{
  "day": "2026-06-09",
  "boundary": "UTC calendar day",
  "published_count": 719,
  "by_severity": {
    "CRITICAL": 37,
    "HIGH": 348,
    "MEDIUM": 314,
    "LOW": 20
  },
  "kev_count": 3,
  "exploit_reference_count": 12,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-20245",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.25323,
      "epss_percentile": 0.97769,
      "kev": true,
      "kev_due_at": "2026-06-23",
      "vendor": "Cisco",
      "product": "Cisco Catalyst SD-WAN Controller",
      "cwe": "CWE-116",
      "title": "Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20245"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-11645",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0219,
      "epss_percentile": 0.81,
      "kev": true,
      "kev_due_at": "2026-06-23",
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Google Chromium V8",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11645"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-7473",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01108,
      "epss_percentile": 0.63262,
      "kev": true,
      "kev_due_at": "2026-06-23",
      "vendor": "Arista Networks",
      "product": "EOS",
      "cwe": "CWE-1023",
      "title": "Arista EOS Unexpected Tunnel Protocol Decapsulation and Forwarding Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7473"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-49160",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.53829,
      "epss_percentile": 0.98915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-400",
      "title": "HTTP.sys Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49160"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-10523",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.5187,
      "epss_percentile": 0.98859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ivanti",
      "product": "Sentry",
      "cwe": "CWE-288",
      "title": "An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10523"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-45484",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.35216,
      "epss_percentile": 0.98315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-502",
      "title": "Microsoft SharePoint Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45484"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-47291",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.2275,
      "epss_percentile": 0.97542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "HTTP.sys Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47291"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-45502",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.20255,
      "epss_percentile": 0.9726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-918",
      "title": "Microsoft Exchange Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45502"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-45657",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.15478,
      "epss_percentile": 0.96523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-122",
      "title": "Windows Kernel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45657"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-10727",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.13635,
      "epss_percentile": 0.9617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ivanti",
      "product": "Endpoint Manager Mobile",
      "cwe": "CWE-78",
      "title": "An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execute arbitrary commands as root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10727"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-50508",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.08678,
      "epss_percentile": 0.94685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-200",
      "title": "Windows NTLM Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50508"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-42980",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.06949,
      "epss_percentile": 0.93581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "NT OS Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42980"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-45447",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.05236,
      "epss_percentile": 0.91855,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-416",
      "title": "Heap Use-After-Free in the PKCS7_verify() Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45447"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-50507",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.05011,
      "epss_percentile": 0.91554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-306",
      "title": "Windows BitLocker Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50507"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-45586",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0363,
      "epss_percentile": 0.88607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-59",
      "title": "Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45586"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-47932",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.02547,
      "epss_percentile": 0.83744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-22",
      "title": "ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47932"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-45591",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0243,
      "epss_percentile": 0.82937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": ".NET 10.0",
      "cwe": "CWE-400",
      "title": "ASP.NET Core Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45591"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-44963",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02351,
      "epss_percentile": 0.8235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Veeam",
      "product": "Backup and Replication",
      "cwe": "CWE-502",
      "title": "A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44963"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-47928",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02319,
      "epss_percentile": 0.82088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-20",
      "title": "ColdFusion | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47928"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-42989",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0227,
      "epss_percentile": 0.81666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-59",
      "title": "Winlogon Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42989"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-47929",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.02092,
      "epss_percentile": 0.80137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-863",
      "title": "ColdFusion | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47929"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-42905",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.02004,
      "epss_percentile": 0.79192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42905"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-42986",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.02004,
      "epss_percentile": 0.79192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Microsoft Graphics Component Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42986"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-26142",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01914,
      "epss_percentile": 0.78184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Nuance PowerScribe 360 4.0",
      "cwe": "CWE-502",
      "title": "Nuance PowerScribe Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26142"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-45454",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0163,
      "epss_percentile": 0.74284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-22",
      "title": "Microsoft SharePoint Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45454"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-42985",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0126,
      "epss_percentile": 0.6724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Remote Desktop client for Windows Desktop",
      "cwe": "CWE-787",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42985"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-42835",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.01259,
      "epss_percentile": 0.67223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Teams for Android",
      "cwe": "CWE-74",
      "title": "Microsoft Teams for Android Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42835"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-8365",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01177,
      "epss_percentile": 0.65134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "creativethemeshq",
      "product": "Blocksy",
      "cwe": "CWE-502",
      "title": "Blocksy <= 2.1.41 - Authenticated (Contributor+) PHP Object Injection via Deserialization of Untrusted Data via 'blocksy_meta' REST API Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8365"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-42764",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01165,
      "epss_percentile": 0.64787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-476",
      "title": "NULL Pointer Dereference in QUIC Server Initial Packet Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42764"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-45648",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01124,
      "epss_percentile": 0.63675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows Server 2022",
      "cwe": "CWE-121",
      "title": "Windows Active Directory Domain Services Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45648"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-44815",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.011,
      "epss_percentile": 0.63065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-121",
      "title": "DHCP Client Service Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44815"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-42766",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0106,
      "epss_percentile": 0.61879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-476",
      "title": "Possible NULL Dereference in Password-Based CMS Decryption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42766"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-11572",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.01057,
      "epss_percentile": 0.61809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "degit",
      "cwe": "CWE-78",
      "title": "Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of user input for git shell commands directly invoked with exec() method by _cloneWithGit() and fetchRefs() functions. An attacker can execute arbitrary operating system commands as the process user by supplying a specially crafted git repository name.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11572"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-34183",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01049,
      "epss_percentile": 0.61569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-1325",
      "title": "Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34183"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-48573",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.01029,
      "epss_percentile": 0.6095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-1329",
      "title": "Secure Boot Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48573"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-48576",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.01028,
      "epss_percentile": 0.6094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-1329",
      "title": "Secure Boot Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48576"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-34180",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01025,
      "epss_percentile": 0.60858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-125",
      "title": "Heap Buffer Over-read in ASN.1 Content Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34180"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-36723",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00998,
      "epss_percentile": 0.60009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "An unrestricted file rename vulnerability in the /api/create-user component of bookcars v8.3 allows authenticated attackers to leverage directory traversal sequences to move arbitrary files from temporary storage to arbitrary locations on the server filesystem. This enables unauthorized access to sensitive files, the overwriting of critical application files, and remote code execution (RCE).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36723"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-47289",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00954,
      "epss_percentile": 0.58588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47289"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-49959",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00945,
      "epss_percentile": 0.58314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nesquena",
      "product": "hermes-webui",
      "cwe": "CWE-78",
      "title": "Hermes WebUI < 0.51.311 RCE via Git Configuration Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49959"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-48560",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00937,
      "epss_percentile": 0.58082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48560"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-47284",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00921,
      "epss_percentile": 0.57509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-200",
      "title": "Visual Studio Code Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47284"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-42903",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00903,
      "epss_percentile": 0.56974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-476",
      "title": "Windows Kerberos Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42903"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-42908",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00871,
      "epss_percentile": 0.56032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42908"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-45639",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00871,
      "epss_percentile": 0.56031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Remote Desktop client for Windows Desktop",
      "cwe": "CWE-125",
      "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45639"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-45504",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00846,
      "epss_percentile": 0.55208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-918",
      "title": "Microsoft Exchange Server Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45504"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-41098",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00831,
      "epss_percentile": 0.54753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Stack Edge",
      "cwe": "CWE-79",
      "title": "Azure Stack Edge Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41098"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-38615",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00816,
      "epss_percentile": 0.54287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38615"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-42907",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00816,
      "epss_percentile": 0.54292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-200",
      "title": "Windows Shell Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42907"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-42914",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00794,
      "epss_percentile": 0.53557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Kerberos Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42914"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-47287",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00787,
      "epss_percentile": 0.53341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-23",
      "title": "Visual Studio Code Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47287"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-40984",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00773,
      "epss_percentile": 0.52874,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Micrometer",
      "cwe": "CWE-400",
      "title": "Micrometer HTTP server instrumentations DoS vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40984"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-47281",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00759,
      "epss_percentile": 0.52446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-306",
      "title": "Visual Studio Code Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47281"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-47643",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00753,
      "epss_percentile": 0.52222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Stack Edge",
      "cwe": "CWE-610",
      "title": "Azure Stack Edge Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47643"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2025-71319",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00729,
      "epss_percentile": 0.51382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "image-size",
      "product": "image-size",
      "cwe": "CWE-835",
      "title": "image-size 2.0.2 Denial of Service via Infinite Loop in JXL/HEIF Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71319"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-7383",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00703,
      "epss_percentile": 0.50467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-787",
      "title": "Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7383"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-49818",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00695,
      "epss_percentile": 0.50156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow Samba provider",
      "cwe": "CWE-22",
      "title": "Apache Airflow Samba provider: Path traversal in GCSToSambaOperator via GCS object names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49818"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-45481",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00687,
      "epss_percentile": 0.49885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45481"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-40376",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00671,
      "epss_percentile": 0.49229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-20",
      "title": "Visual Studio Code Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40376"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2016-20064",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00671,
      "epss_percentile": 0.49227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "myasui",
      "product": "WP Vault",
      "cwe": "CWE-98",
      "title": "WP Vault 0.8.6.6 Local File Inclusion via wpv-image Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20064"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-47298",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00669,
      "epss_percentile": 0.49155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-285",
      "title": "Microsoft SharePoint Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47298"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-5067",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00643,
      "epss_percentile": 0.48047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject-rtos",
      "product": "Zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds read/write in HTTP WebSocket upgrade via non-null-terminated Sec-WebSocket-Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5067"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2017-20248",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00641,
      "epss_percentile": 0.4795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apptha",
      "product": "Apptha Slider Gallery",
      "cwe": "CWE-22",
      "title": "WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20248"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2017-20250",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00641,
      "epss_percentile": 0.47952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apptha",
      "product": "Mac Photo Gallery",
      "cwe": "CWE-22",
      "title": "WordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20250"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-42974",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0064,
      "epss_percentile": 0.479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-190",
      "title": "Windows Performance Monitor Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42974"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-42981",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0064,
      "epss_percentile": 0.479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-191",
      "title": "Windows Performance Monitor Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42981"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-40371",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0063,
      "epss_percentile": 0.4747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Dynamics 365 (on-premises) version 9.1",
      "cwe": "CWE-755",
      "title": "Microsoft Dynamics 365 (on-premises) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40371"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-45455",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00629,
      "epss_percentile": 0.47435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45455"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-40983",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00622,
      "epss_percentile": 0.47163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Micrometer",
      "cwe": "CWE-400",
      "title": "Micrometer gRPC server instrumentation DoS vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40983"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-45650",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00619,
      "epss_percentile": 0.46985,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Bing Search for Android",
      "cwe": "CWE-451",
      "title": "Microsoft Bing Search Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45650"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-9076",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00618,
      "epss_percentile": 0.46932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-125",
      "title": "Out-of-Bounds Read in CMS Password-Based Decryption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9076"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-45445",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00603,
      "epss_percentile": 0.46243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-325",
      "title": "AES-OCB IV Ignored on EVP_Cipher() Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45445"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-47653",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00602,
      "epss_percentile": 0.46158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-787",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47653"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-42987",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00589,
