{
  "day": "2026-06-05",
  "boundary": "UTC calendar day",
  "published_count": 167,
  "by_severity": {
    "CRITICAL": 28,
    "HIGH": 65,
    "MEDIUM": 61,
    "LOW": 13
  },
  "kev_count": 1,
  "exploit_reference_count": 18,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-28318",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.08351,
      "epss_percentile": 0.94495,
      "kev": true,
      "kev_due_at": "2026-06-19",
      "vendor": "SolarWinds",
      "product": "Serv-U",
      "cwe": "CWE-400",
      "title": "SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28318"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-25620",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0988,
      "epss_percentile": 0.95178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)",
      "cwe": "CWE-78",
      "title": "Arista Edge Threat Management NGFW Captive Portal Encrypted Password Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25620"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-25622",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0988,
      "epss_percentile": 0.95179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)",
      "cwe": "CWE-78",
      "title": "Arista Edge Threat Management NGFW Captive Portal Custom Handler Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25622"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-25623",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.05951,
      "epss_percentile": 0.92677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)",
      "cwe": "CWE-78",
      "title": "Arista Edge Threat Management NGFW UI Arbitrary Command Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25623"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-10878",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.04236,
      "epss_percentile": 0.90223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DWR-M920",
      "cwe": "CWE-74",
      "title": "D-Link DWR-M920 formSmsManage sub_41C8E8 command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10878"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-11339",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.03133,
      "epss_percentile": 0.86831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DWR-M920",
      "cwe": "CWE-74",
      "title": "D-Link DWR-M920 formUSSDSetup sub_41CF20 command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11339"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-10580",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02948,
      "epss_percentile": 0.86052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hippooo",
      "product": "Hippoo Mobile App for WooCommerce",
      "cwe": "CWE-285",
      "title": "Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10580"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-9290",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.02502,
      "epss_percentile": 0.8343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpusermanager",
      "product": "WP User Manager – User Profile Builder & Membership",
      "cwe": "CWE-22",
      "title": "WP User Manager <= 2.9.17 - Unauthenticated Path Traversal to Local File Inclusion via 'tab' Query Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9290"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-45744",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02008,
      "epss_percentile": 0.79265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-78",
      "title": "Termix has an OS Command Injection in File Manager resolvePath endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45744"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-45748",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01729,
      "epss_percentile": 0.75739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-78",
      "title": "Termix Vulnerable to Remote Code Execution via SSH Tunnel Forward Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45748"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-49777",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01656,
      "epss_percentile": 0.74684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ShapedPlugin, LLC",
      "product": "Product Slider Pro for WooCommerce",
      "cwe": "CWE-1284",
      "title": "WordPress Product Slider Pro for WooCommerce plugin < 3.5.4 - Backdoor vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49777"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-11429",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01145,
      "epss_percentile": 0.6418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Altium",
      "product": "Altium Enterprise Server",
      "cwe": "CWE-22",
      "title": "Path Traversal in Altium Vault ScriptsController Allows Unauthenticated Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11429"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-48095",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01116,
      "epss_percentile": 0.63465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcmilk",
      "product": "7-Zip",
      "cwe": "CWE-190",
      "title": "GHSL-2026-140_7-Zip: 7-Zip has a heap buffer overflow via NTFS compressed stream buffer under-allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48095"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-11341",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01044,
      "epss_percentile": 0.61413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DWR-M920",
      "cwe": "CWE-77",
      "title": "D-Link DWR-M920 formIMEISetup sub_412DA0 os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11341"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-21837",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0092,
      "epss_percentile": 0.57502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Digital Experience",
      "cwe": "CWE-78",
      "title": "HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21837"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-7654",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00905,
      "epss_percentile": 0.57028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codepress",
      "product": "Admin Columns",
      "cwe": "CWE-502",
      "title": "Admin Columns <= 7.0.18 - Authenticated (Contributor+) PHP Object Injection to Remote Code Execution via Custom Field Meta Value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7654"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-46394",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00768,
      "epss_percentile": 0.5273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haxtheweb",
      "product": "haxcms-php",
      "cwe": "CWE-78",
      "title": "HAX CMS Vulnerable to Command Injection using Git.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46394"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-11420",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00709,
      "epss_percentile": 0.50677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Altium",
      "product": "Altium Enterprise Server",
      "cwe": "CWE-22",
      "title": "Path Traversal in Altium Enterprise Server NIS Allows Unauthenticated Arbitrary File Write and File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11420"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-36500",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00686,
      "epss_percentile": 0.49848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36500"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-50234",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0064,
      "epss_percentile": 0.47912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LMS Community",
      "product": "Lyrion Music Server",
      "cwe": "CWE-22",
