": 0.22835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Akmer Informatics Automation Industry and Trade Ltd. Co.",
      "product": "TeknoPass",
      "cwe": "CWE-89",
      "title": "SQLi in Akmer Informatics' TeknoPass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4104"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2024-27892",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.2286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-306",
      "title": "On affected platforms running Arista EOS with OpenConfig configured, a gNMI Set request can be run when it should have been rejected (SSL Profiles Enabled).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-27892"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-11043",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00301,
      "epss_percentile": 0.2276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11043"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-11047",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00301,
      "epss_percentile": 0.22759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Base in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11047"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-10932",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.2276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in UI in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10932"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-11042",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.2276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11042"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-10966",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.003,
      "epss_percentile": 0.22669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10966"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-10944",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00296,
      "epss_percentile": 0.22194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10944"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-10950",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00296,
      "epss_percentile": 0.22194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10950"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-47706",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00296,
      "epss_percentile": 0.2221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strawberry-graphql",
      "product": "strawberry",
      "cwe": "CWE-400",
      "title": "Strawberry GraphQL has a Circular Fragment Reference DOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47706"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-49191",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00292,
      "epss_percentile": 0.21787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-287",
      "title": "Exposed Hard-coded M3WebServer Backend API Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49191"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-11279",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11279"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-10960",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10960"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-50211",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.2158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-134",
      "title": "Exposed Factory Testing App Boundaries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50211"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-50219",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libexpat project",
      "product": "libexpat",
      "cwe": "CWE-416",
      "title": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_ParserFree, or XML_ParserReset from within handlers in cases of a policy violation. Thus, a use-after-free can occur,",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50219"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-10999",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.21305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10999"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-10884",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10884"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-10889",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10889"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-10894",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Printing in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10894"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-10905",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10905"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-10908",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10908"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-10909",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10909"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-10918",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21195,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Viz in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10918"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-10919",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10919"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-10921",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10921"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-10924",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10924"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-10925",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in Skia in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10925"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-10927",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10927"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-10953",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Core in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10953"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-11010",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebShare in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11010"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-11012",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Serial in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11012"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-10899",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21195,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10899"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-10900",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21195,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Passwords in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10900"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-10970",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.21066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in InterestGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10970"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-10969",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.21066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10969"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-11027",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11027"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-11044",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in ANGLE in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11044"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-11045",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11045"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-10981",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00284,
      "epss_percentile": 0.20987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted video file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10981"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-44917",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00283,
      "epss_percentile": 0.20909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Ironic",
      "cwe": "CWE-669",
      "title": "OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pxe_template.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44917"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-11116",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11116"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2024-27891",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-284",
      "title": "On affected platforms running Arista EOS with MACsec and egress ACLs configured on the same interfaces, the ACL policies may not be enforced for packets egressing on those ports.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-27891"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-11049",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11049"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-11050",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11050"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-11055",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11055"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-11059",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11059"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-11060",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Media in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11060"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-11077",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Bad cast in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11077"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-11086",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20567,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11086"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-11125",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11125"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-11130",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20567,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11130"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-11136",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Canvas in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11136"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-11164",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11164"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-11171",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11171"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-11173",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20567,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11173"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-11211",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11211"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-11262",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in TabStrip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11262"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-10912",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10912"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-11016",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.2058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11016"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-11018",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11018"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-11022",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11022"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-11025",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.2058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Navigation in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11025"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-11037",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00278,
      "epss_percentile": 0.20323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11037"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-11030",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11030"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-38570",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20389,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-125",
      "title": "bacnet_stack 1.3.1 contains an Out-of-bounds Read in bacnet_tag_number_decode which allows attackers to cause a denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38570"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-11095",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00276,
      "epss_percentile": 0.2004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11095"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-11113",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00276,
      "epss_percentile": 0.2004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11113"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-11120",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00276,
      "epss_percentile": 0.20119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Enterprise Reporting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11120"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-10915",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.19949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Core in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10915"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-11004",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.19836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11004"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-11005",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.19837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11005"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-10937",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.1973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10937"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-10810",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.19739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Fees Management System",