      "epss_percentile": 0.45566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows Server 2012",
      "cwe": "CWE-416",
      "title": "Windows Deployment Services (WDS) Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42987"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-49955",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00586,
      "epss_percentile": 0.45463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nesquena",
      "product": "hermes-webui",
      "cwe": "CWE-770",
      "title": "Hermes WebUI < 0.51.270 Resource Exhaustion via passkey/options",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49955"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-11788",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00583,
      "epss_percentile": 0.45306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11.7 E4S for RHEL 8",
      "cwe": "CWE-476",
      "title": "389-ds-base: 389-ds-base: null pointer dereference in deref control plugin ber parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11788"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-42768",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.0058,
      "epss_percentile": 0.45169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-514",
      "title": "Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42768"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-30141",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00573,
      "epss_percentile": 0.44836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in the DecodeLZW function allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via a crafted GIF file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30141"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2025-10263",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00571,
      "epss_percentile": 0.44733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arm",
      "product": "C1-Ultra",
      "cwe": "CWE-362",
      "title": "Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-10263"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-47930",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00569,
      "epss_percentile": 0.44622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-20",
      "title": "ColdFusion | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47930"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2017-20251",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00559,
      "epss_percentile": 0.4408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeisle",
      "product": "Woody Code Snippets",
      "cwe": "CWE-94",
      "title": "WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20251"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-47634",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00559,
      "epss_percentile": 0.44121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Server 2019",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47634"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-42767",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00557,
      "epss_percentile": 0.43995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-476",
      "title": "NULL Pointer Dereference in CRMF EncryptedValue Decryption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42767"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-45644",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00554,
      "epss_percentile": 0.43845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Live Share Canvas SDK",
      "cwe": "CWE-79",
      "title": "Microsoft Live Share Canvas SDK Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45644"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-48303",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00553,
      "epss_percentile": 0.43805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic (ACC)",
      "cwe": "CWE-863",
      "title": "Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48303"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-9662",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00551,
      "epss_percentile": 0.43734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "plasmatizemedia",
      "product": "Recover Exit For WooCommerce",
      "cwe": "CWE-98",
      "title": "Recover Exit For WooCommerce <= 1.0.3 - Unauthenticated Local File Inclusion via 'tpf' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9662"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-47654",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0055,
      "epss_percentile": 0.43642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows Server 2016",
      "cwe": "CWE-787",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47654"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-48563",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0055,
      "epss_percentile": 0.43642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-787",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48563"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-44803",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00522,
      "epss_percentile": 0.42137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Excel for Android",
      "cwe": "CWE-190",
      "title": "Windows Graphics Component Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44803"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-44812",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00522,
      "epss_percentile": 0.42137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Excel for Android",
      "cwe": "CWE-190",
      "title": "Windows Graphics Component Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44812"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-33113",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00522,
      "epss_percentile": 0.42086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33113"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-45599",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0052,
      "epss_percentile": 0.42011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows UPnP Device Host Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45599"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-45635",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0052,
      "epss_percentile": 0.42011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows UPnP Device Host Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45635"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-44822",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00518,
      "epss_percentile": 0.41883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Excel Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44822"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-36726",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00511,
      "epss_percentile": 0.41447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "An arbitrary file deletion vulnerability in the /api/delete-temp-license/{file} endpoint of bookcars v8.3 allows unauthenticated attackers to delete arbitrary files via supplying directory traversal sequences.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36726"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-41731",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0051,
      "epss_percentile": 0.41336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring for Apache Kafka",
      "cwe": "CWE-502",
      "title": "In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41731"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-45453",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0051,
      "epss_percentile": 0.41356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45453"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-45464",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0051,
      "epss_percentile": 0.41356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45464"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-45465",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0051,
      "epss_percentile": 0.41357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45465"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-47636",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0051,
      "epss_percentile": 0.41356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47636"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-47639",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0051,
      "epss_percentile": 0.41356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47639"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-42765",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00508,
      "epss_percentile": 0.41257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-476",
      "title": "NULL Dereference in Certificate Verification with OCSP Checking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42765"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-45462",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00505,
      "epss_percentile": 0.41065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45462"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-45467",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00505,
      "epss_percentile": 0.41067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45467"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-45468",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00505,
      "epss_percentile": 0.41067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45468"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-45479",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00505,
      "epss_percentile": 0.41067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45479"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-45483",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00505,
      "epss_percentile": 0.41066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft Office Project Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45483"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-47637",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00505,
      "epss_percentile": 0.41066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47637"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-47638",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00505,
      "epss_percentile": 0.41065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47638"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-47640",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00505,
      "epss_percentile": 0.41066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47640"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-47641",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00505,
      "epss_percentile": 0.41066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-20",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47641"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-48562",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00505,
      "epss_percentile": 0.41065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48562"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2025-52292",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.005,
      "epss_percentile": 0.40757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "A stack buffer overflow in the filein_process function (in_file.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-52292"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-47288",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00499,
      "epss_percentile": 0.40703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows Server 2012",
      "cwe": "CWE-190",
      "title": "Windows Kerberos Key Distribution Center (KDC) Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47288"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-33582",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00479,
      "epss_percentile": 0.3951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Answer",
      "cwe": "CWE-434",
      "title": "Apache Answer: Uploading specially crafted TIFF files causes an Out-of-Memory error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33582"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-45583",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00475,
      "epss_percentile": 0.39237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-94",
      "title": "Microsoft Exchange Server Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45583"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-42913",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00473,
      "epss_percentile": 0.39052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Remote Desktop client for Windows Desktop",
      "cwe": "CWE-362",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42913"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-42770",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00468,
      "epss_percentile": 0.38758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-325",
      "title": "FFC-DH Peer Validation Uses Attacker-Supplied q",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42770"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2025-52293",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00467,
      "epss_percentile": 0.38667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "A segmentation violaton in the gf_hevc_read_sps_bs_internal function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying crafted HEVC SPS data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-52293"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2025-55657",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00467,
      "epss_percentile": 0.38666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A NULL pointer dereference in the gf_odf_vvc_cfg_write_bs function (odf/descriptors.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55657"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-44821",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00465,
      "epss_percentile": 0.38556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44821"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-9698",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00464,
      "epss_percentile": 0.38487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HMBRAND",
      "product": "DBI",
      "cwe": "CWE-787",
      "title": "DBI versions before 1.648 for Perl saved errors in a limited-sized buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9698"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-42992",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00461,
      "epss_percentile": 0.38334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42992"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-44799",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00461,
      "epss_percentile": 0.38334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Remote Desktop client for Windows Desktop",
      "cwe": "CWE-122",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44799"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-44801",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00461,
      "epss_percentile": 0.38334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Remote Desktop client for Windows Desktop",
      "cwe": "CWE-787",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44801"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-44083",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0046,
      "epss_percentile": 0.38239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "QuMagie",
      "cwe": "CWE-639",
      "title": "QuMagie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44083"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-42971",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00459,
      "epss_percentile": 0.38174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-200",
      "title": "Windows Push Notification Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42971"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-42972",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00459,
      "epss_percentile": 0.38174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-200",
      "title": "Windows Hyper-V Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42972"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-47960",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00457,
      "epss_percentile": 0.38023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-611",
      "title": "ColdFusion | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47960"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-44819",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00455,
      "epss_percentile": 0.37903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44819"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-44824",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00455,
      "epss_percentile": 0.37903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44824"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-45471",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00455,
      "epss_percentile": 0.37902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-822",
      "title": "Microsoft Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45471"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-45475",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00455,
      "epss_percentile": 0.37903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45475"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-40128",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00454,
      "epss_percentile": 0.37866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP NetWeaver Application Server Java (Web Container)",
      "cwe": "CWE-35",
      "title": "Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40128"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-5068",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00452,
      "epss_percentile": 0.37676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject-rtos",
      "product": "Zephyr",
      "cwe": "CWE-787",
      "title": "bt: l2cap le coc: remote oob write via seg counter stored in net_buf user_data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5068"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-47938",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00449,
      "epss_percentile": 0.37496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic (ACC)",
      "cwe": "CWE-918",
      "title": "Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47938"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-49842",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "signalwire",
      "product": "freeswitch",
      "cwe": "CWE-400",
      "title": "FreeSWITCH: Pre-authentication bandwidth amplification via `mod_verto` speed-test frames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49842"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-48574",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.37215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Media Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48574"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-45503",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00445,
      "epss_percentile": 0.37215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-918",
      "title": "Microsoft Exchange Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45503"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2025-62858",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00445,
      "epss_percentile": 0.37197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "QTS",
      "cwe": "CWE-121",
      "title": "QTS, QuTS hero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62858"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-46316",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00441,
      "epss_percentile": 0.36909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-911",
      "title": "KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46316"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-47292",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0044,
      "epss_percentile": 0.36787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code - MSSQL Extension",
      "cwe": "CWE-94",
      "title": "Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47292"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-42904",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00438,
      "epss_percentile": 0.36666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-122",
      "title": "Windows TCP/IP Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42904"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-45456",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-843",
      "title": "Microsoft Outlook and Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45456"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-45458",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-416",
      "title": "Microsoft Outlook and Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45458"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-27671",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00437,
      "epss_percentile": 0.36549,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP NetWeaver AS ABAP and ABAP Platform",
      "cwe": "CWE-121",
      "title": "Memory Corruption vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27671"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-45485",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00437,
      "epss_percentile": 0.36604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45485"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-42993",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00434,
      "epss_percentile": 0.36362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-122",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42993"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-46746",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.3615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "SINEC INS",
      "cwe": "CWE-78",
      "title": "A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly sanitize user input in the /api/sftp/uploadFiles endpoint, allowing the injection of shell command payloads via crafted directory names. These payloads are stored and executed when directory listings are retrieved. This could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system with the privileges of the affected service user (sinecins).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46746"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-48565",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows Narrator Braille",
      "cwe": "CWE-426",
      "title": "Windows Narrator Braille Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48565"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-34711",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0043,
      "epss_percentile": 0.3605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "CAI Content Credentials",
      "cwe": "CWE-190",
      "title": "CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34711"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-44716",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pipecat-ai",
      "product": "pipecat",
      "cwe": "CWE-22",
      "title": "Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44716"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-45595",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00423,
      "epss_percentile": 0.35464,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-693",
      "title": "Windows Mark of the Web Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45595"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-46491",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00422,
