{
  "day": "2026-06-08",
  "boundary": "UTC calendar day",
  "published_count": 286,
  "by_severity": {
    "CRITICAL": 23,
    "HIGH": 132,
    "MEDIUM": 82,
    "LOW": 48
  },
  "kev_count": 2,
  "exploit_reference_count": 11,
  "awaiting_enrichment_count": 1,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-42271",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.83013,
      "epss_percentile": 0.99649,
      "kev": true,
      "kev_due_at": "2026-06-22",
      "vendor": "BerriAI",
      "product": "LiteLLM",
      "cwe": null,
      "title": "BerriAI LiteLLM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42271"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-50751",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.82554,
      "epss_percentile": 0.99639,
      "kev": true,
      "kev_due_at": "2026-06-11",
      "vendor": "checkpoint",
      "product": "Quantum Security Gateway",
      "cwe": "CWE-287",
      "title": "User Authentication Bypass in VPN Remote Access and Mobile Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50751"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-49975",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.27984,
      "epss_percentile": 0.97947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-789",
      "title": "Apache HTTP Server: mod_http2 denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49975"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-11499",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.06561,
      "epss_percentile": 0.93257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "HG7HG9",
      "cwe": "CWE-119",
      "title": "Tenda HG7HG9/HG10 formDOMAINBLK stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11499"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-50752",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.04547,
      "epss_percentile": 0.90819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "checkpoint",
      "product": "Quantum Security Gateway",
      "cwe": "CWE-295",
      "title": "Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50752"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-11498",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.03799,
      "epss_percentile": 0.89141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "HG7HG9",
      "cwe": "CWE-119",
      "title": "Tenda HG7HG9/HG10 Web Management voip_other_set asp_voip_OtherSet stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11498"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-46442",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.03489,
      "epss_percentile": 0.88187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-94",
      "title": "Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46442"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-3238",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.02669,
      "epss_percentile": 0.84547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-476",
      "title": "Samba: denial of service against ad dc wins server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3238"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-25555",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01824,
      "epss_percentile": 0.77056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openbullet",
      "product": "openbullet2",
      "cwe": "CWE-305",
      "title": "OpenBullet2 0.3.2 Authentication Bypass via X-Api-Key Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25555"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-11556",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.01614,
      "epss_percentile": 0.74034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "F451",
      "cwe": "CWE-77",
      "title": "Tenda F451 Web Management WriteFacMac formWriteFacMac os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11556"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-9506",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01238,
      "epss_percentile": 0.66696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "Bagisto",
      "cwe": "CWE-22",
      "title": "Path Traversal Vulnerability in Bagisto",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9506"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-34355",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01118,
      "epss_percentile": 0.63532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-122",
      "title": "Apache HTTP Server: mod_proxy_html buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34355"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-42536",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00986,
      "epss_percentile": 0.59626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-122",
      "title": "Apache HTTP Server: mod_xml2enc heap overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42536"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-11487",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00923,
      "epss_percentile": 0.57587,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Neovim",
      "cwe": "CWE-74",
      "title": "Neovim View Branch secure.lua M.read command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11487"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-40519",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00921,
      "epss_percentile": 0.57529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NginxProxyManager",
      "product": "nginx-proxy-manager",
      "cwe": "CWE-78",
      "title": "Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40519"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-8913",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00907,
      "epss_percentile": 0.57109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Archer MR600 v5",
      "cwe": "CWE-78",
      "title": "Command Injection in TP-Link's Archer MR600 WireGuard Client Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8913"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2024-58348",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00838,
      "epss_percentile": 0.54962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "background-image-cropper",
      "product": "Background Image Cropper",
      "cwe": "CWE-434",
      "title": "WordPress Background Image Cropper 1.2 Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-58348"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-47430",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00723,
      "epss_percentile": 0.51194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Cordova Plugin InAppBrowser",
      "cwe": "CWE-20",
      "title": "Cordova Plugin InAppBrowser: iOS: Arbitrary Cordova callback IDs can be dispatched without validation from InAppBrowser WebViews",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47430"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-44185",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00713,
      "epss_percentile": 0.5083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-126",
      "title": "Apache HTTP Server: Stack Buffer Over-Read in mod_ssl OCSP `send_request`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44185"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-34356",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00708,
      "epss_percentile": 0.50666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-122",
      "title": "Apache HTTP Server: ProxyPassReverseCookieMap buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34356"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-29167",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00688,
      "epss_percentile": 0.49913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-416",
      "title": "Apache HTTP Server: mod_ldap per-dir use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29167"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2024-58349",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00674,
      "epss_percentile": 0.49349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Travel Kit",
      "product": "Travelscape",
      "cwe": "CWE-434",
      "title": "WordPress Theme Travelscape 1.0.3 Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-58349"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2023-54352",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00613,
      "epss_percentile": 0.46677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Travel Kit",
      "product": "Travelscape",
      "cwe": "CWE-306",
      "title": "WordPress Seotheme Remote Code Execution Unauthenticated",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-54352"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-11517",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.006,
      "epss_percentile": 0.46082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTT",
      "product": "HiPER 2610G",
      "cwe": "CWE-119",
      "title": "UTT HiPER 2610G formConfigDnsFilterGlobal strcpy buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11517"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-49755",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00596,
      "epss_percentile": 0.45861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wojtekmach",
      "product": "req",
      "cwe": "CWE-409",
      "title": "Decompression bomb DoS in Req via auto-decoded archive and compressed response bodies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49755"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-44186",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00583,
      "epss_percentile": 0.45321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-835",
      "title": "Apache HTTP Server: Loop in `proxy_ftp_handler` in mod_proxy_ftp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44186"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-25855",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0057,
      "epss_percentile": 0.44663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openbullet",
      "product": "openbullet2",
      "cwe": "CWE-78",
      "title": "OpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25855"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-25559",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00566,
      "epss_percentile": 0.44488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openbullet",
      "product": "openbullet2",
      "cwe": "CWE-22",