      "cwe": "CWE-79",
      "title": "itsourcecode Fees Management System navbar.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10810"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-11191",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds memory access in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11191"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2019-25726",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nicheoffice",
      "product": "All in One Video Downloader",
      "cwe": "CWE-89",
      "title": "All in One Video Downloader 1.2 SQL Injection via admin page-edit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25726"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2019-25730",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themerig",
      "product": "Listing Hub CMS",
      "cwe": "CWE-89",
      "title": "Listing Hub CMS 1.0 SQL Injection via pages.php id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25730"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-41234",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "froxlor",
      "product": "froxlor",
      "cwe": "CWE-74",
      "title": "Froxlor: BIND Zone File Injection via TXT Record Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41234"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-11017",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Link Preview in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11017"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-10876",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0027,
      "epss_percentile": 0.1928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Ship Ferry Ticket Reservation System",
      "cwe": "CWE-266",
      "title": "SourceCodester Ship Ferry Ticket Reservation System admin improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10876"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-41237",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19195,
      "kev": false,
      "kev_due_at": null,
      "vendor": "froxlor",
      "product": "froxlor",
      "cwe": "CWE-74",
      "title": "Froxlor has an incomplete fix for CVE-2026-30932",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41237"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2025-59874",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL",
      "product": "Hive",
      "cwe": "CWE-1027",
      "title": "HCL Hive Telco Observability is affected by a Required directives missing from the CSP .",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59874"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-10933",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Audio in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10933"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-10934",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Autofill in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10934"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-10961",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10961"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-10967",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in SurfaceCapture in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10967"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-11153",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00264,
      "epss_percentile": 0.1845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in Forms in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11153"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-11242",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.1845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Plugins in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11242"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-11255",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.18489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Storage Access API in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11255"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-10586",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.18491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevteam",
      "product": "Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns",
      "cwe": "CWE-918",
      "title": "Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Authenticated (Author+) Server-Side Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10586"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-43986",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00262,
      "epss_percentile": 0.18155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tautulli",
      "product": "Tautulli",
      "cwe": "CWE-918",
      "title": "Tautulli vulnerable to unauthenticated SSRF in /image/<hash> via attacker-seeded image hash replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43986"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2019-25728",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "care2x",
      "product": "Care2x",
      "cwe": "CWE-89",
      "title": "Care2x 2.7 Hospital Information System SQL Injection via ck_config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25728"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2019-25732",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eitube",
      "product": "EI-Tube",
      "cwe": "CWE-89",
      "title": "PHP EI-Tube Script 3 SQL Injection via search parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25732"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2019-25745",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jgwhite33",
      "product": "Google Review Slider",
      "cwe": "CWE-89",
      "title": "WordPress Plugin Google Review Slider 6.1 SQL Injection via tid",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25745"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-46741",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SANBEG",
      "product": "Etsy::StatsD",
      "cwe": "CWE-93",
      "title": "Etsy::StatsD versions through 1.002002 for Perl allow metric injections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46741"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-10996",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.18183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Workers in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10996"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-11019",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.1813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-290",
      "title": "Inappropriate implementation in Payments in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11019"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-50266",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00262,
      "epss_percentile": 0.18211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Neutron",
      "cwe": "CWE-863",
      "title": "In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another project and set device_owner to a value that has \"network:\" at the beginning (\"network:dhcp\" for example). The default port RBAC policies incorrectly included PROJECT_MANAGER without requiring network ownership, allowing any project manager to obtain trusted network-service port behavior on shared networks. Depending on backend and deployment, this can bypass anti-spoofing and security group protections, enabling DHCP, MAC, or IP spoofing against other tenants on the shared network. This is a regression of CVE-2015-5240 (OSSA-2015-018).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50266"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-11144",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11144"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2019-25729",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00258,
      "epss_percentile": 0.17727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "simcy_creative",
      "product": "PDF Signer",
      "cwe": "CWE-352",
      "title": "PDF Signer 3.0 Server-Side Template Injection RCE via CSRF Cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25729"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-46739",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "COSIMO",
      "product": "Net::Statsd",
      "cwe": "CWE-93",
      "title": "Net::Statsd versions before 0.13 for Perl allow metric injections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46739"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-49202",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-287",
      "title": "Unverified Meeting Recording Endpoints & Permissive CORS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49202"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-11263",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in WebAuthentication in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11263"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-11052",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00255,
      "epss_percentile": 0.17333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in GPU in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11052"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-11100",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00255,
      "epss_percentile": 0.17322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in File Input in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11100"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-5589",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject-rtos",
      "product": "Zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write caused by an integer underflow in the Bluetooth Mesh subsystem.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5589"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-11061",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00253,
      "epss_percentile": 0.1701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11061"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-11066",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00253,
      "epss_percentile": 0.17009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11066"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-11033",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in WebML in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11033"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-11039",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11039"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-11057",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11057"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-11064",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Race in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11064"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-11067",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11067"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-11087",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11087"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-11089",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11089"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-11090",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11090"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-11101",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Dawn in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11101"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-11104",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11104"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-11109",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11109"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-11110",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11110"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-11123",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11123"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-11137",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11137"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-11138",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11138"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-11141",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Audio in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11141"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-11268",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11268"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-11085",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11085"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-11091",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Inappropriate implementation in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11091"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-11182",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11182"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-41522",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dfir-iris",
      "product": "iris-web",
      "cwe": "CWE-285",
      "title": "Iris has an Improper Authorization issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41522"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-5228",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kurt Software Studio",
      "product": "WriteUp Mobile App",
      "cwe": "CWE-284",
      "title": "Improper Access Control in Kurt Software Studio's WriteUp Mobile App",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5228"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-49187",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-200",