      "epss_percentile": 0.35449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "simplesamlphp",
      "product": "simplesamlphp-module-casserver",
      "cwe": "CWE-22",
      "title": "SimpleSAMLphp casserver FileSystemTicketStore path traversal allows out-of-ticket-directory read/unserialize and conditional deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46491"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-49957",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00421,
      "epss_percentile": 0.35298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nesquena",
      "product": "hermes-webui",
      "cwe": "CWE-22",
      "title": "Hermes WebUI < 0.51.296 Workspace Boundary Bypass via api/workspace.py",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49957"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-42567",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00421,
      "epss_percentile": 0.35353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sveltejs",
      "product": "svelte",
      "cwe": "CWE-1333",
      "title": "Svelte: ReDoS in `<svelte:element>` Tag Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42567"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-45649",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00419,
      "epss_percentile": 0.35131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Excel for Android",
      "cwe": "CWE-284",
      "title": "Office for Android Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45649"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-49847",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.34722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "signalwire",
      "product": "freeswitch",
      "cwe": "CWE-674",
      "title": "FreeSWITCH: Stack overflow in bundled cJSON parser via deeply nested JSON",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49847"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-45655",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00413,
      "epss_percentile": 0.34587,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-693",
      "title": "Windows BitLocker Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45655"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-45636",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.3446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-20",
      "title": "Windows NTFS Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45636"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-34712",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00407,
      "epss_percentile": 0.34104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "CAI Content Credentials",
      "cwe": "CWE-20",
      "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34712"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-34713",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00407,
      "epss_percentile": 0.34105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "CAI Content Credentials",
      "cwe": "CWE-400",
      "title": "CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34713"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-25688",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00406,
      "epss_percentile": 0.34001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Answer",
      "cwe": "CWE-87",
      "title": "Apache Answer: XSS in AI Answer Rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25688"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-25699",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00406,
      "epss_percentile": 0.34001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Answer",
      "cwe": "CWE-359",
      "title": "Apache Answer: Authorization Bypass in Timeline API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25699"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-42906",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00404,
      "epss_percentile": 0.33802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-200",
      "title": "Windows Shell Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42906"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-42970",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00404,
      "epss_percentile": 0.33802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-200",
      "title": "Windows Push Notification Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42970"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-42973",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00404,
      "epss_percentile": 0.33802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-200",
      "title": "Windows Push Notification Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42973"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-45594",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00404,
      "epss_percentile": 0.33801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-200",
      "title": "Windows Application Identity (AppID) Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45594"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-9185",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sixstorage",
      "product": "6Storage Rentals",
      "cwe": "CWE-639",
      "title": "6Storage Rentals <= 2.22.0 - Unauthenticated Insecure Direct Object Reference to Arbitrary User Disclosure and Modification via 'userId' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9185"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-34031",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00403,
      "epss_percentile": 0.33757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Answer",
      "cwe": "CWE-434",
      "title": "Apache Answer: The custom avatar was not properly validated",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34031"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-11618",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00401,
      "epss_percentile": 0.33472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DTStack",
      "product": "Taier",
      "cwe": "CWE-287",
      "title": "DTStack Taier Source Connection Test Endpoint LoginInterceptor.java preHandle improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11618"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-42769",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00401,
      "epss_percentile": 0.3352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-295",
      "title": "Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42769"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-41842",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00399,
      "epss_percentile": 0.33231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-400",
      "title": "Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41842"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-36779",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain multiple stack overflows in the fromVirtualSer function via the puVar2, puVar1, __s2, __s1_00, and puVar3 parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36779"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-36783",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.33102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in the domain parameter of the fromNetToolGet function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36783"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-36791",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.33102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda O3v3 v1.0.0.5 was discovered to contain a stack overflow in the save_list_data parameter of the formSetCfm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36791"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-36792",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.33102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the wl_radio parameter of the formWifiRadioSet function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36792"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-36793",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.33101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain multiple stack overflows in the formwrlSSIDset function via the mit_ssid and mis_ssid_index parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36793"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-36794",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.33101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain multiple stack overflows in the R7WebsSecurityHandler function via the username and password parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36794"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-36796",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.33101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a stack overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36796"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-36797",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a stack overflow in the IPMacBindRuleIp parameter of the formIPMacBindModify function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36797"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-36799",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.33101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow in the portalAuth parameter of the formPortalAuth function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36799"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-42909",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.33047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Remote Desktop client for Windows Desktop",
      "cwe": "CWE-787",
      "title": "Remote Desktop Client Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42909"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-9213",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00397,
      "epss_percentile": 0.33112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "MR70",
      "cwe": "CWE-20",
      "title": "Insufficient input validation in certain NETGEAR routers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9213"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-49841",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00394,
      "epss_percentile": 0.32798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "signalwire",
      "product": "freeswitch",
      "cwe": "CWE-122",
      "title": "FreeSWITCH: Pre-authentication heap buffer overflow in `mod_verto` HTTP POST body read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49841"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-41729",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Data REST",
      "cwe": "CWE-917",
      "title": "Spring Data REST SpEL Injection via Map Key in JSON Patch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41729"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-42570",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sveltejs",
      "product": "devalue",
      "cwe": "CWE-770",
      "title": "Svelte devalue: DoS via sparse array deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42570"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-45461",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0039,
      "epss_percentile": 0.32322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-787",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45461"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-42968",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00388,
      "epss_percentile": 0.32098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Telephony Server Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42968"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-42969",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00388,
      "epss_percentile": 0.32099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-908",
      "title": "Windows Push Notification Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42969"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-45491",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00388,
      "epss_percentile": 0.32162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": ".NET 10.0",
      "cwe": "CWE-59",
      "title": ".NET Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45491"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-48566",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00388,
      "epss_percentile": 0.32098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-125",
      "title": "Windows DWM Core Library Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48566"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-45490",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": ".NET 10.0",
      "cwe": "CWE-285",
      "title": ".NET SDK Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45490"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-42915",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00383,
      "epss_percentile": 0.31586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-131",
      "title": "Microsoft Windows VMSwitch Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42915"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-45606",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00383,
      "epss_percentile": 0.31586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Microsoft UxTheme Library (uxtheme.dll) Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45606"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-45500",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00375,
      "epss_percentile": 0.30758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-79",
      "title": "Microsoft Exchange Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45500"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-45446",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00374,
      "epss_percentile": 0.30647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-325",
      "title": "Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45446"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-50635",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.30502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LimeSurvey",
      "product": "LimeSurvey",
      "cwe": "CWE-640",
      "title": "LimeSurvey Password Reset Host Header Injection Discloses Reset Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50635"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-44817",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.30439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-843",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44817"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-44820",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.30441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44820"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-44823",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.30439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-197",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44823"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-45457",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.30441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-125",
      "title": "Microsoft Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45457"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-45469",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.3044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45469"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-45486",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.3044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-416",
      "title": "Microsoft Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45486"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-45643",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.3044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-822",
      "title": "Microsoft Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45643"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-45645",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.30439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-787",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45645"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-34033",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00372,
      "epss_percentile": 0.30524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Answer",
      "cwe": "CWE-79",
      "title": "Apache Answer: HTML Content Injection in Email",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34033"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-53673",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BuddyPress",
      "product": "BuddyPress",
      "cwe": "CWE-639",
      "title": "BuddyPress 14.4.0 Private Message IDOR via REST API user_id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53673"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-45459",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00371,
      "epss_percentile": 0.30396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-693",
      "title": "Microsoft Excel Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45459"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-45466",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00371,
      "epss_percentile": 0.30397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-122",
      "title": "Microsoft Word Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45466"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-36778",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0037,
      "epss_percentile": 0.30239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in the username parameter of the R7WebsSecurityHandler function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36778"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2009-10007",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.30122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ETHER",
      "product": "Catalyst::Plugin::Authentication",
      "cwe": "CWE-384",
      "title": "Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2009-10007"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-34182",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00368,
      "epss_percentile": 0.3002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-354",
      "title": "CMS AuthEnvelopedData Processing May Accept Forged Messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34182"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-9750",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00368,
      "epss_percentile": 0.30015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-617",
      "title": "Metadata name collision on $-prefixed fields causes post-auth server crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9750"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-53674",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00367,
      "epss_percentile": 0.29944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BuddyPress",
      "product": "BuddyPress",
      "cwe": "CWE-943",
      "title": "BuddyPress 14.4.0 REGEXP Injection via @Mention Username Resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53674"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-45602",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00366,
      "epss_percentile": 0.29812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-349",
      "title": "Windows Dynamic Host Configuration Protocol (DHCP) Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45602"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-36727",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00364,
      "epss_percentile": 0.29678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-287",
      "title": "An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36727"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-45463",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00364,
      "epss_percentile": 0.29607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-121",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45463"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-45472",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00364,
      "epss_percentile": 0.29607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-787",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45472"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-45474",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00364,
      "epss_percentile": 0.29636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-787",
      "title": "Microsoft Office Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45474"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-41695",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.29582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Data Commons",
      "cwe": "CWE-400",
      "title": "Denial of Service in Spring Data Commons Property Path Resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41695"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-41716",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.29583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Data Commons",
      "cwe": "CWE-770",
      "title": "Spring Data web support unbounded negative-result cache keyed on attacker-supplied property names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41716"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-45634",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00362,
      "epss_percentile": 0.29472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows DHCP Client Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45634"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-41850",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.29213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-407",
      "title": "Spring Framework Algorithmic Denial of Service via SpEL Expressions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41850"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-41851",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.29214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-770",
      "title": "Spring Framework Denial of Service via Unbounded Cache in SpEL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41851"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-48288",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.0036,
      "epss_percentile": 0.29229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-20",
      "title": "Adobe Experience Manager | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48288"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-34691",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.29056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager Forms JEE",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34691"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-50636",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.29008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LimeSurvey",
      "product": "LimeSurvey",
      "cwe": "CWE-89",
      "title": "LimeSurvey RemoteControl invite_participants/remind_participants SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50636"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-45607",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00357,
      "epss_percentile": 0.2889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows Hyper-V Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45607"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-3088",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00357,
      "epss_percentile": 0.28973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "RBR860",
      "cwe": "CWE-787",
      "title": "Unauthenticated users can disrupt router operation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3088"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-45460",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00357,