      "title": "OpenBullet2 0.3.2 Path Traversal via Wordlist Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25559"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-52778",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00561,
      "epss_percentile": 0.44247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YesWiki",
      "product": "yeswiki",
      "cwe": "CWE-94",
      "title": "YesWiki has Unsafe eval() in Formula Calculator - Remote Code Execution (RCE) & Denial of Service (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52778"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-43951",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00545,
      "epss_percentile": 0.43417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-125",
      "title": "Apache HTTP Server: OOB Read in `merge_response_headers` can cause crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43951"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-41448",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00542,
      "epss_percentile": 0.43231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AdguardTeam",
      "product": "AdGuardHome",
      "cwe": "CWE-22",
      "title": "AdGuard Home Authentication Bypass via Path Traversal in Admin-Token Cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41448"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-42535",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00538,
      "epss_percentile": 0.43022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-668",
      "title": "Apache HTTP Server: mod_dav_fs protected directory access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42535"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2023-54350",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00532,
      "epss_percentile": 0.42684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webandprint",
      "product": "Augmented Reality",
      "cwe": "CWE-306",
      "title": "WordPress Augmented-Reality Plugin Remote Code Execution Unauthenticated",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-54350"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-36789",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00529,
      "epss_percentile": 0.42533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda AC1206 v15.03.06.23 was discovered to contain multiple stack overflows in the fromGstDhcpSetSer function via the username and password parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36789"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-29170",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00523,
      "epss_percentile": 0.42166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-79",
      "title": "Apache HTTP Server: mod_proxy_ftp XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29170"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-11492",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00511,
      "epss_percentile": 0.41417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DIR-823G",
      "cwe": "CWE-266",
      "title": "D-Link DIR-823G vsftpd vsftpd.conf least privilege violation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11492"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-44631",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00504,
      "epss_percentile": 0.41034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-124",
      "title": "Apache HTTP Server: Heap Underflow in `ap_regname` via Signed Char Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44631"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-43973",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00482,
      "epss_percentile": 0.39646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ninenines",
      "product": "gun",
      "cwe": "CWE-770",
      "title": "gun HTTP/1.1 response buffer has no size limit allowing server-controlled memory exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43973"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-43974",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00482,
      "epss_percentile": 0.39645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ninenines",
      "product": "gun",
      "cwe": "CWE-841",
      "title": "gun HTTP/1.1 client accepts unsolicited 101 Switching Protocols response allowing server-driven protocol hijack and OOM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43974"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-48913",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.39468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-416",
      "title": "Apache HTTP Server: mod_http2 memory corruption when file handles exhausted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48913"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-11553",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00477,
      "epss_percentile": 0.39365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "HG7HG9",
      "cwe": "CWE-119",
      "title": "Tenda HG7HG9/HG10 formPPPEdit stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11553"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-11557",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00476,
      "epss_percentile": 0.39302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "F451",
      "cwe": "CWE-119",
      "title": "Tenda F451 Web Management Natlimit fromNatlimit stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11557"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-25856",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00473,
      "epss_percentile": 0.39051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openbullet",
      "product": "openbullet2",
      "cwe": "CWE-94",
      "title": "OpenBullet2 0.3.2 Authenticated RCE via Job Configuration Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25856"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-46490",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00469,
      "epss_percentile": 0.38782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tngan",
      "product": "samlify",
      "cwe": "CWE-91",
      "title": "samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46490"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-11503",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "CX12L",
      "cwe": "CWE-119",
      "title": "Tenda CX12L Wi-Fi Configuration Endpoint fast_setting_wifi_set form_fast_setting_wifi_set stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11503"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-11504",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "CX12L",
      "cwe": "CWE-119",
      "title": "Tenda CX12L Wi-Fi Schedule Configuration Endpoint openSchedWifi setSchedWifi stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11504"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-11522",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "W20E",
      "cwe": "CWE-119",
      "title": "Tenda W20E setPortMirror formSetPortMirror stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11522"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-11523",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "W20E",
      "cwe": "CWE-119",
      "title": "Tenda W20E Web Management PortalAuth formPortalAuth stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11523"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-11524",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "W20E",
      "cwe": "CWE-119",
      "title": "Tenda W20E Web Management modifyWifiFilterRules stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11524"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-11528",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "AC18",
      "cwe": "CWE-119",
      "title": "Tenda AC18 Web Management getRebootStatus sub_45304 stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11528"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-46289",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00457,
      "epss_percentile": 0.38062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "lib/scatterlist: fix length calculations in extract_kvec_to_sg",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46289"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-49233",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.37233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Routinator",
      "cwe": "CWE-22",
      "title": "Routinator cache path traversal using rogue rsync URIs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49233"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-11497",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00432,
      "epss_percentile": 0.36175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DCS-5615",
      "cwe": "CWE-266",
      "title": "D-Link DCS-5615 Boa Webserver boa.conf least privilege violation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11497"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-9669",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00428,
      "epss_percentile": 0.35881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Software Foundation",
      "product": "CPython",
      "cwe": "CWE-121",
      "title": "bz2.BZ2Decompressor reuse after error can cause a stack buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9669"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-36786",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00415,
      "epss_percentile": 0.34788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the list1 parameter of the fromDhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36786"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-11555",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00405,
      "epss_percentile": 0.33905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DGS-1100-08PD",
      "cwe": "CWE-266",
      "title": "D-Link DGS-1100-08PD Web boa.conf least privilege violation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11555"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-41723",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00399,
      "epss_percentile": 0.33276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VMware",
      "product": "VCF operations",
      "cwe": "CWE-79",
      "title": "VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41723"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-35058",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00392,