      "title": "Lyrion Music Server 9.2.0 Path Traversal File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50234"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-5411",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00612,
      "epss_percentile": 0.46628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webfactory",
      "product": "Advanced Google reCAPTCHA",
      "cwe": "CWE-434",
      "title": "WP Captcha PRO <= 5.38 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5411"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-7762",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00567,
      "epss_percentile": 0.44524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Morse Micro",
      "product": "HaLowLink 2",
      "cwe": null,
      "title": "Heap buffer overflow in dot11ah.ko S1G Capabilities IE processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7762"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-11419",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00548,
      "epss_percentile": 0.43544,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Altium",
      "product": "Altium Enterprise Server",
      "cwe": "CWE-22",
      "title": "Path Traversal in Altium Enterprise Server Vault UploadController Allows Arbitrary File Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11419"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-8914",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00541,
      "epss_percentile": 0.43181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Teltonika Networks",
      "product": "RUTOS",
      "cwe": "CWE-95",
      "title": "Command injection in Profile change function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8914"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-5415",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00539,
      "epss_percentile": 0.43076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webfactory",
      "product": "Advanced Google reCAPTCHA",
      "cwe": "CWE-288",
      "title": "WP Captcha PRO <= 5.38 - Authenticated (Subscriber+) Authentication Bypass via Temporary Login Link",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5415"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-7763",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00536,
      "epss_percentile": 0.42915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Morse Micro",
      "product": "HaLowLink 2",
      "cwe": null,
      "title": "Heap buffer overflow in morse.ko TIM IE processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7763"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2025-71318",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00533,
      "epss_percentile": 0.42766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Riello UPS",
      "product": "NetMan 204",
      "cwe": "CWE-306",
      "title": "NetMan 204 Missing Authentication for Administrative Functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71318"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-10732",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00521,
      "epss_percentile": 0.42043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "decompress",
      "cwe": "CWE-29",
      "title": "All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archive containing two entries with the same path - the first being a symlink to an arbitrary target and the second being a regular file - the file content is written through the symlink to the target location outside the output directory. This is due to the microtask processing order that checks readlink for the second file before resolving symlink for the first file. An attacker can write arbitrary file on the host filesystem potentially leading to remote code execution by providing a specially crafted ZIP archive. **Note:** This bypasses all existing path traversal protections including preventWritingThroughSymlink, added as a part of the fix for [CVE-2020-12265](https://security.snyk.io/vuln/SNYK-JS-DECOMPRESS-557358).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10732"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-11431",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00517,
      "epss_percentile": 0.41836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Altium",
      "product": "Altium Enterprise Server",
      "cwe": "CWE-22",
      "title": "Path Traversal in Altium Projects Service Allows Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11431"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-10879",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00485,
      "epss_percentile": 0.39816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HMBRAND",
      "product": "DBI",
      "cwe": "CWE-787",
      "title": "DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10879"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-45779",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00479,
      "epss_percentile": 0.3947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ubccr",
      "product": "xdmod",
      "cwe": "CWE-89",
      "title": "Open XDMoD Vulnerable to Unauthenticated SQL Injection Leading to Full Database Compromise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45779"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-11414",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00478,
      "epss_percentile": 0.39388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Altium",
      "product": "Altium Enterprise Server",
      "cwe": "CWE-22",
      "title": "Unauthenticated File Exfiltration in Altium Enterprise Server Vault Service via Hard-coded Cryptographic Key and Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11414"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-11416",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00469,
      "epss_percentile": 0.38799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jxxghp",
      "product": "MoviePilot",
      "cwe": "CWE-22",
      "title": "MoviePilot Path Traversal via Cloud Storage Download Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11416"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-6274",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0046,
      "epss_percentile": 0.38221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DTS Electronics Industry and Trade Ltd. Co.",
      "product": "Redline WR3200",
      "cwe": "CWE-287",
      "title": "Authentication Bypass in DTS Electronics' Redline WR3200",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6274"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-46391",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00457,
      "epss_percentile": 0.38065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haxtheweb",
      "product": "@haxtheweb/open-apis",
      "cwe": "CWE-183",
      "title": "HAX open-apis: Credential Theft via Server-Side Request Forgery (SSRF) in open-apis",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46391"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-11362",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00447,
      "epss_percentile": 0.37345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BINARY",
      "product": "DataDog::DogStatsd",
      "cwe": "CWE-93",
      "title": "DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11362"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2025-71317",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00432,
      "epss_percentile": 0.36155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Riello UPS",
      "product": "NetMan 204",
      "cwe": "CWE-798",
      "title": "NetMan 204 Hard-coded Backdoor Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71317"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-11345",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00414,