      "epss_percentile": 0.28892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-126",
      "title": "Microsoft Office Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45460"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-44805",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00356,
      "epss_percentile": 0.28877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows Server 2019",
      "cwe": "CWE-416",
      "title": "Windows Network Controller (NC) Host Agent Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44805"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-49738",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00356,
      "epss_percentile": 0.28805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "TYPO3 CMS",
      "cwe": "CWE-22",
      "title": "TYPO3 CMS - Broken Access Control in File Abstraction Layer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49738"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-45658",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00353,
      "epss_percentile": 0.28485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-284",
      "title": "Windows BitLocker Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45658"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-47631",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00353,
      "epss_percentile": 0.28553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-79",
      "title": "Microsoft Exchange Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47631"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-48569",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0035,
      "epss_percentile": 0.28232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Visual Studio Code",
      "cwe": "CWE-20",
      "title": "Visual Studio Code Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48569"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-10731",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00349,
      "epss_percentile": 0.28136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nemon",
      "product": "Nemon Trade Energy",
      "cwe": "CWE-89",
      "title": "SQL injection in Nemon products",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10731"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-46325",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00347,
      "epss_percentile": 0.27901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/rxe: Fix iova-to-va conversion for MR page sizes != PAGE_SIZE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46325"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-9742",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-1287",
      "title": "Authenticate command with specific mechanism parameter can trigger server crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9742"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-41732",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring for Apache Pulsar",
      "cwe": "CWE-502",
      "title": "In Spring for Apache Pulsar, overly broad trusted-package matching in header mapper exposes JDK classes to deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41732"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-46541",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nimiq",
      "product": "core-rs-albatross",
      "cwe": "CWE-754",
      "title": "Nimiq network-libp2p: DHT query poisoning via first-record verification failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46541"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-9740",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.2762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-674",
      "title": "Unbounded recursion in BSONColumn interleaved-reference causes pre-auth stack overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9740"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-45482",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Visual Studio Code CoPilot Chat Extension",
      "cwe": "CWE-22",
      "title": "Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45482"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2025-55659",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A NULL pointer dereference in the ctts_box_write function (isomedia/box_code_base.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55659"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-45771",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "signalwire",
      "product": "freeswitch",
      "cwe": "CWE-776",
      "title": "Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45771"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-47652",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.2723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-122",
      "title": "Windows Hyper-V Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47652"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-41843",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00341,
      "epss_percentile": 0.27246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-22",
      "title": "Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41843"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-45604",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00341,
      "epss_percentile": 0.27224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-125",
      "title": "Windows Managed Installer Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45604"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-40404",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40404"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-46545",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nimiq",
      "product": "core-rs-albatross",
      "cwe": "CWE-248",
      "title": "nimiq-primitives: Panic DoS in trie chunk processing via ROOT-keyed item",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46545"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-45608",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00338,
      "epss_percentile": 0.26814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-125",
      "title": "Windows DHCP Client Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45608"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-32193",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00336,
      "epss_percentile": 0.2666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Kubernetes Service",
      "cwe": "CWE-22",
      "title": "Azure Kubernetes Service (AKS) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32193"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-44634",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00333,
      "epss_percentile": 0.26272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "simpleble",
      "product": "simpleble",
      "cwe": "CWE-121",
      "title": "Stack buffer overflows in SimpleBLE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44634"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-47635",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00333,
      "epss_percentile": 0.26345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Office LTSC 2024",
      "cwe": "CWE-122",
      "title": "Microsoft Outlook and Word Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47635"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-40988",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00331,
      "epss_percentile": 0.26118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Security",
      "cwe": "CWE-400",
      "title": "Unbounded DEFLATE Inflation in SAML 2.0 Service Provider",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40988"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-41721",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Data Commons",
      "cwe": "CWE-400",
      "title": "Spring Data Commons Denial of Service via Data Binding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41721"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-47912",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47912"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-47913",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47913"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-47914",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47914"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-50511",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft PC Manager",
      "cwe": "CWE-59",
      "title": "Microsoft PC Manager Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50511"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-36770",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda US_W3V1.0BR v1.0.0.3 was discovered to contain a stack overflow in the Go parameter of the ask_to_reboot function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36770"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-36771",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the wl_radio parameter of the formwrlSSIDset function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36771"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-36784",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in the ip parameter of the fromNetToolGet function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36784"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-41717",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Data MongoDB",
      "cwe": "CWE-917",
      "title": "Spring Data MongoDB - SpEL Expression Injection via Annotated Query Parameter Binding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41717"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-42828",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.25526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-126",
      "title": "Windows Projected File System Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42828"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-42837",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.25527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-125",
      "title": "Windows Projected File System Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42837"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-42916",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.25526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "title": "NT OS Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42916"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-34905",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.25461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Answer",
      "cwe": "CWE-200",
      "title": "Apache Answer: Unlisted Questions Accessible via Direct API Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34905"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-45476",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Linux kernel - Microsoft MANA Network Driver",
      "cwe": "CWE-416",
      "title": "Microsoft Azure Network Adapter Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45476"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-24065",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Waves Audio Ltd.",
      "product": "Waves Central",
      "cwe": "CWE-367",
      "title": "Local Privilege Escalation via Insecure XPC Client Validation in Waves Central for macOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24065"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-9748",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-617",
      "title": "$_internalConvertBucketIndexStats may crash the mongod server when working on no timeseries input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9748"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-0413",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.2516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "RBE370",
      "cwe": "CWE-121",
      "title": "Buffer overflow vulnerability in certain NETGEAR Nighthawk routers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0413"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-26236",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.2506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "QuMagie",
      "cwe": "CWE-862",
      "title": "QuMagie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26236"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-36719",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.25042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "An information disclosure vulnerability in the /api/v1/user/info endpoint of AgentChat v2.3.0 allows unauthenticated attackers to obtain sensitive information, including SHA256 password hashes, via enumerating user IDs.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36719"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-42573",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sveltejs",
      "product": "svelte",
      "cwe": "CWE-79",
      "title": "Svelte: XSS via DOM Clobbering of Internal Framework State",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42573"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-45642",
      "cvss_base": 3.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00319,
      "epss_percentile": 0.24815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-20",
      "title": "Microsoft Azure Attestation service and Device Health Attestation Service Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45642"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-44814",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.2461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 26H1",
      "cwe": "CWE-122",
      "title": "Windows DWM Core Library Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44814"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-41848",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-1333",
      "title": "Spring Framework Denial of Service via AntPathMatcher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41848"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-49742",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.24091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "TYPO3 CMS",
      "cwe": "CWE-22",
      "title": "TYPO3 CMS - Broken Access Control in Media Module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49742"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-41841",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-524",
      "title": "Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41841"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-49840",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0031,
      "epss_percentile": 0.23733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "signalwire",
      "product": "freeswitch",
      "cwe": "CWE-20",
      "title": "FreeSWITCH: Pre-authentication heap buffer overflow in libesl `Content-Length` parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49840"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-33828",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-501",
      "title": "Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33828"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-45654",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-284",
      "title": "Secure Boot Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45654"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-36800",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow in the IPMacBindIndex parameter of the formIPMacBindDel function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36800"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-36801",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow in the IPMacBindRule parameter of the formIPMacBindAdd function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36801"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-36802",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda PW201A v1.0.5 was discovered to contain a buffer overflow in the page parameter of the SafeMacFilter function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36802"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-36803",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda PW201A v1.0.5 was discovered to contain a buffer overflow in the page parameter of the qossetting function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36803"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-36805",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain multiple buffer overflows in the Saveqqlist function via the qqStr and markStr parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36805"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-36806",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthUserPwd parameter of the formModifyWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36806"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-36807",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthUserPwd parameter of the formAddWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36807"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-36808",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthUserInfo parameter of the formAddWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36808"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-36809",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthWhiteID parameter of the formModifyWebAuthWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36809"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-36810",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the gotoUrl parameter of the formPortalAuth function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36810"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-36811",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the picName parameter of the formDelwebAuthPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36811"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-36813",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36813"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-36815",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the hostname parameter of the formSetNetCheckTools function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36815"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-36816",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter of the formAddWewifiWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36816"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-36817",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthWhiteUserInfo parameter of the formAddWebAuthWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36817"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-36818",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter of the formAddWewifiWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36818"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-36819",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the bindMACAddr parameter of the fromSetDhcpRules function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36819"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-36820",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the webAuthWhiteUserInfo parameter of the formAddWebAuthWhiteUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36820"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-36821",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36821"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-36822",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the macAddr parameter of the formDelStaState function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36822"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-36823",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the webAuthUserInfo parameter of the formAddWebAuthUser function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36823"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-45501",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23549,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Server 2016 Cumulative Update 23",
      "cwe": "CWE-79",
      "title": "Microsoft Exchange Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45501"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-45641",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-125",
      "title": "Windows Hyper-V Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45641"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-45656",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-693",
      "title": "UEFI Secure Boot Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45656"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-47915",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47915"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-47917",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47917"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-9743",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB server",
      "cwe": "CWE-476",
      "title": "Aggregation sub-pipeline null dereference may allow DoS via crafted getMore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9743"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-41728",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00306,
      "epss_percentile": 0.23276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Data REST",
      "cwe": "CWE-284",
      "title": "Spring Data REST JSON Patch bypasses Jackson read-only property protection on nested objects and collections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41728"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-45588",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.23058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-693",
      "title": "Secure Boot Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45588"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-47656",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.23057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-693",
      "title": "Windows Boot Manager Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47656"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-48568",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.23058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-693",
      "title": "Secure Boot Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48568"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-48570",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.23057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-693",
      "title": "Secure Boot Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48570"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-48575",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.23057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-693",
      "title": "Secure Boot Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48575"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-35188",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.22891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-415",
      "title": "Double-free When Checking OCSP Stapled Response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35188"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-36798",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00301,
      "epss_percentile": 0.22753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain multiple stack overflows in the formSetDebugCfgr function via the enable, level, and module parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36798"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-46411",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00301,
      "epss_percentile": 0.22764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "halfgaar",
      "product": "FlashMQ",
      "cwe": "CWE-248",
      "title": "FlashMQ: Client can trigger uncaught exception on FlashMQ 1.26.1 and older",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46411"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-41007",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00299,