      "title": "Hard-coded APK Resource Credentials & Scepters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49187"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-49193",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-200",
      "title": "Publicly Readable AWS S3 Telemetry Buckets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49193"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-41858",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloud Foundry Foundation",
      "product": "windows-utilities-release",
      "cwe": "CWE-338",
      "title": "Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities-release allows a network attacker to estimate VM boot time and reconstruct a small candidate list to recover the Administrator password. The randomize_password job exists solely to lock the local Administrator account behind an unguessable password as a hardening control. Because the password is derived from a predictable, clock-seeded PRNG, a network attacker who can estimate VM boot time can reconstruct a small candidate list and recover the Administrator password, defeating the hardening control. Affected versions: - windows-utilities-release: all versions prior to v0.23.0 (inclusive); fixed in v0.23.0 or later",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41858"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-50210",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.16028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-200",
      "title": "Weak Static Cryptographic Initialization Vectors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50210"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-45432",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.1588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GX INDIA",
      "product": "GX Earth 2022",
      "cwe": "CWE-319",
      "title": "Cleartext Transmission of Credentials Vulnerability in GX Earth ONT Models",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45432"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-11224",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.15878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11224"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-10597",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ITPison",
      "product": "OMICARD EDM",
      "cwe": "CWE-639",
      "title": "ITPison｜OMICARD EDM - Insecure Direct Object Reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10597"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-11282",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00243,
      "epss_percentile": 0.15709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11282"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-50225",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-306",
      "title": "Account Creation Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50225"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-11096",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11096"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-11105",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11105"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-11230",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11230"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-11235",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11235"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-11248",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in Google Lens in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11248"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-10997",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-732",
      "title": "Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10997"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-11250",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00239,
      "epss_percentile": 0.15218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11250"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-10868",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00239,
      "epss_percentile": 0.15308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-269",
      "title": "MISP user edit endpoint mass assignment vulnerability allows unauthorized user account modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10868"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-50205",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-532",
      "title": "Plaintext Log Credential Leakage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50205"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-11170",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11170"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-11284",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.15029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in PerformanceAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11284"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-41178",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "go.opentelemetry.io/otel/baggage",
      "cwe": "CWE-789",
      "title": "OpenTelemetry-Go's baggage parsing no longer caps raw header length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41178"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-11303",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11303"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-11056",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.14601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in SiteIsolation in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11056"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-11063",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.14598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebNN in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11063"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-11082",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.14599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Race in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11082"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-11094",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.14559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11094"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-11114",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.14558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Device Trust in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11114"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-11119",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.1456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11119"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-11131",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.14559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Autofill in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11131"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-11146",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.14597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11146"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-11152",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Object lifecycle issue in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11152"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-11163",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.14601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11163"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-11165",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.14599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebMIDI in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11165"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-11167",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.14598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-250",
      "title": "Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11167"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-11041",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11041"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-11071",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Base in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11071"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-11080",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11080"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-11124",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Integer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11124"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-11172",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in Contact Picker in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11172"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-11175",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11175"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-11177",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11177"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-11188",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in USB in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11188"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-11202",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11202"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-11272",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Reading List in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11272"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-50224",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-200",
      "title": "Unauthenticated IPv6 WAN Management Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50224"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-11029",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00233,
      "epss_percentile": 0.1449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Drag and Drop in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11029"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-11287",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.14484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient policy enforcement in Navigation in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11287"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-10984",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.14471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Accessibility in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10984"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-11098",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.14416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11098"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-49194",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00232,
      "epss_percentile": 0.14328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-287",
      "title": "SCREEN_CLICK Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49194"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-50213",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-798",
      "title": "Bulk User Private Data Harvesting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50213"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-42539",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dfir-iris",
      "product": "iris-web",
      "cwe": "CWE-201",
      "title": "IRIS has an Excessive Data Exposure issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42539"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-11051",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in ANGLE in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11051"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-11073",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebGL in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11073"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-11075",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11075"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-11093",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Printing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11093"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-11097",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-474",
      "title": "Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11097"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-11121",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11121"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-11128",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Web Share in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11128"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-11140",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Out of bounds read in Chromecast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11140"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-11160",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Input in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11160"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-11168",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11168"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-11180",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11180"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-11203",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in GPU in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11203"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-11206",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11206"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-11208",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11208"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-11209",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11209"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-11271",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11271"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-11305",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11305"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-11307",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11307"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-10940",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in Codecs in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10940"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-11111",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11111"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-11196",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted XML file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11196"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-11179",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.1372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in ORB in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11179"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-41235",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "froxlor",