      "epss_percentile": 0.34729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "linqi GmbH",
      "product": "linqi",
      "cwe": "CWE-287",
      "title": "Improper Authentication Bypass in linqi CDN File Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11345"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-45409",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00408,
      "epss_percentile": 0.34174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kjd",
      "product": "idna",
      "cwe": "CWE-1333",
      "title": "Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45409"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-50230",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00406,
      "epss_percentile": 0.34002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LMS Community",
      "product": "Lyrion Music Server",
      "cwe": "CWE-79",
      "title": "Lyrion Music Server 9.2.0 Reflected XSS via server.log",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50230"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2025-12656",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.0039,
      "epss_percentile": 0.32299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpvividplugins",
      "product": "WPvivid — Backup, Migration & Staging",
      "cwe": "CWE-73",
      "title": "Migration, Backup, Staging – WPvivid Backup & Migration <= 0.9.128 - Authenticated (Admin+) Arbitrary Directory Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12656"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-45777",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00388,
      "epss_percentile": 0.3216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ubccr",
      "product": "xdmod",
      "cwe": "CWE-78",
      "title": "Open XDMoD Vulnerable to Unauthenticated Remote Code Execution (RCE) via OS Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45777"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-45746",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00387,
      "epss_percentile": 0.32033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-284",
      "title": "Termix Vulnerable to Arbitrary Command Execution via Session Hijacking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45746"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-46400",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00387,
      "epss_percentile": 0.31989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haxtheweb",
      "product": "haxcms-php",
      "cwe": "CWE-434",
      "title": "HAXCMS PHP has a File Upload Validation Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46400"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-11344",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00366,
      "epss_percentile": 0.29848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Vehicle Management System",
      "cwe": "CWE-284",
      "title": "code-projects Vehicle Management System New Driver Registration Form newdriver.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11344"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-50733",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.2948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shd101wyy",
      "product": "Markdown Preview Enhanced",
      "cwe": "CWE-95",
      "title": "Markdown Preview Enhanced Arbitrary Code Execution via WaveDrom eval()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50733"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-45327",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00357,
      "epss_percentile": 0.28892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DatanoiseTV",
      "product": "tinyice",
      "cwe": "CWE-306",
      "title": "TinyIce: Missing authentication on WebRTC ingest endpoint allows unauthorized stream injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45327"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-36785",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00357,
      "epss_percentile": 0.28924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the page parameter of the fromDhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36785"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-6448",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00352,
      "epss_percentile": 0.28428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "expresstech",
      "product": "Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker",
      "cwe": "CWE-89",
      "title": "Quiz and Survey Master (QSM) <= 11.1.2 - Authenticated (Admin+) SQL Injection via 'order' and 'limit' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6448"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-9088",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00348,
      "epss_percentile": 0.28004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-1220",
      "title": "Keycloak: keycloak: information disclosure due to user profile permission bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9088"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-46389",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00341,
      "epss_percentile": 0.27204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "defenseunicorns",
      "product": "uds-identity-config",
      "cwe": "CWE-287",
      "title": "UDS Identity Config has a client authentication bypass in `ClientIdAndKubernetesSecretAuthenticator`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46389"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-49492",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shd101wyy",
      "product": "Markdown Preview Enhanced",
      "cwe": "CWE-78",
      "title": "Markdown Preview Enhanced OS Command Injection in External File and Link Opening",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49492"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-9270",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00331,
      "epss_percentile": 0.2611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BINARY",
      "product": "DataDog::DogStatsd",
      "cwe": "CWE-93",
      "title": "DataDog::DogStatsd versions through 0.07 for Perl allow metric injections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9270"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-49493",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shd101wyy",
      "product": "Markdown Preview Enhanced",
      "cwe": "CWE-94",
      "title": "Markdown Preview Enhanced Arbitrary Code Execution via Bitfield interpretJS()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49493"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-45749",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.2538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-308",
      "title": "Termix's TOTP two-factor authentication can be disabled or bypassed using only the account password",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45749"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-48092",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcmilk",
      "product": "7-Zip",
      "cwe": "CWE-125",
      "title": "7-Zip SquashFS Fragment Offset Overflow (GHSL-2026-116)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48092"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2025-5088",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS / CloudVision eXchange (CVX)",
      "cwe": "CWE-269",
      "title": "Arista CloudVision Exchange (CVX) Cluster Privilege Escalation via MCS Redis Session",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-5088"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-45300",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-200",
      "title": "async-http-client: Cookie header not stripped on cross-origin redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45300"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-11423",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00321,