      "epss_percentile": 0.22546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring HATEOAS",
      "cwe": "CWE-770",
      "title": "Spring HATEOAS heap exhaustion through unbounded internal caching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41007"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-34693",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager Forms JEE",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager Forms JEE | Cross-site Scripting (Reflected XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34693"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-40409",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-197",
      "title": "Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40409"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-9753",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-787",
      "title": "Server crash via malformed binary diff passed to $_internalApplyOplogUpdate.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9753"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-47918",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47918"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-47919",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.22301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47919"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-44505",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00297,
      "epss_percentile": 0.22392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nimiq",
      "product": "core-rs-albatross",
      "cwe": "CWE-755",
      "title": "Nimiq network-libp2p: Untrusted peer can wedge DHT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44505"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2025-55658",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00296,
      "epss_percentile": 0.22213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-1077",
      "title": "GPAC MP4Box v2.4 was discovered to contain a floating point exception in the gf_opus_parse_packet_header function (media_tools/av_parsers.c). bThis vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55658"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-41726",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00296,
      "epss_percentile": 0.22218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring for Apache Kafka",
      "cwe": "CWE-770",
      "title": "In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41726"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2017-20249",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.2209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apptha",
      "product": "Apptha Slider Gallery",
      "cwe": "CWE-89",
      "title": "WordPress Plugin Apptha Slider Gallery 1.0 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20249"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-47347",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "TYPO3 CMS",
      "cwe": "CWE-601",
      "title": "TYPO3 CMS - Open Redirect in Core Utilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47347"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-47924",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47924"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-25860",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frankverbeke",
      "product": "OpenClinic GA",
      "cwe": "CWE-79",
      "title": "OpenClinic GA 5.351.19 Reflected XSS via DICOM Image Upload Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25860"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-41092",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-284",
      "title": "Microsoft Kinect Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41092"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-42829",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-284",
      "title": "Windows Administrator Protection Secure Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42829"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-42902",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft PowerToys",
      "cwe": "CWE-285",
      "title": "Microsoft PowerToys Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42902"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-46543",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nimiq",
      "product": "core-rs-albatross",
      "cwe": "CWE-617",
      "title": "nimiq-blockchain: Genesis batch set request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46543"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-11790",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11",
      "cwe": "CWE-400",
      "title": "389-ds-base: 389-ds-base: pbkdf2 password storage plugin unbounded iteration count denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11790"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-49948",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.21533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mem0ai",
      "product": "mem0",
      "cwe": "CWE-862",
      "title": "Mem0 0.2.8 Missing Authorization via POST /configure Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49948"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-36724",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An uncaught exception in the /application/job/update/{id} endpoint of FastapiAdmin v2.2.0 allows authenticated attackers with the module_task:job:update permission to cause a Denial of Service (DoS) via manipulating the func field of scheduled tasks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36724"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-0419",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "JR6150",
      "cwe": "CWE-20",
      "title": "Insufficient input validation vulnerability in NETGEAR JR6150",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0419"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-42910",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-787",
      "title": "Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42910"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-42983",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42983"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-45592",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.2122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-190",
      "title": "Windows Internet (wininet.dll) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45592"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-45593",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-190",
      "title": "Windows SDK Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45593"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-45600",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-843",
      "title": "Windows Kernel-Mode Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45600"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-45605",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Bluetooth Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45605"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-45637",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Microsoft DWM Core Library Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45637"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-45638",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45638"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-11620",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "EX200",
      "cwe": "CWE-266",
      "title": "TOTOLINK EX200 vsftpd vsftpd.conf least privilege violation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11620"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-49843",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00284,
      "epss_percentile": 0.20989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "signalwire",
      "product": "freeswitch",
      "cwe": "CWE-287",
      "title": "FreeSWITCH: Pre-authentication session eviction via attacker-chosen `sessid` in `mod_verto`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49843"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-11789",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11",
      "cwe": "CWE-191",
      "title": "389-ds-base: 389-ds-base: smd5 password storage plugin salt length integer underflow crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11789"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-47939",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47939"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-47941",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47941"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-47942",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47942"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-47943",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47943"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-47945",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47945"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-47948",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47948"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-47970",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47970"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-11793",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11",
      "cwe": "CWE-121",
      "title": "389-ds-base: 389-ds-base: stack buffer overflow in checkprefix() algorithm id parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11793"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-48291",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Format Plugins",
      "cwe": "CWE-122",
      "title": "Format Plugins | Heap-based Buffer Overflow (CWE-122)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48291"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-48292",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Format Plugins",
      "cwe": "CWE-122",
      "title": "Format Plugins | Heap-based Buffer Overflow (CWE-122)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48292"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-47923",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-125",
      "title": "Acrobat Reader | Out-of-bounds Read (CWE-125)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47923"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-41710",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Retry",
      "cwe": "CWE-770",
      "title": "Cache Exhaustion in Stateful Retries leads to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41710"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-41711",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Data Commons",
      "cwe": "CWE-400",
      "title": "Potential Denial of Service through crafted Sort Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41711"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-6445",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Everpure",
      "product": "FlashArray",
      "cwe": "CWE-939",
      "title": "A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information to an authenticated user with low privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6445"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-6444",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Everpure",
      "product": "FlashArray",
      "cwe": "CWE-639",
      "title": "A flaw exists in the FlashArray Purity management interface where an authenticated low-privileged user may, under specific conditions, access functionality beyond their assigned privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6444"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-49475",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "signalwire",
      "product": "freeswitch",
      "cwe": "CWE-20",
      "title": "FreeSWITCH: Out-of-bounds memory access in core STUN attribute parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49475"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-0411",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "RBE970",
      "cwe": "CWE-200",
      "title": "A Sensitive Information Disclosure Vulnerability in NETGEAR Orbi Satellites",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0411"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-47911",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-787",
      "title": "Acrobat Reader | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47911"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-41006",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring HATEOAS",
      "cwe": "CWE-284",
      "title": "Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41006"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-7486",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00275,
      "epss_percentile": 0.19977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcad Software Inc.",
      "product": "E-İmar",
      "cwe": "CWE-89",
      "title": "SQLi in Netcad's E-İmar",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7486"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-8025",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00275,
      "epss_percentile": 0.19977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MOSK Information Technologies Ltd.",
      "product": "CBS Platform",
      "cwe": "CWE-89",
      "title": "SQLi in MOSK Informatics' CBS Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8025"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-11616",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.19982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stiofansisland",
      "product": "Events Calendar for GeoDirectory",
      "cwe": "CWE-269",
      "title": "Events Calendar for GeoDirectory <= 2.3.28 - Authenticated (Subscriber+) Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11616"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-41108",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-122",
      "title": "Windows DNS Client Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41108"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-8499",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.19732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "helpfulcrowd",
      "product": "Helpfulcrowd Product Reviews",
      "cwe": "CWE-843",
      "title": "Helpfulcrowd Product Reviews <= 1.2.9 - Inccorect Authorization via Type Juggling in 'token' Parameter to Arbitrary Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8499"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-49956",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nesquena",
      "product": "hermes-webui",
      "cwe": "CWE-862",
      "title": "Hermes WebUI < 0.51.269 Profile Isolation Bypass via sessions search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49956"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2016-20062",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ollie Armstrong",
      "product": "Simply Poll",
      "cwe": "CWE-89",
      "title": "Simply Poll 1.4.1 Plugin for WordPress SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20062"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2016-20065",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EvWill",
      "product": "Product Catalog 8",
      "cwe": "CWE-89",
      "title": "Product Catalog 8 1.2 Plugin WordPress SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20065"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2017-20244",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wow-Company",
      "product": "Wow Forms",
      "cwe": "CWE-89",
      "title": "Wow Forms WordPress Plugin 2.1 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20244"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2017-20245",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wow-Company",
      "product": "Wow Viral Signups",
      "cwe": "CWE-89",
      "title": "Wow Viral Signups 2.1 WordPress Plugin SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20245"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2017-20246",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Missilesilo",
      "product": "KittyCatfish",
      "cwe": "CWE-89",
      "title": "KittyCatfish 2.2 Plugin for WordPress SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20246"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-9279",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "logseq",
      "product": "logseq",
      "cwe": "CWE-78",
      "title": "Shell command injection in Logseq",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9279"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-9746",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-617",
      "title": "Server crashes in case of the use of exchange",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9746"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-9747",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-617",
      "title": "Crafted cross-shard merge aggregation crashes MongoDB Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9747"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-9749",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-617",
      "title": "Using MaxKey() may crash the server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9749"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-9752",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-476",
      "title": "GeometryCollection with strict-winding polygon causes server crash during 2dsphere index key generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9752"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-9212",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "LBR1020",
      "cwe": "CWE-20",
      "title": "Insufficient authentication and input validation in certain NETGEAR products",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9212"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-47348",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "TYPO3 CMS",
      "cwe": "CWE-79",
      "title": "TYPO3 CMS - Cross-Site Scripting in Indexed Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47348"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-36721",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00268,
      "epss_percentile": 0.19107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-347",
      "title": "A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36721"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-41855",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00268,
      "epss_percentile": 0.19042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-502",
      "title": "Spring Framework Unsafe Deserialization via Jackson JMS Converters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41855"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-48578",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-284",
      "title": "Secure Boot Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48578"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-44802",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44802"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-44804",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 26H1",
      "cwe": "CWE-416",
      "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44804"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-44807",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 26H1",
      "cwe": "CWE-416",
      "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44807"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-44808",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 26H1",
      "cwe": "CWE-416",
      "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44808"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-44809",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 Version 24H2",
      "cwe": "CWE-416",
      "title": "Windows Common Log File System Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44809"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-44811",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 26H1",
      "cwe": "CWE-416",
      "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44811"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-44813",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18939,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 26H1",
      "cwe": "CWE-416",
      "title": "Windows DWM Core Library Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44813"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-48583",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48583"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-41849",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-190",
      "title": "Spring Framework Denial of Service via Integer Overflow in SpEL Expressions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41849"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-46373",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sqlfluff",
      "product": "sqlfluff",
      "cwe": "CWE-674",
      "title": "SQLFluff: Recursive Stack Overflow in Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46373"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-46374",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sqlfluff",
      "product": "sqlfluff",
      "cwe": "CWE-400",
      "title": "SQLFluff: Uncontrolled Resource Consumption in Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46374"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-44818",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-362",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44818"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2017-20243",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuanticaLabs",
      "product": "Car Park Booking System",
      "cwe": "CWE-89",
      "title": "WordPress Car Park Booking Plugin SQL Injection via space_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20243"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2017-20247",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apptha",
      "product": "PICA Photo Gallery",
      "cwe": "CWE-89",
      "title": "WordPress Plugin PICA Photo Gallery 1.0 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20247"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-41696",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.18163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Data MongoDB",
      "cwe": "CWE-943",
      "title": "Spring Data MongoDB Bind Parameter Literal Quoting Breakout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41696"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-48289",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00262,
      "epss_percentile": 0.18188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-20",
      "title": "Adobe Experience Manager | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48289"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-44810",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.18011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-287",
      "title": "Microsoft Cryptographic Services Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44810"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-47946",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47946"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-47947",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47947"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-48258",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48258"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-48265",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48265"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-48266",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48266"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-48271",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48271"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-48280",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48280"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-46540",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nimiq",