      "epss_percentile": 0.32561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "OpenVPN",
      "cwe": "CWE-617",
      "title": "Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and cause a denial of service via a specially crafted packet.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35058"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-46304",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00389,
      "epss_percentile": 0.32211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46304"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-46306",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00389,
      "epss_percentile": 0.32211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "flow_dissector: do not dissect PPPoE PFC frames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46306"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-11518",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00388,
      "epss_percentile": 0.32151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Inventory System",
      "cwe": "CWE-79",
      "title": "SourceCodester Inventory System User Management users.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11518"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-40215",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00386,
      "epss_percentile": 0.31921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "OpenVPN",
      "cwe": "CWE-125",
      "title": "A race condition in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows remote attackers to potentially cause a server crash or leak heap memory via a use-after-free triggered during TLS session promotion.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40215"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-46486",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00376,
      "epss_percentile": 0.30913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mvt-project",
      "product": "mvt",
      "cwe": "CWE-22",
      "title": "Mobile Verification Toolkit (MVT): Path Traversal via unsanitized File identifiers in iOS Backup processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46486"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-46484",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00374,
      "epss_percentile": 0.3064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tale",
      "product": "headplane",
      "cwe": "CWE-22",
      "title": "Headplane: Path Traversal + RBAC Bypass in renameNode allows authenticated OIDC users to expire or rename any node/user",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46484"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-11516",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.0037,
      "epss_percentile": 0.30235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UTT",
      "product": "HiPER 2610G",
      "cwe": "CWE-119",
      "title": "UTT HiPER 2610G formNatStaticMap strcpy buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11516"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-49235",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00368,
      "epss_percentile": 0.29978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Routinator",
      "cwe": "CWE-755",
      "title": "Routinator crashes on specifically crafted RRDP XML files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49235"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-47345",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00366,
      "epss_percentile": 0.29832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "HTML Sanitizer",
      "cwe": "CWE-79",
      "title": "TYPO3 HTML Sanitizer allows Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47345"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-11662",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00359,
      "epss_percentile": 0.29178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11662"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-49232",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Routinator",
      "cwe": "CWE-755",
      "title": "Routinator exits when accepting an incoming HTTP or RTR connection fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49232"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-46478",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-915",
      "title": "Flowise: DatasetRow create+update mass-assignment allows cross-workspace row takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46478"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2022-50953",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00342,
      "epss_percentile": 0.27321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brooks24",
      "product": "admin-word-count-column",
      "cwe": "CWE-22",
      "title": "WordPress Plugin admin-word-count-column 2.2 Local File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-50953"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-22164",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-122",
      "title": "GPU DDK - Kernel heap OOB write in DevmemIntComputeVirtualIndicesFromLogical",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22164"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-11651",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00337,
      "epss_percentile": 0.26762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11651"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-46475",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-915",
      "title": "Flowise: Assistant create+update mass-assignment allows cross-workspace assistant takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46475"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-46476",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-915",
      "title": "Flowise: CustomTemplate create+update mass-assignment allows cross-workspace template takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46476"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-46477",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-915",
      "title": "Flowise: Dataset create+update mass-assignment allows cross-workspace dataset takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46477"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-46479",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-915",
      "title": "Flowise: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46479"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-46480",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-915",
      "title": "Flowise: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46480"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-46444",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-862",
      "title": "Flowise: Vector Store No Permission Checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46444"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-11530",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "imvks786",
      "product": "student_management_system",
      "cwe": "CWE-74",
      "title": "imvks786 student_management_system Login index.ph sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11530"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-11531",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "imvks786",
      "product": "student_management_system",
      "cwe": "CWE-74",
      "title": "imvks786 student_management_system Administrator Login Endpoint admin_login.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11531"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-11393",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "AgentCore CLI",
      "cwe": "CWE-94",
      "title": "Code injection via improper triple-quote escaping in AgentCore CLI Bedrock Agent import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11393"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-11649",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.24263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11649"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-11650",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.24264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11650"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-39908",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.24208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openbullet",
      "product": "openbullet2",
      "cwe": "CWE-522",
      "title": "OpenBullet2 0.3.2 NTLMv2 Hash Disclosure via UNC Path Proxy Source",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39908"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-41724",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VMware",
      "product": "VCF operations",
      "cwe": "CWE-79",
      "title": "VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41724"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-11683",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebCodecs in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11683"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-11477",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00303,
      "epss_percentile": 0.23043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hs-web",
      "product": "hsweb-framework",
      "cwe": "CWE-601",
      "title": "hs-web hsweb-framework OAuth2 Client OAuth2Client.java OAuth2Client redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11477"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-39910",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00302,
      "epss_percentile": 0.22849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "STACKIT",
      "product": "IaaS API",
      "cwe": "CWE-862",
      "title": "STACKIT IaaS API Privilege Escalation via Service Account Attachment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39910"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-41722",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.22865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VMware",
      "product": "VCF operations",
      "cwe": "CWE-79",
      "title": "VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41722"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-11470",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00301,
      "epss_percentile": 0.22739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hs-web",
      "product": "hsweb-framework",
      "cwe": "CWE-22",