      "epss_percentile": 0.25028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Altium",
      "product": "Altium Enterprise Server",
      "cwe": "CWE-22",
      "title": "Path Traversal in Altium Enterprise Server Collaboration Service Allows Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11423"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-46401",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00311,
      "epss_percentile": 0.23907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haxtheweb",
      "product": "issues",
      "cwe": "CWE-613",
      "title": "HAX CMS PHP has Insufficient Session Expiration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46401"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-11400",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "AWS Advanced JDBC Wrapper",
      "cwe": "CWE-426",
      "title": "Privilege Escalation in AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11400"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-11401",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.2318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "AWS Advanced Go Wrapper",
      "cwe": "CWE-426",
      "title": "Privilege Escalation in AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11401"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-21035",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00298,
      "epss_percentile": 0.22482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Plus TV",
      "cwe": null,
      "title": "Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21035"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-46395",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00295,
      "epss_percentile": 0.22085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haxtheweb",
      "product": "haxcms-nodejs",
      "cwe": "CWE-200",
      "title": "HAX CMS Vulnerable to Private Key Disclosure via Broken HMAC Implementation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46395"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-45750",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00294,
      "epss_percentile": 0.21986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-78",
      "title": "Termix Vulnerable to Arbitrary Command Execution in File Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45750"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-50233",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LMS Community",
      "product": "Lyrion Music Server",
      "cwe": "CWE-548",
      "title": "Lyrion Music Server 9.2.0 Arbitrary Directory Listing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50233"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-46399",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haxtheweb",
      "product": "haxcms-nodejs",
      "cwe": "CWE-15",
      "title": "Authenticated Remote Code Execution via File Overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46399"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-8976",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeisle",
      "product": "RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator",
      "cwe": "CWE-862",
      "title": "RSS Aggregator by Feedzy <= 5.1.7 - Missing Authorization to Authenticated (Contributor+) Import Job Creation, Execution, Purge, Log Clearing, and Information Disclosure via Multiple AJAX Sub-Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8976"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-46397",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haxtheweb",
      "product": "haxcms-php",
      "cwe": "CWE-22",
      "title": "haxcms-php Local File Inclusion via saveOutline API Location Parameter v2.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46397"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-46493",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haxtheweb",
      "product": "haxcms-php",
      "cwe": "CWE-338",
      "title": "haxtheweb/haxcms-php uses insecure method for generating salt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46493"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-10038",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More",
      "cwe": "CWE-639",
      "title": "Charitable <= 1.8.11.1 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Attachment Deletion via 'avatar' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10038"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-11334",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00284,
      "epss_percentile": 0.20969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tittuvarghese",
      "product": "CollegeManagementSystem",
      "cwe": "CWE-74",
      "title": "tittuvarghese CollegeManagementSystem fetch.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11334"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-45743",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-639",
      "title": "Termix has a File-Manager Session Hijack via Missing Ownership Check (IDOR)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45743"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-36501",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-20",
      "title": "An issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36501"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-45290",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CloudburstMC",
      "product": "Network",
      "cwe": "CWE-770",
      "title": "Cloudburst Network has DoS in RakNet connection handling due to missing bound checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45290"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-48101",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcmilk",
      "product": "7-Zip",
      "cwe": "CWE-908",
      "title": "GHSL-2026-117: 7-Zip UEFI Capsule uninitialized heap memory disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48101"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-45758",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00276,
      "epss_percentile": 0.20058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardrails-ai",
      "product": "guardrails",
      "cwe": "CWE-506",
      "title": "Malicious code in guardrails-ai 0.10.1 (supply chain compromise)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45758"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-46511",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.20016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haxtheweb",
      "product": "haxcms-nodejs",
      "cwe": "CWE-79",
      "title": "HAXcms: Mass Token Exfiltration and Cross-Tenant Hijack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46511"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-11337",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.19739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tittuvarghese",
      "product": "CollegeManagementSystem",
      "cwe": "CWE-79",
      "title": "tittuvarghese CollegeManagementSystem fetch.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11337"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-7523",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alejo30",
      "product": "Alba Board",
      "cwe": "CWE-862",
      "title": "Alba Board <= 2.1.3 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Disclosure via 'card_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7523"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-46390",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haxtheweb",
      "product": "haxcms-php",
      "cwe": "CWE-639",