      "product": "core-rs-albatross",
      "cwe": "CWE-841",
      "title": "Nimiq light-blockchain: Light blockchain rebranch issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46540"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-11792",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00258,
      "epss_percentile": 0.1771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11",
      "cwe": "CWE-122",
      "title": "389-ds-base: 389-ds-base: heap buffer overflow in audit log password masking (create_masked_entry_string)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11792"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-50512",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft PC Manager",
      "cwe": "CWE-306",
      "title": "Microsoft PC Manager Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50512"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-41720",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring LDAP",
      "cwe": "CWE-287",
      "title": "Authentication Bypass with Empty Password in Spring LDAP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41720"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-5714",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shortpixel",
      "product": "Enable Media Replace",
      "cwe": "CWE-79",
      "title": "Enable Media Replace <= 4.1.8 - Authenticated (Author+) Stored Cross-Site Scripting via 'location_dir' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5714"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-0409",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "Orbi 370",
      "cwe": "CWE-119",
      "title": "Netgear Orbi 370 Series Remote Code Execution vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0409"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-47346",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.16965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "TYPO3 CMS",
      "cwe": "CWE-178",
      "title": "TYPO3 CMS - Broken Access Control in Form Framework",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47346"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-10738",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weaverlancegmailcom",
      "product": "jQuery Hover Footnotes",
      "cwe": "CWE-79",
      "title": "jQuery Hover Footnotes <= 1.4 - Authenticated (Author+) Stored Cross-Site Scripting via Footnote Qualifier ('{{...}}' Syntax)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10738"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-7542",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revolution Slider",
      "product": "Slider Revolution",
      "cwe": "CWE-200",
      "title": "Slider Revolution 7.0 - 7.0.10 - Authenticated (Subscriber+) Sensitive Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7542"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-42984",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-416",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42984"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-45653",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Kernel Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45653"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-36720",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modifying their user type.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36720"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-41840",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.1631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-401",
      "title": "Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, 5.3.0 through 5.3.48.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41840"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-42978",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-362",
      "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42978"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-0418",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.15952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "CBR750",
      "cwe": "CWE-610",
      "title": "Certain NETGEAR devices allow administrators to tamper with system",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0418"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-49741",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.15894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "TYPO3 CMS",
      "cwe": "CWE-89",
      "title": "TYPO3 CMS - Privilege Escalation & SQL Injection in Form Framework",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49741"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-8677",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmessiah",
      "product": "Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages",
      "cwe": "CWE-79",
      "title": "Prime Elementor Addons <= 1.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Widget HTML Tag Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8677"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-41031",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00242,
      "epss_percentile": 0.15675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Skilja GmbH",
      "product": "Vinna Process Monitor",
      "cwe": "CWE-79",
      "title": "A Stored Cross-Site Scripting (XSS) vulnerability occurs in Vinna Process Monitor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41031"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-47931",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-20",
      "title": "ColdFusion | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47931"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-46747",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "SINEC INS",
      "cwe": "CWE-26",
      "title": "A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not properly sanitize path input in the `GET /api/sftp/uploadFiles` endpoint used for directory listing. This allows path traversal through crafted input, enabling access to unintended file system locations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46747"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-7556",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "foliovision",
      "product": "FV Flowplayer Video Player",
      "cwe": "CWE-79",
      "title": "FV Flowplayer Video Player <= 7.5.49.7212 - Unauthenticated Stored Cross-Site Scripting via Comment Text",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7556"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-41727",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring for Apache Kafka",
      "cwe": "CWE-20",
      "title": "In Spring for Apache Kafka, forged retry topic headers subvert retry routing and backoff behavior",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41727"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-49161",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft PC Manager",
      "cwe": "CWE-284",
      "title": "Microsoft PC Manager Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49161"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-11607",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "TYPO3 CMS",
      "cwe": "CWE-862",
      "title": "TYPO3 CMS - Broken Access Control in Form Framework",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11607"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-47343",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "TYPO3 CMS",
      "cwe": "CWE-862",
      "title": "TYPO3 CMS - Destructive Actions on File Mount Folders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47343"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-47349",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "TYPO3 CMS",
      "cwe": "CWE-862",
      "title": "TYPO3 CMS - Broken Access Control in Recycler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47349"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-47350",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "TYPO3 CMS",
      "cwe": "CWE-862",
      "title": "TYPO3 CMS - Broken Access Control in DataHandler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47350"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-47351",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "TYPO3 CMS",
      "cwe": "CWE-200",
      "title": "TYPO3 CMS - Broken Access Control in Clipboard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47351"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-47352",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "TYPO3 CMS",
      "cwe": "CWE-862",
      "title": "TYPO3 CMS - Broken Access Control in Backend API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47352"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-34181",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-354",
      "title": "PKCS#12 Files with PBMAC1 Are Accepted with Short HMAC Keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34181"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-46320",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tap: free page on error paths in tap_get_user_xdp()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46320"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-9211",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "CAX30",
      "cwe": "CWE-20",
      "title": "Certain NETGEAR routers allow unauthenticated users to gain control of the router",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9211"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-34335",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34335"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-42911",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42911"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-45640",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-416",
      "title": "Windows Bluetooth Port Driver Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45640"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-47293",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-416",
      "title": "Microsoft Office Click-To-Run Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47293"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-8599",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mailerpress",
      "product": "MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails",
      "cwe": "CWE-79",
      "title": "MailerPress <= 2.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via Campaign HTML Content Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8599"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-8045",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00233,
      "epss_percentile": 0.14468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Schneider Electric",
      "product": "EcoStruxure™ IT Data Center Expert",
      "cwe": "CWE-611",
      "title": "CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8045"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-39169",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39169"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-46492",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "commenthol",
      "product": "md-fileserver",
      "cwe": "CWE-80",
      "title": "md-fileserver: Stored/Reflected XSS when viewing Markdown (raw HTML allowed)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46492"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-44748",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00231,
      "epss_percentile": 0.14265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP NetWeaver AS ABAP and ABAP Platform",
      "cwe": "CWE-347",
      "title": "XML Signature Wrapping in SAML Authentication in SAP NetWeaver AS ABAP and ABAP Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44748"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-46542",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nimiq",
      "product": "core-rs-albatross",
      "cwe": "CWE-617",
      "title": "nimiq-keys: Denial of service in Ed25519 multisig delinearization via invalid curve points",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46542"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-47991",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-601",
      "title": "Adobe Experience Manager | URL Redirection to Untrusted Site ('Open Redirect') (CWE-601)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47991"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-0415",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.14007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "RBE970",
      "cwe": "CWE-20",
      "title": "Insufficient input validation vulnerability in certain Orbi routers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0415"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-0417",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.14006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "MR60",
      "cwe": "CWE-20",
      "title": "Insufficient input validation in certain NETGEAR routers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0417"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-11764",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00229,
      "epss_percentile": 0.13973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "pretix",
      "cwe": "CWE-280",
      "title": "Data exposed without proper permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11764"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-10024",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "360crest",
      "product": "TinyMCE shortcode Addon",
      "cwe": "CWE-79",
      "title": "TinyMCE shortcode Addon <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'btnrel' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10024"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-53675",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BuddyPress",
      "product": "BuddyPress",
      "cwe": "CWE-639",
      "title": "BuddyPress 14.4.0 Friends List IDOR via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53675"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-41697",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Data Relational",
      "cwe": "CWE-943",
      "title": "Spring Data Relational Parameter not Escaped for Query By Example LIKE Pattern",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41697"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-46433",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lldpd",
      "product": "lldpd",
      "cwe": "CWE-125",
      "title": "lldpd: Heap OOB Read in VLAN Decapsulation memmove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46433"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-9754",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB",
      "cwe": "CWE-457",
      "title": "Stack memory disclosure in filemd5 command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9754"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-44744",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP S/4HANA",
      "cwe": "CWE-89",
      "title": "SQL Injection vulnerability in SAP S/4HANA",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44744"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-40991",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring REST Docs",
      "cwe": "CWE-611",
      "title": "XML External Entity (XXE) injection when documenting untrusted XML content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40991"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-49472",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "signalwire",
      "product": "freeswitch",
      "cwe": "CWE-116",
      "title": "FreeSWITCH includes a vulnerable function, PREFIX(prologTok)() from libexpat",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49472"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2016-20063",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Md. Shamim Shahnewaz",
      "product": "Single Personal Message",
      "cwe": "CWE-89",
      "title": "Single Personal Message 1.0.3 WordPress Plugin SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20063"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-32856",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ellucian",
      "product": "Banner Self-Service",
      "cwe": "CWE-79",
      "title": "Ellucian Banner Self-Service Reflected XSS via dateConverter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32856"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-44754",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "ODP Data Replication APIs",
      "cwe": "CWE-862",
      "title": "Missing caller identification check-in for ODP Data Replication APIs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44754"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-0410",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00219,
      "epss_percentile": 0.1264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "R7000",
      "cwe": "CWE-20",
      "title": "Insufficient input validation in certain NETGEAR routers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0410"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-47648",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.12612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-426",
      "title": "Windows Storage Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47648"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-42771",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12549,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSSL",
      "product": "OpenSSL",
      "cwe": "CWE-125",
      "title": "Possible Out of Bounds Read in X509_VERIFY_PARAM_set1_email()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42771"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-11621",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00218,
      "epss_percentile": 0.1257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Dcat-Admin",
      "cwe": "CWE-284",
      "title": "Dcat-Admin User Setting upload editorMDUpload unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11621"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2023-43688",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00217,
      "epss_percentile": 0.12416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). There is a Heap buffer overflow in various buffer encryption utilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-43688"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-36777",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the param_1 parameter of the formSetCfm function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36777"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-36722",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-434",
      "title": "An authenticated arbitrary file upload vulnerability in the /api/create-car-image component of bookcars v8.3 allows attackers to execute arbitrary code via uploading a crafted file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36722"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-11799",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00216,
      "epss_percentile": 0.12261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Focus for iOS",
      "cwe": "CWE-79",
      "title": "UXSS in Focus for iOS / Klar Webkit navigation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11799"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-9210",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.1229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "EX3700",
      "cwe": "CWE-20",
      "title": "Certain NETGEAR routers allow authenticated administrators to gain unintended control of the router",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9210"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-45647",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Defender for Endpoint for Mac",
      "cwe": "CWE-367",
      "title": "Microsoft Defender for Endpoint for Mac Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45647"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-49740",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TYPO3",
      "product": "TYPO3 CMS",
      "cwe": "CWE-502",
      "title": "TYPO3 CMS - Insecure Deserialization in Core API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49740"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-41706",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Security",
      "cwe": "CWE-601",
      "title": "Open Redirect When Using CookieRequestCache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41706"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-28301",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Observability Self-Hosted",
      "cwe": "CWE-601",
      "title": "SolarWinds Observability Self-Hosted Open Redirect Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28301"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-10045",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00209,
      "epss_percentile": 0.11324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shenzhen Kangda Xin Intelligent Network Technology Co., Ltd",
      "product": "DR300",
      "cwe": null,
      "title": "CVE-2026-10045",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10045"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-47916",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.1136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47916"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-11619",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "ERP CRM",
      "cwe": "CWE-266",
      "title": "Dolibarr ERP CRM Legacy Filemanager config.inc.php improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11619"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-46518",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00208,
      "epss_percentile": 0.1122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openemr",
      "product": "openemr",
      "cwe": "CWE-79",
      "title": "OpenEMR: Stored XSS in prescription CSS/HTML print view via patient demographics",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46518"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-44751",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.11071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP NetWeaver AS ABAP and ABAP Platform",
      "cwe": "CWE-862",
      "title": "Missing Authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44751"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-46748",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.10958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "SINEC INS",
      "cwe": "CWE-250",
      "title": "A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a binary that is configured with the cap_dac_override capability. This capability allows the process to bypass file system permission checks, resulting in unrestricted file system access. This could allow a local attacker to escalate privileges leading to arbitrary file modification and gaining root privileges on the system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46748"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-41719",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.11039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Data KeyValue",
      "cwe": "CWE-917",
      "title": "Spring Data KeyValue - SpEL Injection vulnerability in SpelPropertyComparator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41719"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-42912",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows Telephony Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42912"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-11603",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brthumar1959",