      "title": "hs-web hsweb-framework File Upload FileUploadProperties.java denied path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11470"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-44541",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.22352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ethyca",
      "product": "fides",
      "cwe": "CWE-79",
      "title": "Fides: DOM-based XSS vulnerability in fides.js via fides_description override",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44541"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-46656",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.22013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bludit",
      "product": "bludit",
      "cwe": "CWE-285",
      "title": "Bludit CMS has improper authorization and mediation failure leading to persistent ghost sessions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46656"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-11482",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System archive5.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11482"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-11490",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Online Music Site",
      "cwe": "CWE-74",
      "title": "code-projects Online Music Site Search.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11490"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-11474",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kushan2k",
      "product": "student-management-system",
      "cwe": "CWE-284",
      "title": "Kushan2k student-management-system Registration Endpoint RegisterService.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11474"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-11552",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.21186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Onlne Examination & Learning Management System",
      "cwe": "CWE-255",
      "title": "SourceCodester Onlne Examination & Learning Management System import_users.php hard-coded password",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11552"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-47344",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00282,
      "epss_percentile": 0.20762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "HTML Sanitizer",
      "cwe": "CWE-79",
      "title": "TYPO3 HTML Sanitizer allows Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47344"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-11500",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00281,
      "epss_percentile": 0.20699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Weaviate",
      "cwe": "CWE-285",
      "title": "Weaviate Static API Key client.go validateConfig authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11500"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-46303",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "isofs: validate Rock Ridge CE continuation extent against volume size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46303"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-11515",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.20029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Barangay Resident Profiling and Information Management System",
      "cwe": "CWE-255",
      "title": "SourceCodester Barangay Resident Profiling and Information Management System Password Reset passsword_reset.php hard-coded password",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11515"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-11639",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.19995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Compositing in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11639"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-11641",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.19995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Bluetooth in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11641"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-11483",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System archive4.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11483"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-11484",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System archive3.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11484"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-11485",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System archive2.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11485"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-11486",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System archive1.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11486"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-11488",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Simple Flight Ticket Booking System",
      "cwe": "CWE-74",
      "title": "code-projects Simple Flight Ticket Booking System POST Parameter checkUser.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11488"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-11489",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Online Music Site",
      "cwe": "CWE-74",
      "title": "code-projects Online Music Site AdminDeleteAlbum.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11489"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-46441",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-284",
      "title": "Flowise: Mass Assignment in Assistant Update Endpoint Allows Cross-Workspace Resource Reassignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46441"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-11512",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.19738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-79",
      "title": "itsourcecode Hospital Management System billing.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11512"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-11521",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00272,
      "epss_percentile": 0.19609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mohammed-eid35",
      "product": "bank-management-system-springboot",
      "cwe": "CWE-266",
      "title": "Mohammed-eid35 bank-management-system-springboot Transaction Endpoint TransactionController.java improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11521"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-11643",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.19591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11643"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-46657",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.19411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bludit",
      "product": "bludit",
      "cwe": "CWE-212",
      "title": "Bludit's persistent authentication tokens not revoked upon account disablement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46657"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-46443",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.19426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-200",
      "title": "Flowise: Credential Data Leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46443"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-11629",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11629"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-11532",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0027,
      "epss_percentile": 0.1928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "imvks786",
      "product": "student_management_system",
      "cwe": "CWE-266",
      "title": "imvks786 student_management_system Student Record add.php access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11532"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-11582",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Student Attendance Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Student Attendance Management System index.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11582"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-42863",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-284",
      "title": "Flowise: Mass Assignment in Chatflow Update Endpoint Allows Cross-Workspace AgentFlow Reassignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42863"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-49234",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Routinator",
      "cwe": "CWE-20",
      "title": "Routinator crashes on specifically crafted ASN strings in the API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49234"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-11632",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.1848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11632"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-11648",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in FullScreen in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11648"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-11471",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System index2.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11471"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-11472",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System index1.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11472"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-11501",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Hospitals Patient Records Management System",
      "cwe": "CWE-74",
      "title": "SourceCodester Hospitals Patient Records Management System Master.php save_patient sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11501"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-11637",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.1816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11637"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-11646",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.1816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ViewTransitions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11646"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-11519",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00261,
      "epss_percentile": 0.18053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Inventory System",
      "cwe": "CWE-266",