      "title": "HAX CMS has Unauthenticated Git Access via User-Controlled Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46390"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-48112",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00267,
      "epss_percentile": 0.18932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcmilk",
      "product": "7-Zip",
      "cwe": "CWE-125",
      "title": "GHSL-2026-122 7-Zip Ar SYMDEF OOB Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48112"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-45291",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CloudburstMC",
      "product": "Network",
      "cwe": "CWE-20",
      "title": "Cloudburst Network erroneously handles invalid connections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45291"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-11342",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Hotel and Tourism Reservation System",
      "cwe": "CWE-74",
      "title": "code-projects Hotel and Tourism Reservation System details.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11342"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-46357",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haxtheweb",
      "product": "haxcms-nodejs",
      "cwe": "CWE-20",
      "title": "HAX CMS NodeJS application Vulnerable to Denial of Service using Malicious Import Request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46357"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-46393",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haxtheweb",
      "product": "haxcms-nodejs",
      "cwe": "CWE-918",
      "title": "HAXcms createSite SSRF Enables Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46393"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-45776",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ubccr",
      "product": "xdmod",
      "cwe": "CWE-284",
      "title": "Open XDMoD has Broken Access Control via Client-Controlled Session Variable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45776"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2025-5089",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS / CloudVision eXchange (CVX)",
      "cwe": "CWE-20",
      "title": "Arista EOS SysDB Agent Denial of Service via Malformed CVX Client/Server Messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-5089"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2025-5090",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS / CloudVision eXchange (CVX)",
      "cwe": "CWE-20",
      "title": "Arista CloudVision Exchange Cluster Instability via Unexpected Switch Messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-5090"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-11335",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00232,
      "epss_percentile": 0.14299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tittuvarghese",
      "product": "CollegeManagementSystem",
      "cwe": "CWE-384",
      "title": "tittuvarghese CollegeManagementSystem login-form.php session_start session fixiation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11335"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-46396",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0023,
      "epss_percentile": 0.14101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haxtheweb",
      "product": "haxcms-nodejs",
      "cwe": "CWE-79",
      "title": "HAX CMS has a stored XSS via <iframe> that allows access to sensitive client-side data and account takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46396"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-46496",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0023,
      "epss_percentile": 0.141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haxtheweb",
      "product": "haxcms-nodejs",
      "cwe": "CWE-79",
      "title": "HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46496"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-11424",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Altium",
      "product": "Altium Enterprise Server",
      "cwe": "CWE-200",
      "title": "Server-Side Request Forgery in Altium Platform Design GraphQL Service Allows Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11424"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-2379",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-672",
      "title": "Arista EOS IPsec Tunnel Sequence Number Mismatch via Interface Flaps when Anti-Replay is Disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2379"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-11346",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.1359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "linqi GmbH",
      "product": "linqi",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF) allowing Internal Network Probing in linqi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11346"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-48103",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcmilk",
      "product": "7-Zip",
      "cwe": "CWE-125",
      "title": "GHSL-2026-119 7-Zip WIM SecurityId OOB read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48103"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-48111",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcmilk",
      "product": "7-Zip",
      "cwe": "CWE-125",
      "title": "GHSL-2026-121 7-Zip UEFI DEPEX OOB Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48111"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-46392",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00223,
      "epss_percentile": 0.13225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haxtheweb",
      "product": "haxcms-php",
      "cwe": "CWE-178",
      "title": "HAX CMS PHP Has a Stored XSS via Case-Sensitivity Mismatch in HTML Upload Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46392"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-25621",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.12994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)",
      "cwe": "CWE-78",
      "title": "Arista Edge Threat Management NGFW Reports Application Insecure Input Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25621"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-11332",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.11976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-88",
      "title": "Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11332"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-11326",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenAI",
      "product": "OpenAI Atlas",
      "cwe": "CWE-284",
      "title": "OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site scripting vulnerability in forum.openai.com could be used to access these functions, allowing access to browser history information and the ability to open or close tabs. OpenAI Atlas 1.2025.288.15 narrows access to these APIs to *.chatgpt.com; users should upgrade to 1.2025.288.15 or later.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11326"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-11333",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00214,
      "epss_percentile": 0.1202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tittuvarghese",
      "product": "CollegeManagementSystem",
      "cwe": "CWE-284",
      "title": "tittuvarghese CollegeManagementSystem Student Data Upload Endpoint upload_student_data.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11333"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-11336",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00214,
      "epss_percentile": 0.1202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tittuvarghese",
      "product": "CollegeManagementSystem",
      "cwe": "CWE-266",