      "product": "froxlor",
      "cwe": "CWE-863",
      "title": "Froxlor has an authorization bypass in FTP shell assignment via missing server-side `available_shells` enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41235"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-11107",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11107"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-11108",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in NFC in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11108"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-11023",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in WebAppInstalls in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11023"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-10863",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-20",
      "title": "MISP User-controlled order parameter in correlations over-correlation endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10863"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-11306",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11306"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-10861",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-601",
      "title": "MISP post-login open redirect via pre_login_requested_url",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10861"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-11040",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11040"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-11149",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11149"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-11151",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11151"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-11239",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11239"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-11020",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.1295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted XML file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11020"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-11231",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.12589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-94",
      "title": "Inappropriate implementation in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a malicious file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11231"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-45739",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strawberry-graphql",
      "product": "strawberry",
      "cwe": "CWE-200",
      "title": "Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45739"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-8653",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StylemixThemes",
      "product": "MasterStudy LMS Pro",
      "cwe": "CWE-89",
      "title": "MasterStudy LMS Pro Plus <= 4.8.20 - Authenticated (Instructor+) SQL Injection via 'columns' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8653"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-11001",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-290",
      "title": "Inappropriate implementation in Payments in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11001"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-43926",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-204",
      "title": "FOSSBilling's password reset confirmation endpoint lacks rate limiting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43926"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-11070",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00216,
      "epss_percentile": 0.12347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the network process to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11070"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-11112",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00216,
      "epss_percentile": 0.12347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11112"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-11198",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00216,
      "epss_percentile": 0.12317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11198"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-11207",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00216,
      "epss_percentile": 0.12317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11207"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-11079",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00216,
      "epss_percentile": 0.12347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory write via a crafted video file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11079"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-11193",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11193"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2025-65640",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.1231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Cross Site Scripting (XSS) vulnerability in the \"Task in Progress / Recent\" page in Arket Globe Document Intelligence 5.0.0.559 due to improper sanitization of user input in text fields when creating a new document. Specifically, when an authenticated attacker submits data containing JavaScript code within these fields, the application fails to properly sanitize or escape the content. As a result, the injected script is executed when the page is rendered, allowing the attacker to execute arbitrary JavaScript in the context of other users' browsers who view the affected page.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-65640"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-11014",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11014"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-10916",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10916"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-11277",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.1186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11277"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-11256",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Integer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11256"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-11169",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-91",
      "title": "Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted XML file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11169"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-10840",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Builds 1.7.4",
      "cwe": "CWE-732",
      "title": "Openshift-pipelines-operator-rh: openshift-pipelines-operator: tekton-scheduler-rolebinding grants system:authenticated write access to kueue and cert-manager resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10840"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2019-25731",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zuz",
      "product": "Zuz Music",
      "cwe": "CWE-79",
      "title": "Zuz Music 2.1 Persistent Cross-site Scripting via zuzconsole Contact",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25731"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2019-25737",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Screets",
      "product": "Live Chat Unlimited",
      "cwe": "CWE-79",
      "title": "Live Chat Unlimited 2.8.3 Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25737"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-4881",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Octopus Deploy",
      "product": "Octopus Server",
      "cwe": "CWE-862",
      "title": "In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4881"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-11301",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.11376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Inappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via malicious network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11301"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-11069",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11069"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-10806",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mjperpinosa",
      "product": "stumasy",
      "cwe": "CWE-284",
      "title": "mjperpinosa stumasy add_post.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10806"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-10807",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mjperpinosa",
      "product": "stumasy",
      "cwe": "CWE-284",
      "title": "mjperpinosa stumasy change_profile_image.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10807"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-10815",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LakshayD02",
      "product": "Hostel-Management-System-PHP",
      "cwe": "CWE-862",
      "title": "LakshayD02 Hostel-Management-System-PHP Admin Dashboard index.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10815"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-43984",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.11097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tautulli",
      "product": "Tautulli",
      "cwe": "CWE-79",
      "title": "Tautulli has stored XSS in logFile via guest-controlled log_js_errors input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43984"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-11058",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.1118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in CredentialProvider in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform OS-level privilege escalation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11058"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-11154",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.11143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11154"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-11174",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in Site Isolation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11174"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-11244",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00207,
      "epss_percentile": 0.11185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebAuthentication in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11244"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-11201",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.10944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11201"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-11295",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.10989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11295"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-11166",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11166"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-11159",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11159"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-11265",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-352",
      "title": "Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11265"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-11031",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10562,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11031"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-11293",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00202,
      "epss_percentile": 0.10528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11293"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-11132",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11132"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-11133",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11133"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-40930",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pnggroup",
      "product": "libpng",
      "cwe": "CWE-436",