      "title": "SourceCodester Inventory System Account Creation users_handler.php improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11519"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-11660",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11660"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-11688",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-94",
      "title": "Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11688"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-42861",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.17187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-284",
      "title": "Flowise: Mass Assignment in Variable Update Endpoint Allows Cross-Workspace Resource Reassignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42861"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-11634",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00252,
      "epss_percentile": 0.16917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11634"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-11638",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00252,
      "epss_percentile": 0.16917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11638"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-11654",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00252,
      "epss_percentile": 0.16918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11654"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-11659",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00252,
      "epss_percentile": 0.16917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11659"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-11630",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11630"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-11657",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Payments in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11657"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-11664",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Payments in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11664"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-46440",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00251,
      "epss_percentile": 0.16836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-522",
      "title": "Flowise: Basic Auth Credentials Exposed via API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46440"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-43966",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ninenines",
      "product": "cowlib",
      "cwe": "CWE-113",
      "title": "HTTP Response Splitting via Non-VCHAR Bytes in cow_http_struct_hd:escape_string/2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43966"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-11502",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0025,
      "epss_percentile": 0.16709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "JeecgBoot",
      "cwe": "CWE-601",
      "title": "JeecgBoot Third-Party Login ThirdLoginController.java HttpServletResponse.sendRedirect redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11502"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-11520",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00248,
      "epss_percentile": 0.16359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Inventory System",
      "cwe": "CWE-79",
      "title": "SourceCodester Inventory System header.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11520"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-11611",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11",
      "cwe": "CWE-400",
      "title": "389-ds-base: 389-ds-base: content sync plugin unbounded queue growth and race conditions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11611"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-11671",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00243,
      "epss_percentile": 0.15774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11671"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-11673",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in InterestGroups in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11673"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-11674",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11674"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-11680",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Media in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11680"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-11652",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11652"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-11655",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11655"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-11661",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11661"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-46481",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-metadata",
      "product": "OpenMetadata",
      "cwe": "CWE-201",
      "title": "OpenMetadata: TEST_CONNECTION workflow leaks ingestion-bot JWT and database password to regular users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46481"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-11672",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11672"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-11633",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11633"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-11640",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11640"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-11642",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Web Apps in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11642"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-11676",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Dawn in Google Chrome on Linux and ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11676"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-25558",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QloApps",
      "product": "QloApps",
      "cwe": "CWE-79",
      "title": "QloApps 1.7.0 Stored XSS via SVG File Upload in Admin File Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25558"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-11533",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0023,
      "epss_percentile": 0.14038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "imvks786",
      "product": "student_management_system",
      "cwe": "CWE-266",
      "title": "imvks786 student_management_system Student Deletion Endpoint see.php improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11533"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-11653",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11653"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-11658",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Extensions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11658"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-11670",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11670"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-11493",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00224,
      "epss_percentile": 0.13318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "AC15",
      "cwe": "CWE-521",
      "title": "Tenda AC15 Samba smb.conf weak password",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11493"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-11491",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00223,
      "epss_percentile": 0.13201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Human Resource Management System",
      "cwe": "CWE-79",
      "title": "CodeAstro Human Resource Management System Notice Board Management All_notice cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11491"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-11631",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11631"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-11635",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11635"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-11647",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Printing in Google Chrome on Android prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11647"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-11663",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11663"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-11636",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11636"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-46307",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.12861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "wifi: ath5k: do not access array OOB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46307"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-11689",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.12528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11689"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-11665",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Dawn in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11665"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-49141",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArnasDon",
      "product": "wacrm",
      "cwe": "CWE-639",
      "title": "WACRM Authorization Bypass via Automation Engine Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49141"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-11667",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in WebRTC in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the GPU process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11667"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-11494",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00215,
      "epss_percentile": 0.12196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "AC1200 T8",
      "cwe": "CWE-266",