      "title": "tittuvarghese CollegeManagementSystem Admin admin_page.php improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11336"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-11338",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0021,
      "epss_percentile": 0.1152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Ship Ferry Ticket Reservation System",
      "cwe": "CWE-79",
      "title": "SourceCodester Ship Ferry Ticket Reservation System manage_user cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11338"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-11369",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.11125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "linqi GmbH",
      "product": "linqi",
      "cwe": "CWE-639",
      "title": "IDOR in Comment API Allows Cross-Process Comment Read and Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11369"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-8714",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.11,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Tapo C520WS v2",
      "cwe": "CWE-20",
      "title": "Denial-of-Service Vulnerability in RTSP Input Handling on TP-Link's Tapo C520WS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8714"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-9719",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.11024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "latepoint",
      "product": "LatePoint – Calendar Booking Plugin for Appointments and Events",
      "cwe": "CWE-352",
      "title": "LatePoint <= 5.6.0 - Cross-Site Request Forgery via invoices__change_status Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9719"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2020-25900",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HelloTalk",
      "product": "HelloTalk",
      "cwe": "CWE-359",
      "title": "HelloTalk through 3.4.1 stores full-precision GPS coordinates even when the user had intended to share only a country or city. Furthermore, these coordinates are placed into a database on the client of other users. (The client side was changed in 2019 to encrypt that database.)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-25900"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-38579",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Multiple reflected Cross-Site Scripting (XSS) vulnerabilities in damasac thaipalliative_lte through version 3.0 allow remote attackers to inject arbitrary web script or HTML via the idFormMain parameter (line 24), the id parameter (lines 25, 75), and the ptid_key parameter (lines 26, 42) in /substudy/ezform.php. User input is echoed into HTML attributes and JavaScript contexts without encoding.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38579"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-50232",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LMS Community",
      "product": "Lyrion Music Server",
      "cwe": "CWE-79",
      "title": "Lyrion Music Server 9.2.0 Stored XSS via Metadata Tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50232"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-8900",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "spyrosvl",
      "product": "Simple SEO Slideshow",
      "cwe": "CWE-79",
      "title": "Simple SEO Slideshow <= 1.2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8900"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-48102",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcmilk",
      "product": "7-Zip",
      "cwe": "CWE-125",
      "title": "GHSL-2026-118: 7-Zip UDF Field OOB Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48102"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-8893",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "payaddons",
      "product": "Express Payment For Stripe",
      "cwe": "CWE-79",
      "title": "Express Payment For Stripe <= 1.28.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8893"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-46398",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00183,
      "epss_percentile": 0.08218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haxtheweb",
      "product": "haxcms-php",
      "cwe": "CWE-614",
      "title": "HAX CMS Missing Secure Flag on Cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46398"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-50231",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LMS Community",
      "product": "Lyrion Music Server",
      "cwe": "CWE-79",
      "title": "Lyrion Music Server 9.2.0 Unauthenticated Stored XSS via server.log",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50231"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-6239",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.0791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Tapo C520WS v2",
      "cwe": "CWE-121",
      "title": "Authenticated Stack-based Buffer Overflow in ONVIF CreateUsers Service in TP-Link Tao C520WS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6239"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-6240",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.0791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Tapo C520WS v2",
      "cwe": "CWE-121",
      "title": "Authenticated Stack-based Buffer Overflow in ONVIF DeleteUsers Service on TP-Link Tapo C520WS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6240"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-48104",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcmilk",
      "product": "7-Zip",
      "cwe": "CWE-125",
      "title": "GHSL-2026-120: 7-Zip SquashFS BlockToNode uninitialized heap read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48104"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-6242",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Tapo C520WS v2",
      "cwe": "CWE-134",
      "title": "Authenticated Format String Vulnerability in ONVIF Subscribe Service on TP-Link Tapo C520WS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6242"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-45745",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00168,
      "epss_percentile": 0.06527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Termix-SSH",
      "product": "Termix",
      "cwe": "CWE-295",
      "title": "Termix has improper certificate validation in Electron desktop client that enables MITM credential/token theft",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45745"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-50259",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-121",
      "title": "Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb setmap request via mapwidths indexing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50259"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2025-59174",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.0619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ericsson",
      "product": "Packet Core Controller",
      "cwe": "CWE-228",
      "title": "Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59174"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-25657",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.0619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ericsson",
      "product": "Packet Core Gateway (PCG)",
      "cwe": "CWE-228",
      "title": "Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25657"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-25658",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ericsson",
      "product": "Packet Core Gateway (PCG)",
      "cwe": "CWE-230",
      "title": "Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25658"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-25659",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ericsson",