      "title": "LIBPNG: Chunk smuggling in push-mode APNG parser via unconsumed chunk body",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40930"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-11246",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.1045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in IndexedDB in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11246"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-11185",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.10418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11185"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-11078",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11078"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-11135",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11135"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-11142",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-639",
      "title": "Insufficient policy enforcement in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11142"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-11197",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in Workers in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11197"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-11204",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Signin in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11204"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-11258",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in File System Access in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11258"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-11275",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Page Info in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11275"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-41518",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.002,
      "epss_percentile": 0.1028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chartbrew",
      "product": "chartbrew",
      "cwe": "CWE-79",
      "title": "Chartbrew has a stored DOM XSS via Chart Tooltip innerHTML (ChartDatasetConfig.legend)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41518"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-11218",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in PlatformIntegration in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a malicious file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11218"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-11283",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Shortcuts in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11283"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-10808",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Fees Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Fees Management System manage_student.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10808"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-10809",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Fees Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Fees Management System manage_user.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10809"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-10811",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Fees Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Fees Management System receipt.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10811"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2025-52612",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL",
      "product": "iControl",
      "cwe": "CWE-1236",
      "title": "HCL iControl was affected by Export CSV - CSV Injection vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-52612"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-11299",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Integer overflow in Fonts in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11299"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-10860",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00197,
      "epss_percentile": 0.09808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-863",
      "title": "MISP CRUDComponent delete validation bypass via operator precedence error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10860"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-11288",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11288"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-11289",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11289"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2025-67448",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00196,
      "epss_percentile": 0.09665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "The SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. The application does not properly sanitize user input in SMS messages before storing and displaying them. An attacker can send an SMS containing a malicious XSS payload, which will be executed in the context of the victim's browser when the message is viewed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67448"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-49940",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RRWO",
      "product": "Net::CIDR::Set",
      "cwe": "CWE-1289",
      "title": "Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49940"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-11213",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00195,
      "epss_percentile": 0.0957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Reading Mode in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11213"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-11237",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.09456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11237"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-41207",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty-incubator-codec-ohttp",
      "cwe": "CWE-330",
      "title": "netty-incubator-codec-ohttp's HPKEContext operations may produce empty byte[] on failures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41207"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-11038",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient policy enforcement in Subresource Integrity in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11038"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-49077",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tips and Tricks HQ",
      "product": "WP eMember",
      "cwe": "CWE-497",
      "title": "WordPress WP eMember plugin <= v10.2.2 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49077"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-36175",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-20",
      "title": "An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and gain root access via interrupting the boot sequence and injecting a crafted string into the kernel boot arguments.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36175"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-36182",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0019,
      "epss_percentile": 0.09018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-328",
      "title": "GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing attackers to obtain root credentials and privileges via a bruteforce attack.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36182"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-11195",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.09053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in MHTML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11195"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-11199",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in WebRTC in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged network position to leak cross-origin data via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11199"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-11257",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.0887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Browser in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11257"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-10888",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00187,
      "epss_percentile": 0.08678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Cast Streaming in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10888"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-10926",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00187,
      "epss_percentile": 0.08678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to execute arbitrary code via malicious network traffic. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10926"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-11304",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00187,
      "epss_percentile": 0.08609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11304"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-50226",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.0867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-321",
      "title": "Firmware Theft & IMEI Spoofing via Connect-OTA",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50226"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-11106",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-352",
      "title": "Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11106"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-11270",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-352",
      "title": "Inappropriate implementation in UI in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11270"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-11162",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11162"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-11249",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11249"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-11292",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11292"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-11240",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00186,
      "epss_percentile": 0.0852,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Loader in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11240"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-11251",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00186,
      "epss_percentile": 0.08545,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11251"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-11210",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Safe Browsing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted RAR file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11210"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-10890",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00183,
      "epss_percentile": 0.08205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10890"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-11194",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11194"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-11280",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Signin in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11280"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-11285",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11285"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-42540",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dfir-iris",
      "product": "iris-web",
      "cwe": "CWE-915",
      "title": "IRIS has a Mass Assignment issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42540"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-11034",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Tab Group Sync in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11034"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-11259",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11259"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-11260",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.0808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11260"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-11264",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Policy bypass in Content Security Policy in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11264"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-11236",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.08042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11236"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-11092",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00179,
      "epss_percentile": 0.07713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11092"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-11302",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.0779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11302"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-11233",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient policy enforcement in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11233"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-11234",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.0759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11234"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-11247",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00177,
      "epss_percentile": 0.07591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in CustomTabs in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11247"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-11032",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11032"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-11083",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11083"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-11084",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11084"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-11129",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-352",