      "title": "TOTOLINK AC1200 T8 vsftpd vsftpd.conf least privilege violation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11494"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-11690",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read and write in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11690"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-11694",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11694"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-11666",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11666"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-11669",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Out of bounds read in Media in Google Chrome on ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11669"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-11476",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kushan2k",
      "product": "student-management-system",
      "cwe": "CWE-266",
      "title": "Kushan2k student-management-system Profile Update Endpoint AdminController.php edit-admin improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11476"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-11558",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Payroll System",
      "cwe": "CWE-74",
      "title": "CodeAstro Payroll System home_salary.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11558"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-49756",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00207,
      "epss_percentile": 0.11142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wojtekmach",
      "product": "req",
      "cwe": "CWE-93",
      "title": "Multipart form-data header injection in Req via unescaped name/filename/content_type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49756"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-3011",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.11029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpzoom",
      "product": "Recipe Card Blocks Lite",
      "cwe": "CWE-79",
      "title": "Recipe Card Blocks Lite <= 3.4.13 - Authenticated (Author+) Stored Cross-Site Scripting via 'summary' and 'notes'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3011"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-11554",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00206,
      "epss_percentile": 0.1098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "CP450",
      "cwe": "CWE-266",
      "title": "TOTOLINK CP450 vsftpd vsftpd.conf least privilege violation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11554"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-11529",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00205,
      "epss_percentile": 0.1082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "designcomputer",
      "product": "mysql-mcp-server",
      "cwe": "CWE-74",
      "title": "designcomputer mysql-mcp-server mysql URI server.py read_resource sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11529"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-11473",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jflyfox",
      "product": "jfinal_cms",
      "cwe": "CWE-74",
      "title": "jflyfox jfinal_cms AdvicefeedbackController.java list sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11473"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-11559",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.10761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Payroll System",
      "cwe": "CWE-74",
      "title": "CodeAstro Payroll System view_account.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11559"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-11583",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.10758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Student Attendance Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Student Attendance Management System createClass.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11583"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-11584",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.10761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Student Attendance Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Student Attendance Management System createClass.php edit sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11584"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-11697",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00203,
      "epss_percentile": 0.10563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11697"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-11681",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11681"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-11687",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Dawn in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11687"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-11698",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11698"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-11699",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11699"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-11644",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11644"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-11675",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Out of bounds read in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11675"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-11480",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chengdu Everbrite Network Technology",
      "product": "BeikeShop",
      "cwe": "CWE-74",
      "title": "Chengdu Everbrite Network Technology BeikeShop Admin Design Builder Endpoint admin.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11480"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-11495",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Ingredients Stock Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Ingredients Stock Management System add_stock.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11495"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-11506",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Leave Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Leave Management System search_staff_for_deletion.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11506"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-11507",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Leave Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Leave Management System delete_leave_type.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11507"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-11508",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Leave Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Leave Management System search_staff_to_assign_pc.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11508"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-11510",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Leave Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Leave Management System add_leave.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11510"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-11513",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System adminaccount.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11513"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-11514",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System addpatient.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11514"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-11585",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.1024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Student Attendance Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Student Attendance Management System createClassArms.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11585"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-11534",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.1003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "imvks786",
      "product": "student_management_system",
      "cwe": "CWE-79",
      "title": "imvks786 student_management_system add.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11534"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-11505",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00197,
      "epss_percentile": 0.09837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL.iNet",
      "product": "A1300",
      "cwe": "CWE-320",
      "title": "GL.iNet XE3000 glnassys hard-coded key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11505"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-10544",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-78",
      "title": "Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated user with write access to a vault to execute arbitrary commands on the systems managed by the affected PAM provider. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server 2026.1.20.0 and earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10544"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-42862",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00195,
      "epss_percentile": 0.09587,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlowiseAI",
      "product": "Flowise",
      "cwe": "CWE-284",
      "title": "Flowise: Mass Assignment in Tool Update Endpoint Allows Cross-Workspace Resource Reassignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42862"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-48507",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.09504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-863",
      "title": "Snipe-IT: Bulk editing users allowed `ldap_import` and `activated_in` bulk editing users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48507"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-11696",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Video in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11696"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-11668",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Codecs in Google Chrome on Linux, ChromeOS prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted video file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11668"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-11682",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00192,
      "epss_percentile": 0.09186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11682"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-11509",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Leave Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Leave Management System search_staff_for_updation.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11509"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-11511",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00191,