      "product": "Packet Core Gateway (PCG)",
      "cwe": "CWE-230",
      "title": "Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25659"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-8608",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "awordpresslife",
      "product": "Event Monster – Event Manager, Ticket Booking & Registration",
      "cwe": "CWE-345",
      "title": "Event Monster <= 2.1.0 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via em_capture_payment AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8608"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-37737",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-346",
      "title": "sanic-cors version 2.2.0 and prior contains an improper regular expression in the try_match() function in sanic_cors/core.py that uses re.match without end-anchoring. This allows an attacker to bypass CORS origin allowlists by registering a domain that begins with a trusted origin string, to gain unauthorized access to cross-origin requests for authenticated resources.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37737"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-6241",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.06009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Tapo C520WS v2",
      "cwe": "CWE-134",
      "title": "Authenticated Format String Vulnerability in ONVIF AddScopes Method on TP-Link Tapo C520WS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6241"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-50258",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00161,
      "epss_percentile": 0.05822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-121",
      "title": "Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb key types due to unchecked shift levels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50258"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-41567",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00161,
      "epss_percentile": 0.05803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "moby/v2/daemon",
      "cwe": "CWE-427",
      "title": "Docker: `PUT /containers/{id}/archive` executes container binary on the host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41567"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-11422",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shd101wyy",
      "product": "Markdown Preview Enhanced",
      "cwe": "CWE-95",
      "title": "Markdown Preview Enhanced 0.8.x Code Injection via WaveDrom Rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11422"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-50235",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LMS Community",
      "product": "Lyrion Music Server",
      "cwe": "CWE-79",
      "title": "Lyrion Music Server 9.2.0 Reflected XSS via search Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50235"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-50256",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.0542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-121",
      "title": "Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font alias resolution due to libxfont2 name length mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50256"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-50260",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.05078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-416",
      "title": "Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50260"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-50261",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.05078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-416",
      "title": "Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50261"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-25624",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "Arista Edge Threat Management - Arista Next Generation Firewall (NGFW)",
      "cwe": "CWE-79",
      "title": "Arista Edge Threat Management NGFW UI Administrative Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25624"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-21825",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "DX Compose",
      "cwe": "CWE-79",
      "title": "HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21825"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-34123",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Tapo C520WS v2",
      "cwe": "CWE-287",
      "title": "Whitelist Validation Bypass in TP-Link Tapo C520WS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34123"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-50264",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04549,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-787",
      "title": "Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds heap write in dri2 drigetbuffers/drigetbufferswithformat",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50264"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-50592",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Znuny",
      "product": "Znuny",
      "cwe": "CWE-79",
      "title": "In Znuny LTS before 6.5.21 and Znuny before 7.3.3, there is reflected XSS in AdminCommunicationLog (aka the communication log administration view).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50592"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-45778",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00147,
      "epss_percentile": 0.04432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ubccr",
      "product": "xdmod",
      "cwe": "CWE-79",
      "title": "Open XDMoD Vulnerable to Reflected Cross-Site Scripting (XSS) in Password Reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45778"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-21826",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Digital Experience & DX Compose",
      "cwe": "CWE-601",
      "title": "HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21826"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-50257",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.04001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-416",
      "title": "Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in misyncdestroyfence()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50257"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-50263",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-416",
      "title": "Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information disclosure in createsaverwindow()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50263"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-50591",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Znuny",
      "product": "Znuny",
      "cwe": "CWE-79",
      "title": "In Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can occur via stored user preferences.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50591"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-50262",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in glx changedrawableattributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50262"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-7047",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "absikandar",
      "product": "Frontend User Notes",
      "cwe": "CWE-352",
      "title": "Frontend User Notes <= 2.1.1 - Cross-Site Request Forgery to Note Content Modification via 'confirmEdit' Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7047"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-50593",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Graphite project",
      "product": "Graphite",
      "cwe": "CWE-191",
      "title": "Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50593"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-11312",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00112,