      "title": "Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11129"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-11134",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-352",
      "title": "Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11134"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-11139",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-352",
      "title": "Inappropriate implementation in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11139"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-11176",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11176"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-11200",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11200"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-11220",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.0744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11220"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-11223",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11223"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-10854",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-200",
      "title": "Unauthorized exposure of private galaxies in MISP event template creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10854"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-10864",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-200",
      "title": "MISP Dashboard widget field selection may expose restricted user and organisation data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10864"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-11192",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11192"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-11245",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Payments in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11245"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-11254",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07464,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11254"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-11261",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07464,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11261"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-11296",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in ImageCapture in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11296"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-11143",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Out of bounds read in Extensions in Google Chrome on Linux prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11143"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-42538",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dfir-iris",
      "product": "iris-web",
      "cwe": "CWE-434",
      "title": "IRIS has an Insecure File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42538"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-11252",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.0735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in Content Settings in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11252"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-11274",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.0735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in DOM Distiller in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11274"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-48040",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty-incubator-codec-ohttp",
      "cwe": "CWE-125",
      "title": "netty-incubator-codec-ohttp's Incorrect Native Pointer Derivation in Pooled Direct ByteBuf Fallback Leads to Out-of-Bounds Native Memory Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48040"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-42547",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dfir-iris",
      "product": "iris-web",
      "cwe": "CWE-863",
      "title": "IRIS Alerts Can be Falsely Attributed to Customers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42547"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-42329",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dfir-iris",
      "product": "iris-web",
      "cwe": "CWE-602",
      "title": "Iris has an Open Redirect issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42329"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-42543",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dfir-iris",
      "product": "iris-web",
      "cwe": "CWE-650",
      "title": "IRIS has a Cross-Site Request Forgery (CSRF) issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42543"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-44393",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-297",
      "title": "An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not perform TLS hostname verification when connecting to the message broker. When ssl_ca_file is configured, the driver enables certificate chain validation but does not pass the expected broker hostname into the underlying TLS stack. Any certificate signed by the deployment CA is accepted regardless of hostname, allowing an attacker who can intercept control-plane traffic to impersonate the RabbitMQ broker and perform a man-in-the-middle attack on RPC and notification traffic. All OpenStack services using oslo.messaging with RabbitMQ over TLS are affected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44393"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-11189",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11189"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-11222",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in Tab Strip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11222"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2019-25739",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gigtodoscript",
      "product": "GigToDo",
      "cwe": "CWE-79",
      "title": "GigToDo Freelance Marketplace Script 1.3 Persistent XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25739"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2019-25742",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fruitfulcode",
      "product": "Zoner Real Estate",
      "cwe": "CWE-79",
      "title": "WordPress Theme Zoner Real Estate 4.1.1 Persistent XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25742"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2019-25743",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.0687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Soliloquywp",
      "product": "Soliloquy Lite",
      "cwe": "CWE-79",
      "title": "WordPress Soliloquy Lite 2.5.6 Persistent Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25743"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2019-25744",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.0687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Popup-Builder",
      "product": "Popup Builder",
      "cwe": "CWE-79",
      "title": "WordPress Popup Builder 3.49 Persistent Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25744"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-11238",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-306",
      "title": "Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11238"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-11183",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.0672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in GWP-ASan in Google Chrome prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11183"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2025-52606",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL",
      "product": "iControl",
      "cwe": "CWE-209",
      "title": "HCL iControl was affected by Weak Input Validation vulnerability. .",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-52606"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-49203",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00168,
      "epss_percentile": 0.06558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-287",
      "title": "Unauthenticated eSIM Configuration Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49203"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-11127",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-358",
      "title": "Inappropriate implementation in WebAPKs in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted WebAPK. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11127"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-11266",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in SafeBrowsing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass Safe Browsing via a malicious file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11266"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-45287",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00168,
      "epss_percentile": 0.06517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "go.opentelemetry.io/otel/schema/v1.1",
      "cwe": "CWE-772",
      "title": "OpenTelemetry-Go's Schema ParseFile leaks file descriptors on each parse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45287"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-50214",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00167,
      "epss_percentile": 0.06479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-345",
      "title": "Shared Secret Quota Inflation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50214"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-48480",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty-incubator-codec-ohttp",
      "cwe": "CWE-325",
      "title": "netty-incubator-codec-ohttp OHttpVersionChunkDraft's Missing Final-Chunk Enforcement Leads to Undetected Stream Truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48480"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-11026",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11026"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-50212",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.0619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-400",
      "title": "Arbitrary Remote Device Unbinding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50212"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-11036",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in DOM in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11036"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-11081",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Canvas in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11081"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-11190",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11190"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-11145",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in Geolocation in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11145"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-11216",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11216"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-11214",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11214"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2025-52609",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL",
      "product": "iControl",
      "cwe": "CWE-693",
      "title": "HCL iControl was affected by Missing Security Headers vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-52609"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-49204",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-798",
      "title": "Hard-coded AWS Cognito Testing Accounts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49204"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-11122",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-358",
      "title": "Inappropriate implementation in Keyboard in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11122"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-11150",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11150"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-11186",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11186"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-11273",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05567,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11273"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-11291",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Android Autofill in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11291"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-11298",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11298"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-11048",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11048"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-11215",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Cronet in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11215"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-11225",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11225"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-11227",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in Tab Hover Cards in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11227"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-11184",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11184"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2025-52611",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL",
      "product": "iControl",
      "cwe": "CWE-209",
      "title": "HCL iControl was affected by Unhandled Exception - Stack Trace Disclosure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-52611"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-10855",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-862",