      "epss_percentile": 0.09118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bolt",
      "product": "CMS",
      "cwe": "CWE-74",
      "title": "Bolt CMS HTML Attribute TextType.php HTML injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11511"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-7765",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Checkmk GmbH",
      "product": "Checkmk",
      "cwe": "CWE-863",
      "title": "User Messages widget leaked issuer messages on shared dashboards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7765"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2021-47982",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "maxfoundry",
      "product": "WP-Paginate",
      "cwe": "CWE-79",
      "title": "WordPress Plugin WP-Paginate 2.1.3 Stored XSS via preset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-47982"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2021-47983",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mra13",
      "product": "Accept Stripe Payments",
      "cwe": "CWE-79",
      "title": "WordPress Plugin Stripe Payments 2.0.39 Stored XSS via currency_code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-47983"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2021-47984",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP24",
      "product": "WP24 Domain Check",
      "cwe": "CWE-79",
      "title": "WordPress Plugin WP24 Domain Check 1.6.2 Stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-47984"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2020-37248",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OfflineIMAP",
      "product": "OfflineIMAP",
      "cwe": "CWE-348",
      "title": "OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials in cleartext.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-37248"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-46275",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46275"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-11693",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.08324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11693"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2023-54351",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonaar",
      "product": "Sonaar Music Plugin",
      "cwe": "CWE-79",
      "title": "WordPress Sonaar Music Plugin 4.7 Stored XSS via Comments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-54351"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-48488",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00182,
      "epss_percentile": 0.08095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-328",
      "title": "phpMyFAQ has Weak Cryptography - SHA1 for Password Hashing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48488"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-11628",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Ozone in Google Chrome prior to 149.0.7827.103 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11628"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-11679",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00179,
      "epss_percentile": 0.07793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Codecs in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11679"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-11692",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00179,
      "epss_percentile": 0.07793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Read Anything in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11692"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-11700",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00179,
      "epss_percentile": 0.07793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11700"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-11701",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11701"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-44119",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HTTP Server",
      "cwe": "CWE-269",
      "title": "Apache HTTP Server: escalation of privilege through expressions in .htaccess in multiple modules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44119"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-11678",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11678"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-11685",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07549,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in MediaCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11685"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-11695",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07548,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11695"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-11684",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00171,
      "epss_percentile": 0.069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the utility process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11684"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-11686",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00171,
      "epss_percentile": 0.069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11686"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-11656",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00169,
      "epss_percentile": 0.06687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11656"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-11691",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00169,
      "epss_percentile": 0.06692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11691"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-43972",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ninenines",
      "product": "gun",
      "cwe": "CWE-346",
      "title": "gun HTTP/2 PUSH_PROMISE authority not validated against connection origin allows cross-origin cookie injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43972"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-11479",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0016,
      "epss_percentile": 0.05719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yoanbernabeu",
      "product": "grepai",
      "cwe": "CWE-327",
      "title": "yoanbernabeu grepai Qdrant Backend chunker.go weak hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11479"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-10787",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-862",
      "title": "Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server 2026.1.20.0 and earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10787"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-11677",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.0454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in Network in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the network process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11677"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-10786",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-312",
      "title": "Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server 2026.1.20.0 and earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10786"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-46294",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00143,
      "epss_percentile": 0.0406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "dm: fix a buffer overflow in ioctl processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46294"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-8078",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Checkmk GmbH",
      "product": "Checkmk",
      "cwe": "CWE-79",
      "title": "Fix stored XSS in global settings change log",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8078"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-9549",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Checkmk GmbH",
      "product": "Checkmk",
      "cwe": "CWE-79",
      "title": "Fix XSS in service discovery active check output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9549"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-8833",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.03876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Checkmk GmbH",
      "product": "Checkmk",
      "cwe": "CWE-79",
      "title": "XSS in urls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8833"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-46288",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "of: unittest: fix use-after-free in of_unittest_changeset()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46288"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-46281",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.0389,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "vmalloc: fix buffer overflow in vrealloc_node_align()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46281"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-46274",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "io-wq: check that the predecessor is hashed in io_wq_remove_pending()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46274"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-11569",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Quay 3",
      "cwe": "CWE-79",
      "title": "Quay: quay: stored xss via filedrop svg upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11569"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-7186",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.03513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Checkmk GmbH",
      "product": "Checkmk",
      "cwe": "CWE-79",
      "title": "Fix stored XSS in URL dashboard widget via dangerous URI schemes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7186"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-11475",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00133,
      "epss_percentile": 0.03307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kushan2k",
      "product": "student-management-system",
      "cwe": "CWE-74",
      "title": "Kushan2k student-management-system Certificate Verification Endpoint GradeController.php getStatus sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11475"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-46279",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-415",