      "epss_percentile": 0.01596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bytedance",
      "product": "InfiniStore",
      "cwe": "CWE-404",
      "title": "bytedance InfiniStore KV Map infinistore.h purge_kv_map algorithmic complexity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11312"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-21037",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Members",
      "cwe": null,
      "title": "Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21037"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-21038",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.01036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Android USB Driver for Windows",
      "cwe": "CWE-125",
      "title": "Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to access out-of-bounds memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21038"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-21030",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.00702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21030"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-21036",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.00696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Internet",
      "cwe": "CWE-863",
      "title": "Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21036"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-21025",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21025"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-21032",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Assistant",
      "cwe": null,
      "title": "Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21032"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-21033",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Assistant",
      "cwe": null,
      "title": "Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21033"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-21029",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21029"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-21026",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21026"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-21031",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": "CWE-863",
      "title": "Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21031"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-21028",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21028"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-21017",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21017"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-50590",
      "cvss_base": 4.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0009,
      "epss_percentile": 0.00531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mimecast",
      "product": "Incydr",
      "cwe": "CWE-732",
      "title": "In Mimecast Incydr before 2.6.0, arbitrary file access can occur.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50590"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-21027",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00084,
      "epss_percentile": 0.00339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21027"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-21034",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00084,
      "epss_percentile": 0.00339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Auto",
      "cwe": null,
      "title": "Improper export of android application components in Samsung Auto prior to version 3.1.2.61 in Android 15 and 3.2.0.38 in Android 16 allows local attacker to change audio configuration.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21034"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-11329",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00078,
      "epss_percentile": 0.00157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "onnx",
      "product": "onnx-mlir",
      "cwe": "CWE-327",
      "title": "onnx onnx-mlir Placeholder Node Cache backend.py generate_hash_key weak hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11329"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-11330",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00075,
      "epss_percentile": 0.00107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thedotmack",
      "product": "claude-mem",
      "cwe": "CWE-327",
      "title": "thedotmack claude-mem Observation Content Hash store.ts computeObservationContentHash weak hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11330"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-11347",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00073,
      "epss_percentile": 0.00079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "linqi GmbH",
      "product": "linqi",
      "cwe": "CWE-321",
      "title": "Hardcoded Cryptographic Keys and Weak IV Generation in linqi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11347"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45300",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45300 (AsyncHttpClient async-http-client). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45743",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45743 (Termix-SSH Termix). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45744",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45744 (Termix-SSH Termix). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45745",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45745 (Termix-SSH Termix). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45746",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45746 (Termix-SSH Termix). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45748",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45748 (Termix-SSH Termix). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45749",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45749 (Termix-SSH Termix). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45750",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45750 (Termix-SSH Termix). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48092",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48092 (mcmilk 7-Zip). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48095",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48095 (mcmilk 7-Zip). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48101",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48101 (mcmilk 7-Zip). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48102",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48102 (mcmilk 7-Zip). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48103",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48103 (mcmilk 7-Zip). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48104",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48104 (mcmilk 7-Zip). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48111",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48111 (mcmilk 7-Zip). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48112",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48112 (mcmilk 7-Zip). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2024-21182",
      "detail": "DUE DATE PASSED — CVE-2024-21182 (Oracle WebLogic Server). CISA remediation deadline was June 4, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2025-34291",
      "detail": "DUE DATE PASSED — CVE-2025-34291 (Langflow). CISA remediation deadline was June 4, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-34926",
      "detail": "DUE DATE PASSED — CVE-2026-34926 (Trend Micro, Inc. TrendAI Apex One). CISA remediation deadline was June 4, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