      "title": "MISP Event template importer authorization bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10855"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-11219",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11219"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-11228",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11228"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-11286",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Wallet in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11286"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-11294",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11294"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-11300",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11300"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-10805",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Multicluster Engine for Kubernetes",
      "cwe": "CWE-78",
      "title": "Networkmanager: networkmanager: local privilege escalation via malformed mud urls in dhclient backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10805"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-11187",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11187"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-11155",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-352",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11155"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-11156",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.0488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-352",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11156"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-11161",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in DataTransfer in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11161"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-11178",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11178"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-11226",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.0477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in PreviewTab in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11226"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-11217",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.04757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Fenced Frames in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11217"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-11243",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Downloads in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11243"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2026-11221",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.0464,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in PointerLock in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11221"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-11253",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11253"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2019-25733",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nsauditor",
      "product": "NetShareWatcher",
      "cwe": "CWE-120",
      "title": "NetShareWatcher 1.5.8.0 SEH Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25733"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2019-25735",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Allplayer",
      "product": "AllPlayer",
      "cwe": "CWE-120",
      "title": "AllPlayer 7.4 Local Buffer Overflow via SEH Unicode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25735"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-10856",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-601",
      "title": "Open redirect in MISP dashboard button widget URL handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10856"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-11205",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted QR code. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11205"
    },
    {
      "rank": 564,
      "cve_id": "CVE-2026-43985",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tautulli",
      "product": "Tautulli",
      "cwe": "CWE-352",
      "title": "Taultulli has CSRF in /configUpdate via missing anti-CSRF and method restriction that allows admin credential takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43985"
    },
    {
      "rank": 565,
      "cve_id": "CVE-2019-25736",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Labf",
      "product": "LabF nfsAxe",
      "cwe": "CWE-120",
      "title": "LabF nfsAxe 3.7 Ping Client Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25736"
    },
    {
      "rank": 566,
      "cve_id": "CVE-2026-11232",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11232"
    },
    {
      "rank": 567,
      "cve_id": "CVE-2026-36178",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-212",
      "title": "The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configuration partition, possibly allowing attackers to recover and obtain sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36178"
    },
    {
      "rank": 568,
      "cve_id": "CVE-2024-6858",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-1287",
      "title": "In Arista’s EOS when in 802.1X mode, multi-auth unauthenticated hosts might be allowed access to a switch port if there exists an EAPOL capable device in the fallback VLAN.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-6858"
    },
    {
      "rank": 569,
      "cve_id": "CVE-2026-11278",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.0404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in CustomTabs in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11278"
    },
    {
      "rank": 570,
      "cve_id": "CVE-2026-11126",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.04021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11126"
    },
    {
      "rank": 571,
      "cve_id": "CVE-2026-50208",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00141,
      "epss_percentile": 0.03964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-330",
      "title": "Permissive TrustAllCerts TLS Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50208"
    },
    {
      "rank": 572,
      "cve_id": "CVE-2026-36174",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-256",
      "title": "GNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext during routine operations to the serial console. This issue allows physically-proximate attackers to obtain sensitive information, including network credentials, via monitoring the serial UART interface.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36174"
    },
    {
      "rank": 573,
      "cve_id": "CVE-2026-11267",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11267"
    },
    {
      "rank": 574,
      "cve_id": "CVE-2026-49192",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-639",
      "title": "Summary Service Insecure Direct Object Reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49192"
    },
    {
      "rank": 575,
      "cve_id": "CVE-2026-11148",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-352",
      "title": "Inappropriate implementation in Payments in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11148"
    },
    {
      "rank": 576,
      "cve_id": "CVE-2026-11181",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Media Session in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11181"
    },
    {
      "rank": 577,
      "cve_id": "CVE-2026-11212",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11212"
    },
    {
      "rank": 578,
      "cve_id": "CVE-2026-36180",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "A lack of runtime integrity in GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass file system read-only protections and modify system files and binaries for the duration of a boot session via a bind-mount attack.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36180"
    },
    {
      "rank": 579,
      "cve_id": "CVE-2026-11062",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11062"
    },
    {
      "rank": 580,
      "cve_id": "CVE-2026-50207",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.03318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-22",
      "title": "Local Modem Manipulation via Binder Interfaces",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50207"
    },
    {
      "rank": 581,
      "cve_id": "CVE-2026-11309",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in History in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11309"
    },
    {
      "rank": 582,
      "cve_id": "CVE-2026-25551",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.03094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Seagull Software, LLC.",
      "product": "BarTender 2021",
      "cwe": "CWE-502",
      "title": "Seagull Software BarTender Deserialization Privilege Escalation via .NET Remoting Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25551"
    },
    {
      "rank": 583,
      "cve_id": "CVE-2026-7764",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Morse Micro",
      "product": "HaLowLink 2",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in morse.ko Vendor IE processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7764"
    },
    {
      "rank": 584,
      "cve_id": "CVE-2026-10942",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in UI in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10942"
    },
    {
      "rank": 585,
      "cve_id": "CVE-2026-41010",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloud Foundry Foundation",
      "product": "BOSH Director",
      "cwe": "CWE-78",
      "title": "ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', \"#{name}.tgz\") where name returns @job_meta['name'], a value taken verbatim from the jobs: array of the attacker-supplied release.MF inside the uploaded tarball. These paths are then interpolated into a shell string: Bosh::Common::Exec.sh(\"tar -C #{job_dir} -xf #{job_tgz} 2>&1\", :on_error => :return). Bosh::Common::Exec.sh executes via %x{#{command}} (bosh-common/lib/bosh/common/exec.rb:53), i.e. /bin/sh -c, so any shell metacharacters in name are interpreted. FileUtils.mkdir_p(job_dir) on line 49 creates the literal directory (no shell) and succeeds even when the name contains $()/;, so execution reaches the sh call. Affected versions: - BOSH Director: all versions prior to v282.1.12 (inclusive); fixed in v282.1.12 or later",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41010"
    },
    {
      "rank": 586,
      "cve_id": "CVE-2026-21404",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NAVTOR",
      "product": "NavBox",
      "cwe": "CWE-798",
      "title": "NAVTOR NavBox Use of Hard-coded Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21404"
    },
    {
      "rank": 587,
      "cve_id": "CVE-2026-11157",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-94",
      "title": "Script injection in Accessibility in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11157"
    },
    {
      "rank": 588,
      "cve_id": "CVE-2026-41011",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloud Foundry Foundation",
      "product": "BOSH",
      "cwe": "CWE-78",
      "title": "PackagePersister.validate_tgz builds \"tar -tf #{tgz} 2>&1\" where tgz = File.join(release_dir, 'packages', \"#{name}.tgz\") and name = package_meta['name'] comes directly from release.MF inside the uploaded tarball. The string is passed to Bosh::Common::Exec.sh, which executes via %x{} — i.e., /bin/sh -c. No Shellwords.escape is applied. The Models::Package Sequel validation (VALID_ID = /^[-0-9A-Za-z_+.]+$/i) would reject the name, but in create_package (lines 74–79) the shell-out in save_package_source_blob runs before package.save, so validation fires too late. Affected versions: - BOSH: all versions prior to v282.1.12 (inclusive); fixed in v282.1.12 or later",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41011"
    },
    {
      "rank": 589,
      "cve_id": "CVE-2026-11241",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11241"
    },
    {
      "rank": 590,
      "cve_id": "CVE-2026-11072",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.01285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to execute arbitrary code via a malicious file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11072"
    },
    {
      "rank": 591,
      "cve_id": "CVE-2026-10998",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Media in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform an out of bounds memory read via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10998"
    },
    {
      "rank": 592,
      "cve_id": "CVE-2026-47318",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.0121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "rlottie",
      "cwe": "CWE-121",
      "title": "Stack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before ce72b35a7ad0dded03051d3aa0ef75321c3bd035.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47318"
    },
    {
      "rank": 593,
      "cve_id": "CVE-2025-12694",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00104,
      "epss_percentile": 0.01183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Forcepoint",
      "product": "VPN Client",
      "cwe": "CWE-250",
      "title": "Local Privilege Escalation in VPN Client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12694"
    },
    {
      "rank": 594,
      "cve_id": "CVE-2026-47320",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.01148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "rlottie",