      "title": "mm/alloc_tag: clear codetag for pages allocated before page_ext initialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46279"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-46280",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "lib: test_hmm: evict device pages on file close to avoid use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46280"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-46285",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.0267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "mtd: docg3: fix use-after-free in docg3_release()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46285"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-46293",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "clk: microchip: mpfs-ccc: fix out of bounds access during output registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46293"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-46309",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.0262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "drm/xe/uapi: Reject coh_none PAT index for CPU cached memory in madvise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46309"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-46276",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.0246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu: fix zero-size GDS range init on RDNA4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46276"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-46291",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: caam - guard HMAC key hex dumps in hash_digest_key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46291"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-46292",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-772",
      "title": "pmdomain: core: Fix detach procedure for virtual devices in genpd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46292"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-46282",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "iio: frequency: admv1013: fix NULL pointer dereference on str",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46282"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-46283",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tpm: Use kfree_sensitive() to free auth session in tpm_dev_release()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46283"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-46286",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "leds: qcom-lpg: Check for array overflow when selecting the high resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46286"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-46287",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-617",
      "title": "net: txgbe: fix RTNL assertion warning when remove module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46287"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-46284",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "mm/hugetlb: fix early boot crash on parameters without '=' separator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46284"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-46290",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "x86/efi: Fix graceful fault handling after FPU softirq changes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46290"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-46277",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/zone_device: do not touch device folio after calling ->folio_free()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46277"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-46301",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "spi: topcliff-pch: fix use-after-free on unbind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46301"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-34194",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-468",
      "title": "GPU DDK - UAF read and/or write to arbitrary physical pages in DevmemIntChangeSparse due to incorrect calculation of the virtual index count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34194"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-46308",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "pmdomain: mediatek: fix use-after-free in scpsys_get_bus_protection_legacy()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46308"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-46314",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-835",
      "title": "drm/v3d: Reject empty multisync extension to prevent infinite loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46314"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-46296",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "spi: s3c64xx: fix NULL-deref on driver unbind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46296"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-46312",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: videobuf2: Set vma_flags in vb2_dma_sg_mmap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46312"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-46313",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "media: intel/ipu6: fix error pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46313"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-11478",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00113,
      "epss_percentile": 0.01671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kokke",
      "product": "tiny-regex-c",
      "cwe": "CWE-400",
      "title": "kokke tiny-regex-c Pattern re.c matchstar redos",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11478"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-46311",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/amdgpu/userq: fix access to stale wptr mapping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46311"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2025-71315",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01587,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/vkms: Convert to DRM's vblank timer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71315"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-46295",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: x86: Do IRR scan in __kvm_apic_update_irr even if PIR is empty",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46295"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-46297",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: libwx: use request_irq for VF misc interrupt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46297"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-46310",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "media: renesas: vsp1: Fix NULL pointer deref on module unload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46310"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-46278",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "drm/imagination: Fix segfault when updating ftrace mask",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46278"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-45581",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hyperledger",
      "product": "fabric-chaincode-java",
      "cwe": "CWE-532",
      "title": "fabric-chaincode-java: TLS Private Key Password Disclosed in INFO Startup Logs in Chaincode-as-a-Service Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45581"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-46302",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.0098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "selinux: allow multiple opens of /sys/fs/selinux/policy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46302"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-46305",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.0098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "staging: rtl8723bs: os_dep: avoid NULL pointer dereference in rtw_cbuf_alloc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46305"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-46299",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00091,
      "epss_percentile": 0.00549,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "hfsplus: fix held lock freed on hfsplus_fill_super()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46299"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-11481",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00082,
      "epss_percentile": 0.00262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yoanbernabeu",
      "product": "grepai",
      "cwe": "CWE-327",
      "title": "yoanbernabeu grepai Postgres Embedding Cache chunker.go PostgresStore.LookupByContentHash weak hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11481"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-46298",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00074,
      "epss_percentile": 0.00086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "pseries/papr-hvpipe: Fix race with interrupt handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46298"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-35058",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-35058 (OpenVPN). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42861",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42861 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42862",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42862 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42863",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42863 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46441",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46441 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46442",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46442 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46443",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46443 (FlowiseAI Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46490",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46490 (tngan samlify). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49755",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49755 (wojtekmach req). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