      "product": "Product Filter Widget for Elementor",
      "cwe": "CWE-79",
      "title": "Product Filter Widget for Elementor <= 1.0.6 - Reflected Cross-Site Scripting via 'args[filterFormArray]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11603"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-47936",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47936"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-47944",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47944"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-47949",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47949"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-47950",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47950"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-47951",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47951"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-47953",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47953"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-47954",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47954"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-47956",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47956"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-47957",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47957"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-47958",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47958"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-47962",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47962"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-47966",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47966"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-47972",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47972"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-47973",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47973"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-47974",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47974"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-47975",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47975"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-47977",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47977"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-47978",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.1092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47978"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-47980",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47980"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-47981",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47981"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-47990",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47990"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-48297",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48297"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-48299",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.1092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48299"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-48300",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.1092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48300"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-48301",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.1092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48301"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-48304",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48304"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-47933",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-79",
      "title": "ColdFusion | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47933"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-41003",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Security",
      "cwe": "CWE-79",
      "title": "Unencoded HTML Outputs in Spring Security May Allow Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41003"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-49938",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiPortal",
      "cwe": "CWE-284",
      "title": "A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions may allow attacker to improper access control via <insert attack vector here>",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49938"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-44746",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP NetWeaver AS Java (JDBC Test Servlet)",
      "cwe": "CWE-79",
      "title": "Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS Java (JDBC Test Servlet)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44746"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-34416",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brian-ruf",
      "product": "OSCAL-GUI",
      "cwe": "CWE-79",
      "title": "OSCAL-GUI Reflected XSS via project parameter in oscal.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34416"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-40993",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Security",
      "cwe": "CWE-502",
      "title": "Unfiltered Java Native Deserialization of SAML 2.0 Asserting Party Credentials BLOB Database Entry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40993"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-42836",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.0992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows Function Discovery Service (fdwsd.dll) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42836"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-4986",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPForms",
      "cwe": "CWE-862",
      "title": "WPForms Lite < 1.10.0.5 – Unauthenticated PayPal Webhook Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4986"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-41730",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Data REST",
      "cwe": "CWE-209",
      "title": "Spring Data REST exposes persistence-layer internals in error responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41730"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-41839",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-384",
      "title": "Spring Framework Escalation via Session Fixation in WebFlux",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41839"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-47106",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.0972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ellucian",
      "product": "Banner Self-Service",
      "cwe": "CWE-79",
      "title": "Ellucian Banner Self-Service Stored XSS via getFacultyMeetingTimes API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47106"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-46332",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00193,
      "epss_percentile": 0.09333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-120",
      "title": "greybus: gb-beagleplay: bound bootloader receive buffering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46332"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-41539",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "QTS",
      "cwe": "CWE-79",
      "title": "QTS, QuTS hero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41539"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-7662",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joshin85",
      "product": "Plugin Name: ePaperFlip Publisher",
      "cwe": "CWE-79",
      "title": "ePaperFlip Publisher <= 1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'publicationid' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7662"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-8880",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "romancartsupport",
      "product": "RomanCart Ecommerce",
      "cwe": "CWE-79",
      "title": "RomanCart Ecommerce <= 2.0.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8880"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2025-55651",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55651"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-40639",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Dell Edge Gateway 3000",
      "cwe": "CWE-261",
      "title": "Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of Privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40639"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-41837",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Data REST",
      "cwe": "CWE-284",
      "title": "Spring Data REST Querydsl integration exposes Jackson-hidden persistent fields as filter keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41837"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-34692",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34692"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-47935",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47935"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-47982",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47982"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-47983",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47983"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-47985",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47985"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-47986",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47986"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-47987",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47987"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-47989",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47989"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-47993",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47993"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-48250",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48250"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-48251",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48251"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-48256",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48256"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-48264",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48264"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-48268",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager | Cross-site Scripting (DOM-based XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48268"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-8883",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "helpstring",
      "product": "Global Body Mass Index Calculator",
      "cwe": "CWE-79",
      "title": "Global Body Mass Index Calculator <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8883"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-8977",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "techjewel",
      "product": "WP GDPR Cookie Consent",
      "cwe": "CWE-79",
      "title": "WP GDPR Cookie Consent <= 1.0.0 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'ninja_gdpr_ajax_actions' AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8977"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-44743",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00188,
      "epss_percentile": 0.08809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Business Objects",
      "cwe": "CWE-497",
      "title": "Security Misconfiguration vulnerability in SAP Business Objects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44743"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-25557",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Evoluted",
      "product": "PHP Directory Listing Script",
      "cwe": "CWE-79",
      "title": "Evoluted PHP Directory Listing Script 4.0.5 Reflected XSS via dir parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25557"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-45597",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 11 version 23H2",
      "cwe": "CWE-362",
      "title": "Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45597"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2025-40808",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "SIPROTEC 5 6MD84 (CP300)",
      "cwe": "CWE-434",
      "title": "A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions), SIPROTEC 5 6MD89 (CP300) (All versions), SIPROTEC 5 6MU85 (CP300) (All versions), SIPROTEC 5 7KE85 (CP200) (All versions), SIPROTEC 5 7KE85 (CP300) (All versions), SIPROTEC 5 7SA82 (CP100) (All versions), SIPROTEC 5 7SA82 (CP150) (All versions), SIPROTEC 5 7SA86 (CP200) (All versions), SIPROTEC 5 7SA86 (CP300) (All versions), SIPROTEC 5 7SA87 (CP200) (All versions), SIPROTEC 5 7SA87 (CP300) (All versions), SIPROTEC 5 7SD82 (CP100) (All versions), SIPROTEC 5 7SD82 (CP150) (All versions), SIPROTEC 5 7SD86 (CP200) (All versions), SIPROTEC 5 7SD86 (CP300) (All versions), SIPROTEC 5 7SD87 (CP200) (All versions), SIPROTEC 5 7SD87 (CP300) (All versions), SIPROTEC 5 7SJ81 (CP100) (All versions), SIPROTEC 5 7SJ81 (CP150) (All versions), SIPROTEC 5 7SJ82 (CP100) (All versions), SIPROTEC 5 7SJ82 (CP150) (All versions), SIPROTEC 5 7SJ85 (CP200) (All versions), SIPROTEC 5 7SJ85 (CP300) (All versions), SIPROTEC 5 7SJ86 (CP200) (All versions), SIPROTEC 5 7SJ86 (CP300) (All versions), SIPROTEC 5 7SK82 (CP100) (All versions), SIPROTEC 5 7SK82 (CP150) (All versions), SIPROTEC 5 7SK85 (CP200) (All versions), SIPROTEC 5 7SK85 (CP300) (All versions), SIPROTEC 5 7SL82 (CP100) (All versions), SIPROTEC 5 7SL82 (CP150) (All versions), SIPROTEC 5 7SL86 (CP200) (All versions), SIPROTEC 5 7SL86 (CP300) (All versions), SIPROTEC 5 7SL87 (CP200) (All versions), SIPROTEC 5 7SL87 (CP300) (All versions), SIPROTEC 5 7SS85 (CP200) (All versions), SIPROTEC 5 7SS85 (CP300) (All versions), SIPROTEC 5 7ST85 (CP200) (All versions), SIPROTEC 5 7ST85 (CP300) (All versions), SIPROTEC 5 7ST86 (CP300) (All versions), SIPROTEC 5 7SX82 (CP150) (All versions), SIPROTEC 5 7SX85 (CP300) (All versions), SIPROTEC 5 7SY82 (CP150) (All versions), SIPROTEC 5 7UM85 (CP300) (All versions), SIPROTEC 5 7UT82 (CP100) (All versions), SIPROTEC 5 7UT82 (CP150) (All versions), SIPROTEC 5 7UT85 (CP200) (All versions), SIPROTEC 5 7UT85 (CP300) (All versions), SIPROTEC 5 7UT86 (CP200) (All versions), SIPROTEC 5 7UT86 (CP300) (All versions), SIPROTEC 5 7UT87 (CP200) (All versions), SIPROTEC 5 7UT87 (CP300) (All versions), SIPROTEC 5 7VE85 (CP300) (All versions), SIPROTEC 5 7VK87 (CP200) (All versions), SIPROTEC 5 7VK87 (CP300) (All versions), SIPROTEC 5 7VU85 (CP300) (All versions), SIPROTEC 5 Compact 7SX800 (CP050) (All versions). The affected application allows authenticated users to upload arbitrary files using DIGSI 5 protocol. This could allow an attacker to upload malicious configuration files, that could cause denial of service condition and potentially lead to code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-40808"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-41853",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-444",
      "title": "Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41853"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2026-42977",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-362",
      "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42977"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2026-42979",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-362",
      "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42979"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-47926",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-125",
      "title": "Acrobat Reader | Out-of-bounds Read (CWE-125)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47926"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-45487",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.08288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-367",
      "title": "Windows Program Compatibility Assistant Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45487"
    },
    {
      "rank": 564,
      "cve_id": "CVE-2026-8841",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.0805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "andrewabarber",
      "product": "Extra Settings for RocketChat",
      "cwe": "CWE-79",
      "title": "Extra Settings for RocketChat <= 0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8841"
    },
    {
      "rank": 565,
      "cve_id": "CVE-2026-8882",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.08048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jdm-labs",
      "product": "WP ApplicantStack Jobs Display",
      "cwe": "CWE-79",
      "title": "WP ApplicantStack Jobs Display <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8882"
    },
    {
      "rank": 566,
      "cve_id": "CVE-2026-8895",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.0805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kenz60",
      "product": "kk blog card",
      "cwe": "CWE-79",
      "title": "kk blog card <= 1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8895"
    },
    {
      "rank": 567,
      "cve_id": "CVE-2026-36725",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "A markdown based cross-site scripting (XSS) vulnerability in the /system/notice/create endpoint of FastapiAdmin v2.2.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the notice_content parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36725"
    },
    {
      "rank": 568,
      "cve_id": "CVE-2026-36772",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the wl_radio parameter of the formwrlSSIDget function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36772"
    },
    {
      "rank": 569,
      "cve_id": "CVE-2026-36773",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the Go parameter of the ask_to_reboot function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36773"
    },
    {
      "rank": 570,
      "cve_id": "CVE-2026-0416",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "RAXE450",
      "cwe": "CWE-20",
      "title": "Improper input validation in certain NETGEAR routers allows unauthorized modification of protected router functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0416"
    },
    {
      "rank": 571,
      "cve_id": "CVE-2026-45596",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00179,
      "epss_percentile": 0.07773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45596"
    },
    {
      "rank": 572,
      "cve_id": "CVE-2026-45598",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00179,
      "epss_percentile": 0.07773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45598"
    },
    {
      "rank": 573,
      "cve_id": "CVE-2026-45601",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00179,
      "epss_percentile": 0.07772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-362",
      "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45601"
    },
    {
      "rank": 574,
      "cve_id": "CVE-2026-45603",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00179,
      "epss_percentile": 0.07772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1607",
      "cwe": "CWE-416",
      "title": "Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45603"
    },
    {
      "rank": 575,
      "cve_id": "CVE-2026-11785",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11",
      "cwe": "CWE-843",
      "title": "389-ds-base: 389-ds-base: partial stack address information leak via ber_printf type confusion in sso token handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11785"
    },
    {
      "rank": 576,
      "cve_id": "CVE-2026-34707",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00178,
      "epss_percentile": 0.07665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "InCopy",
      "cwe": "CWE-122",
      "title": "InCopy | Heap-based Buffer Overflow (CWE-122)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34707"
    },
    {
      "rank": 577,
      "cve_id": "CVE-2026-34657",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "CAI Content Credentials",
      "cwe": "CWE-22",
      "title": "CAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34657"
    },
    {
      "rank": 578,
      "cve_id": "CVE-2026-47906",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00177,
      "epss_percentile": 0.07536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Dreamweaver Desktop",
      "cwe": "CWE-1395",
      "title": "Dreamweaver Desktop | Dependency on Vulnerable Third-Party Component (CWE-1395)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47906"
    },
    {
      "rank": 579,
      "cve_id": "CVE-2026-11787",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11",
      "cwe": "CWE-126",
      "title": "389-ds-base: 389-ds-base: heap buffer over-read in ldap_utf8prev() via str2simple filter parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11787"
    },
    {
      "rank": 580,
      "cve_id": "CVE-2026-41852",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-863",
      "title": "Spring Framework Arbitrary Method Invocation in SpEL Expressions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41852"
    },
    {
      "rank": 581,
      "cve_id": "CVE-2026-11822",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SQLite",
      "product": "SQLite",
      "cwe": "CWE-122",
      "title": "SQLite before 3.53.2 Memory Corruption in FTS5 Extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11822"
    },
    {
      "rank": 582,
      "cve_id": "CVE-2026-11824",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SQLite",
      "product": "SQLite",
      "cwe": "CWE-122",
      "title": "SQLite before 3.53.2 Heap Buffer Overflow via FTS5 fts5ChunkIterate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11824"
    },
    {
      "rank": 583,
      "cve_id": "CVE-2026-34695",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "InDesign Desktop",
      "cwe": "CWE-121",
      "title": "InDesign Desktop | Stack-based Buffer Overflow (CWE-121)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34695"
    },
    {
      "rank": 584,
      "cve_id": "CVE-2026-34697",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "InDesign Desktop",
      "cwe": "CWE-121",
      "title": "InDesign Desktop | Stack-based Buffer Overflow (CWE-121)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34697"
    },
    {
      "rank": 585,
      "cve_id": "CVE-2026-34698",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "InDesign Desktop",
      "cwe": "CWE-122",
      "title": "InDesign Desktop | Heap-based Buffer Overflow (CWE-122)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34698"
    },
    {
      "rank": 586,
      "cve_id": "CVE-2026-34699",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "InDesign Desktop",
      "cwe": "CWE-122",
      "title": "InDesign Desktop | Heap-based Buffer Overflow (CWE-122)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34699"
    },
    {
      "rank": 587,
      "cve_id": "CVE-2026-34701",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "InDesign Desktop",
      "cwe": "CWE-122",
      "title": "InDesign Desktop | Heap-based Buffer Overflow (CWE-122)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34701"
    },
    {
      "rank": 588,
      "cve_id": "CVE-2026-34702",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "InDesign Desktop",
      "cwe": "CWE-121",
      "title": "InDesign Desktop | Stack-based Buffer Overflow (CWE-121)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34702"
    },
    {
      "rank": 589,
      "cve_id": "CVE-2026-34708",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "InCopy",
      "cwe": "CWE-121",
      "title": "InCopy | Stack-based Buffer Overflow (CWE-121)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34708"
    },
    {
      "rank": 590,
      "cve_id": "CVE-2026-34694",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Experience Manager Forms JEE",