      "cwe": "CWE-674",
      "title": "Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Manipulation, Oversized Serialized Data Payloads. This issue affects rlottie: before eae37633fda13ac05b25c6c95aacea4bc33c80a3.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47320"
    },
    {
      "rank": 595,
      "cve_id": "CVE-2026-49510",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.01148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "rlottie",
      "cwe": "CWE-190",
      "title": "Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects rlottie: before 21292665023e5074b38254432716866d00f1985f.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49510"
    },
    {
      "rank": 596,
      "cve_id": "CVE-2026-8916",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "rlottie",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: before dcfde72eae1b0464dc0dd760aec00ada6a148635.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8916"
    },
    {
      "rank": 597,
      "cve_id": "CVE-2026-10305",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "rlottie",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: before 223a2a41ba4f462e4abe767bebba49a366c9b9fd.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10305"
    },
    {
      "rank": 598,
      "cve_id": "CVE-2026-47306",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "rlottie",
      "cwe": "CWE-674",
      "title": "Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This issue affects rlottie: before e2d19e3b150e0e4a9586fa90b56fd3061cc98945.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47306"
    },
    {
      "rank": 599,
      "cve_id": "CVE-2026-47319",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "rlottie",
      "cwe": "CWE-789",
      "title": "Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. This issue affects rlottie: before 0b4e308fa88c72cbb60cc8a2c1d2c2ad89b101dd.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47319"
    },
    {
      "rank": 600,
      "cve_id": "CVE-2026-10803",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00103,
      "epss_percentile": 0.01122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "MLflow",
      "cwe": "CWE-327",
      "title": "MLflow Dataset Digest Computation digest_utils.py mlflow.data.digest_utils weak hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10803"
    },
    {
      "rank": 601,
      "cve_id": "CVE-2026-11269",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00102,
      "epss_percentile": 0.0109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-829",
      "title": "Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged network position to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11269"
    },
    {
      "rank": 602,
      "cve_id": "CVE-2025-62338",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.001,
      "epss_percentile": 0.00974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "BigFix Cloud Lifecycle Management",
      "cwe": null,
      "title": "HCL BigFix Cloud Lifecycle Management is affected by lack of input validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62338"
    },
    {
      "rank": 603,
      "cve_id": "CVE-2026-11308",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00099,
      "epss_percentile": 0.00941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11308"
    },
    {
      "rank": 604,
      "cve_id": "CVE-2026-50209",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00098,
      "epss_percentile": 0.00887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-732",
      "title": "MDM Server Registration Overriding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50209"
    },
    {
      "rank": 605,
      "cve_id": "CVE-2026-49189",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00098,
      "epss_percentile": 0.00887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Acer",
      "product": "Connect M6E 5G Portable WiFi Router",
      "cwe": "CWE-269",
      "title": "Broadcast Receiver Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49189"
    },
    {
      "rank": 606,
      "cve_id": "CVE-2026-41859",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00098,
      "epss_percentile": 0.00887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloud Foundry Foundation",
      "product": "BOSH",
      "cwe": "CWE-295",
      "title": "A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and can tamper with the VM list that is written into the NATS authorization file. Stolen credentials grant administrative director access. UsersSync#bosh_api_response_body builds a Net::HTTP client with verify_mode = OpenSSL::SSL::VERIFY_NONE for every director call (/info, /deployments, /deployments/<name>/vms). Affected versions: - BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41859"
    },
    {
      "rank": 607,
      "cve_id": "CVE-2025-52608",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00098,
      "epss_percentile": 0.00889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL",
      "product": "iControl",
      "cwe": "CWE-614",
      "title": "HCL iControl was affected by Missing Cookie Attributes vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-52608"
    },
    {
      "rank": 608,
      "cve_id": "CVE-2026-11229",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via physical access to the device. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11229"
    },
    {
      "rank": 609,
      "cve_id": "CVE-2026-36176",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00093,
      "epss_percentile": 0.00628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-312",
      "title": "GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows physically-proximate attackers to extract these active tokens to perform unauthorized operations via monitoring the serial UART interface.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36176"
    },
    {
      "rank": 610,
      "cve_id": "CVE-2026-11297",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00091,
      "epss_percentile": 0.00554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Reader Mode in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11297"
    },
    {
      "rank": 611,
      "cve_id": "CVE-2026-10814",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00089,
      "epss_percentile": 0.00494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "milvus-io",
      "product": "milvus",
      "cwe": "CWE-327",
      "title": "milvus-io milvus Grantee ID Hash kv_catalog.go weak hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10814"
    },
    {
      "rank": 612,
      "cve_id": "CVE-2026-11281",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00085,
      "epss_percentile": 0.00364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in Chromoting in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted ETW event. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11281"
    },
    {
      "rank": 613,
      "cve_id": "CVE-2026-11158",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00083,
      "epss_percentile": 0.00289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Downloads in Google Chrome on Mac prior to 149.0.7827.53 allowed a local attacker to potentially perform a sandbox escape via a crafted AppleScript command. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11158"
    },
    {
      "rank": 614,
      "cve_id": "CVE-2026-10804",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00083,
      "epss_percentile": 0.00302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Streamlit",
      "cwe": "CWE-327",
      "title": "Streamlit Palette hashing.py weak hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10804"
    },
    {
      "rank": 615,
      "cve_id": "CVE-2026-11103",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0008,
      "epss_percentile": 0.00203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in Installer in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11103"
    },
    {
      "rank": 616,
      "cve_id": "CVE-2026-11276",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0008,
      "epss_percentile": 0.00209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to bypass discretionary access control via malicious network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11276"
    },
    {
      "rank": 617,
      "cve_id": "CVE-2026-11035",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00079,
      "epss_percentile": 0.00168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via a crafted XML file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11035"
    },
    {
      "rank": 618,
      "cve_id": "CVE-2026-11115",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00079,
      "epss_percentile": 0.00168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Updater in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11115"
    },
    {
      "rank": 619,
      "cve_id": "CVE-2026-10800",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00075,
      "epss_percentile": 0.00108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PaddlePaddle",
      "product": "FastDeploy",
      "cwe": "CWE-327",
      "title": "PaddlePaddle FastDeploy MultimodalHasher hasher.py hash_features weak hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10800"
    },
    {
      "rank": 620,
      "cve_id": "CVE-2026-10801",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00075,
      "epss_percentile": 0.00107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "modelscope",
      "product": "ms-swift",
      "cwe": "CWE-327",
      "title": "modelscope ms-swift PIL Image Cache Key base.py Template._save_pil_image weak hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10801"
    },
    {
      "rank": 621,
      "cve_id": "CVE-2026-10812",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00075,
      "epss_percentile": 0.00107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zilliztech",
      "product": "GPTCache",
      "cwe": "CWE-327",
      "title": "zilliztech GPTCache Cache Key pre.py BufferedReader.peek weak hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10812"
    },
    {
      "rank": 622,
      "cve_id": "CVE-2026-10813",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00075,
      "epss_percentile": 0.00107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "LMCache",
      "cwe": "CWE-327",
      "title": "LMCache KV Cache utils.py hex_hash_to_int16 weak hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10813"
    },
    {
      "rank": 623,
      "cve_id": "CVE-2026-41860",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00074,
      "epss_percentile": 0.00084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloud Foundry Foundation",
      "product": "BOSH",
      "cwe": "CWE-326",
      "title": "CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an attacker to intercept traffic between bosh-monitor and the BOSH director or UAA and steal credentials. Affected versions: - BOSH: all versions prior to v282.1.9 (inclusive); fixed in v282.1.9 or later",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41860"
    },
    {
      "rank": 624,
      "cve_id": "CVE-2026-11290",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00066,
      "epss_percentile": 0.00022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to cause a denial of service via a malicious file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11290"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10796",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10796 (nvm-sh nvm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-11216",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-11216 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45287",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45287 (open-telemetry go.opentelemetry.io/otel/schema/v1.1). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47706",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47706 (strawberry-graphql strawberry). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47707",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47707 (strawberry-graphql strawberry). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-5066",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-5066 (zephyrproject-rtos Zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-5589",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-5589 (zephyrproject-rtos Zephyr). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2008-4250",
      "detail": "DUE DATE PASSED — CVE-2008-4250 (Microsoft Windows). CISA remediation deadline was June 3, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2009-1537",
      "detail": "DUE DATE PASSED — CVE-2009-1537 (Microsoft DirectX). CISA remediation deadline was June 3, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2009-3459",
      "detail": "DUE DATE PASSED — CVE-2009-3459 (Adobe Acrobat and Reader). CISA remediation deadline was June 3, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2010-0249",
      "detail": "DUE DATE PASSED — CVE-2010-0249 (Microsoft Internet Explorer). CISA remediation deadline was June 3, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2010-0806",
      "detail": "DUE DATE PASSED — CVE-2010-0806 (Microsoft Internet Explorer). CISA remediation deadline was June 3, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-41091",
      "detail": "DUE DATE PASSED — CVE-2026-41091 (Microsoft Malware Protection Engine). CISA remediation deadline was June 3, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-45498",
      "detail": "DUE DATE PASSED — CVE-2026-45498 (Microsoft Defender Antimalware Platform). CISA remediation deadline was June 3, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