      "cwe": "CWE-79",
      "title": "Adobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34694"
    },
    {
      "rank": 591,
      "cve_id": "CVE-2026-47952",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.0718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-122",
      "title": "Acrobat Reader | Heap-based Buffer Overflow (CWE-122)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47952"
    },
    {
      "rank": 592,
      "cve_id": "CVE-2026-47959",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.07181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-121",
      "title": "Acrobat Reader | Stack-based Buffer Overflow (CWE-121)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47959"
    },
    {
      "rank": 593,
      "cve_id": "CVE-2026-24315",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Fiori (launchpad)",
      "cwe": "CWE-35",
      "title": "Path Traversal Vulnerability in SAP Fiori (launchpad)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24315"
    },
    {
      "rank": 594,
      "cve_id": "CVE-2026-42991",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 1809",
      "cwe": "CWE-362",
      "title": "Windows Push Notifications Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42991"
    },
    {
      "rank": 595,
      "cve_id": "CVE-2026-41701",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.0707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring AMQP",
      "cwe": "CWE-330",
      "title": "In Spring AMQP sequential correlation IDs enable reply poisoning on fixed reply queues",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41701"
    },
    {
      "rank": 596,
      "cve_id": "CVE-2026-41008",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Security",
      "cwe": "CWE-601",
      "title": "Spring Security Authorization Server Open Redirect via request_uri",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41008"
    },
    {
      "rank": 597,
      "cve_id": "CVE-2026-41715",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Reactor Netty",
      "cwe": "CWE-522",
      "title": "Reactor Netty HTTP Client Leaks Credentials On Protocol Downgrade Redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41715"
    },
    {
      "rank": 598,
      "cve_id": "CVE-2026-49848",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "signalwire",
      "product": "freeswitch",
      "cwe": "CWE-287",
      "title": "FreeSWITCH: Pre-authentication `userVariables` injection in `mod_verto`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49848"
    },
    {
      "rank": 599,
      "cve_id": "CVE-2026-41838",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-330",
      "title": "Spring Framework Predictable Session ID in WebSocket Module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41838"
    },
    {
      "rank": 600,
      "cve_id": "CVE-2026-47907",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00168,
      "epss_percentile": 0.06491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Dreamweaver Desktop",
      "cwe": "CWE-284",
      "title": "Dreamweaver Desktop | Improper Access Control (CWE-284)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47907"
    },
    {
      "rank": 601,
      "cve_id": "CVE-2026-47921",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00168,
      "epss_percentile": 0.06623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47921"
    },
    {
      "rank": 602,
      "cve_id": "CVE-2026-34417",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brian-ruf",
      "product": "OSCAL-GUI",
      "cwe": "CWE-79",
      "title": "OSCAL-GUI Reflected XSS via project parameter in oscal-forms.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34417"
    },
    {
      "rank": 603,
      "cve_id": "CVE-2026-42599",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sveltejs",
      "product": "svelte",
      "cwe": "CWE-79",
      "title": "Cross-site scripting via spread attributes in Svelte SSR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42599"
    },
    {
      "rank": 604,
      "cve_id": "CVE-2026-0414",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "RBE970",
      "cwe": "CWE-94",
      "title": "Insufficient Input Validation Allows Unauthorized Modification of Router Software in certain NETGEAR Routers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0414"
    },
    {
      "rank": 605,
      "cve_id": "CVE-2026-34696",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.06285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "InDesign Desktop",
      "cwe": "CWE-416",
      "title": "InDesign Desktop | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34696"
    },
    {
      "rank": 606,
      "cve_id": "CVE-2026-47925",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-190",
      "title": "Acrobat Reader | Integer Overflow or Wraparound (CWE-190)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47925"
    },
    {
      "rank": 607,
      "cve_id": "CVE-2026-41847",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-284",
      "title": "Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41847"
    },
    {
      "rank": 608,
      "cve_id": "CVE-2026-47920",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.0621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47920"
    },
    {
      "rank": 609,
      "cve_id": "CVE-2026-47955",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-416",
      "title": "Acrobat Reader | Use After Free (CWE-416)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47955"
    },
    {
      "rank": 610,
      "cve_id": "CVE-2026-36728",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "A markdown based cross-site scripting (XSS) vulnerability in the AI assistant chat function of FastapiAdmin v2.2.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into a chat message.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36728"
    },
    {
      "rank": 611,
      "cve_id": "CVE-2026-47908",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00161,
      "epss_percentile": 0.05839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Dreamweaver Desktop",
      "cwe": "CWE-824",
      "title": "Dreamweaver Desktop | Access of Uninitialized Pointer (CWE-824)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47908"
    },
    {
      "rank": 612,
      "cve_id": "CVE-2026-41845",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-79",
      "title": "Spring Framework Cross-site Scripting via JavaScriptUtils",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41845"
    },
    {
      "rank": 613,
      "cve_id": "CVE-2026-44750",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP MDG (Review Match Groups Application)",
      "cwe": "CWE-862",
      "title": "Missing Authorization check in SAP MDG (Review Match Groups Application)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44750"
    },
    {
      "rank": 614,
      "cve_id": "CVE-2026-11786",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11",
      "cwe": "CWE-125",
      "title": "389-ds-base: 389-ds-base: heap out-of-bounds read in ldif parser str2entry_state_information_from_type()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11786"
    },
    {
      "rank": 615,
      "cve_id": "CVE-2026-10862",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pickplugins",
      "product": "Accordions",
      "cwe": "CWE-79",
      "title": "Accordions <= 2.3.23 - Authenticated (Custom+) Stored Cross-Site Scripting via Accordion Body Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10862"
    },
    {
      "rank": 616,
      "cve_id": "CVE-2026-34705",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "InDesign Desktop",
      "cwe": "CWE-125",
      "title": "InDesign Desktop | Out-of-bounds Read (CWE-125)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34705"
    },
    {
      "rank": 617,
      "cve_id": "CVE-2026-41972",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.0515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-22",
      "title": "Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability may affect availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41972"
    },
    {
      "rank": 618,
      "cve_id": "CVE-2026-24180",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.0508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "DALI",
      "cwe": "CWE-122",
      "title": "NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24180"
    },
    {
      "rank": 619,
      "cve_id": "CVE-2026-47961",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-125",
      "title": "Acrobat Reader | Out-of-bounds Read (CWE-125)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47961"
    },
    {
      "rank": 620,
      "cve_id": "CVE-2026-44757",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Wily Introscope Enterprise Manager",
      "cwe": "CWE-79",
      "title": "Cross-Site Scripting (XSS) vulnerability in SAP Wily Introscope Enterprise Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44757"
    },
    {
      "rank": 621,
      "cve_id": "CVE-2026-47902",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "CAI Content Credentials",
      "cwe": "CWE-400",
      "title": "CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47902"
    },
    {
      "rank": 622,
      "cve_id": "CVE-2026-47903",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "CAI Content Credentials",
      "cwe": "CWE-20",
      "title": "CAI Content Credentials | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47903"
    },
    {
      "rank": 623,
      "cve_id": "CVE-2026-47904",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "CAI Content Credentials",
      "cwe": "CWE-400",
      "title": "CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47904"
    },
    {
      "rank": 624,
      "cve_id": "CVE-2026-47905",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "CAI Content Credentials",
      "cwe": "CWE-400",
      "title": "CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47905"
    },
    {
      "rank": 625,
      "cve_id": "CVE-2026-0412",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.04964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "JR6150",
      "cwe": "CWE-20",
      "title": "Insufficient input validation vulnerability in NETGEAR JR6150 Web UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0412"
    },
    {
      "rank": 626,
      "cve_id": "CVE-2026-4058",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wedevs",
      "product": "User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration",
      "cwe": "CWE-862",
      "title": "User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.2 - Missing Authorization to Authenticated (Subscriber+) Subscription Pack Cancellation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4058"
    },
    {
      "rank": 627,
      "cve_id": "CVE-2026-49762",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-lang",
      "product": "elixir",
      "cwe": "CWE-400",
      "title": "Unbounded integer parsing in the Version module enables CPU and memory exhaustion denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49762"
    },
    {
      "rank": 628,
      "cve_id": "CVE-2026-24064",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Waves Audio Ltd.",
      "product": "Waves Central",
      "cwe": "CWE-426",
      "title": "Local Privilege Escalation via Dynamic Library Injection in Waves Central for macOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24064"
    },
    {
      "rank": 629,
      "cve_id": "CVE-2026-47937",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-427",
      "title": "Acrobat Reader | Uncontrolled Search Path Element (CWE-427)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47937"
    },
    {
      "rank": 630,
      "cve_id": "CVE-2026-46539",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.04719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nimiq",
      "product": "core-rs-albatross",
      "cwe": "CWE-345",
      "title": "nimiq-primitives: BlockInclusionProof interlink issue when hops are empty",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46539"
    },
    {
      "rank": 631,
      "cve_id": "CVE-2025-67862",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiOS",
      "cwe": "CWE-1244",
      "title": "An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0 all versions may allow an authenticated admin to execute lua scripts via crafted CLI commands.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67862"
    },
    {
      "rank": 632,
      "cve_id": "CVE-2026-8795",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "Velociraptor",
      "cwe": "CWE-74",
      "title": "A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version 0.76.6. The hostname field in client_info.json inside a collection ZIP is inserted into a YAML template via Go's text/template without escaping. An attacker providing a crafted collection ZIP can leverage literal double quotes and newlines in the hostname to break out of the YAML quoted string and inject a new mount remapping entry. When an analyst applies the generated remapping file with --remap, arbitrary VQL executes on their machine with NullACLManager (all permissions granted, unsandboxed).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8795"
    },
    {
      "rank": 633,
      "cve_id": "CVE-2026-46517",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InternLM",
      "product": "lmdeploy",
      "cwe": "CWE-94",
      "title": "LMDeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46517"
    },
    {
      "rank": 634,
      "cve_id": "CVE-2026-47909",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04525,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Dreamweaver Desktop",
      "cwe": "CWE-20",
      "title": "Dreamweaver Desktop | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47909"
    },
    {
      "rank": 635,
      "cve_id": "CVE-2026-10553",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weaverlancegmailcom",
      "product": "jQuery Hover Footnotes",
      "cwe": "CWE-352",
      "title": "jQuery Hover Footnotes <= 1.4 - Cross-Site Request Forgery to Plugin Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10553"
    },
    {
      "rank": 636,
      "cve_id": "CVE-2026-34710",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00144,
      "epss_percentile": 0.04193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Substance3D - Sampler",
      "cwe": "CWE-787",
      "title": "Substance3D - Sampler | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34710"
    },
    {
      "rank": 637,
      "cve_id": "CVE-2026-46432",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.04042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InternLM",
      "product": "lmdeploy",
      "cwe": "CWE-94",
      "title": "LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46432"
    },
    {
      "rank": 638,
      "cve_id": "CVE-2026-48305",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00141,
      "epss_percentile": 0.03942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Substance3D - Sampler",
      "cwe": "CWE-787",
      "title": "Substance3D - Sampler | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48305"
    },
    {
      "rank": 639,
      "cve_id": "CVE-2026-48306",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00141,
      "epss_percentile": 0.03942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Substance3D - Sampler",
      "cwe": "CWE-787",
      "title": "Substance3D - Sampler | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48306"
    },
    {
      "rank": 640,
      "cve_id": "CVE-2026-41846",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-79",
      "title": "Spring Framework Cross-site Scripting via JSP Form Tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41846"
    },
    {
      "rank": 641,
      "cve_id": "CVE-2026-34700",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "InDesign Desktop",
      "cwe": "CWE-787",
      "title": "InDesign Desktop | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34700"
    },
    {
      "rank": 642,
      "cve_id": "CVE-2026-34706",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "InCopy",
      "cwe": "CWE-787",
      "title": "InCopy | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34706"
    },
    {
      "rank": 643,
      "cve_id": "CVE-2026-48293",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "InDesign Desktop",
      "cwe": "CWE-787",
      "title": "InDesign Desktop | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48293"
    },
    {
      "rank": 644,
      "cve_id": "CVE-2026-24181",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "DALI",
      "cwe": "CWE-129",
      "title": "NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24181"
    },
    {
      "rank": 645,
      "cve_id": "CVE-2026-47900",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "logseq",
      "product": "logseq",
      "cwe": "CWE-79",
      "title": "Stored XSS via Unsanitized Plugin Metadata in Logseq",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47900"
    },
    {
      "rank": 646,
      "cve_id": "CVE-2026-47901",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "logseq",
      "product": "logseq",
      "cwe": "CWE-79",
      "title": "Iframe escape by plugins in Logseq",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47901"
    },
    {
      "rank": 647,
      "cve_id": "CVE-2026-45782",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cloud-hypervisor",
      "product": "cloud-hypervisor",
      "cwe": "CWE-416",
      "title": "Cloud Hypervisor: Use-after-free in virtio-block Async I/O Completion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45782"
    },
    {
      "rank": 648,
      "cve_id": "CVE-2026-34709",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Substance3D - Sampler",
      "cwe": "CWE-787",
      "title": "Substance3D - Sampler | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34709"
    },
    {
      "rank": 649,
      "cve_id": "CVE-2026-8981",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00138,
      "epss_percentile": 0.0369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Custom Block Builder",
      "cwe": "CWE-79",
      "title": "Lazy Blocks < 4.3.0 - Admin+ Stored XSS via Custom Block Frontend HTML",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8981"
    },
    {
      "rank": 650,
      "cve_id": "CVE-2026-47899",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.03571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "logseq",
      "product": "logseq",
      "cwe": "CWE-749",
      "title": "Arbitrary File Read, Write, Rename, and Delete in Logseq",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47899"
    },
    {
      "rank": 651,
      "cve_id": "CVE-2026-46323",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.03581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "net: gro: don't merge zcopy skbs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46323"
    },
    {
      "rank": 652,
      "cve_id": "CVE-2026-47910",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Dreamweaver Desktop",
      "cwe": "CWE-863",
      "title": "Dreamweaver Desktop | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47910"
    },
    {
      "rank": 653,
      "cve_id": "CVE-2026-41694",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03543,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Security",
      "cwe": "CWE-347",
      "title": "SAML Payloads Decrypted Without Valid Signature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41694"
    },
    {
      "rank": 654,
      "cve_id": "CVE-2026-41983",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-399",
      "title": "Null pointer dereference vulnerability in the browser module. Impact: Successful exploitation of this vulnerability may affect availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41983"
    },
    {
      "rank": 655,
      "cve_id": "CVE-2026-46546",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00136,
      "epss_percentile": 0.035,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "lms",
      "cwe": "CWE-79",
      "title": "Frappe LMS: HTML injection in user-controlled metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46546"
    },
    {
      "rank": 656,
      "cve_id": "CVE-2026-0420",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.0346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETGEAR",
      "product": "RAX120v1",
      "cwe": "CWE-325",
      "title": "Missing TLS certificate validation in NETGEAR's ReadyCloud client app",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0420"
    },
    {
      "rank": 657,
      "cve_id": "CVE-2026-41844",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.03362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-601",
      "title": "Spring Framework Open Redirect in Spring MVC and WebFlux",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41844"
    },
    {
      "rank": 658,
      "cve_id": "CVE-2026-41982",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-416",
      "title": "Race condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41982"
    },
    {
      "rank": 659,
      "cve_id": "CVE-2026-46326",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iio: pressure: mprls0025pa: fix spi_transfer struct initialisation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46326"
    },
    {
      "rank": 660,
      "cve_id": "CVE-2026-22926",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Omnissa",
      "product": "Omnissa Workspace ONE® Assist for macOS",
      "cwe": "CWE-22",
      "title": "Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22926"
    },
    {
      "rank": 661,
      "cve_id": "CVE-2026-41714",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.0323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring AMQP",
      "cwe": "CWE-295",
      "title": "In Spring AMQP the RabbitConnectionFactoryBean.setUri(\"amqps://...\") bypasses secure SSL setup, uses TrustEverythingTrustManager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41714"
    },
    {
      "rank": 662,
      "cve_id": "CVE-2026-46317",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.03073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: arm64: Reassign nested_mmus array behind mmu_lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46317"
    },
    {
      "rank": 663,
      "cve_id": "CVE-2026-34703",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "InDesign Desktop",
      "cwe": "CWE-476",
      "title": "InDesign Desktop | NULL Pointer Dereference (CWE-476)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34703"
    },
    {
      "rank": 664,
      "cve_id": "CVE-2026-34704",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.0307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "InDesign Desktop",
      "cwe": "CWE-476",
      "title": "InDesign Desktop | NULL Pointer Dereference (CWE-476)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34704"
    },
    {
      "rank": 665,
      "cve_id": "CVE-2026-46321",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tun: free page on short-frame rejection in tun_xdp_one()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46321"
    },
    {
      "rank": 666,
      "cve_id": "CVE-2026-46322",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tun: free page on build_skb failure in tun_xdp_one()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46322"
    },
    {
      "rank": 667,
      "cve_id": "CVE-2026-8909",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rahulbhangale",
      "product": "WpMobi",
      "cwe": "CWE-352",
      "title": "WpMobi <= 0.0.3 - Cross-Site Request Forgery via save_general_settings Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8909"
    },
    {
      "rank": 668,
      "cve_id": "CVE-2026-8940",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jasonpitts",
      "product": "WP Meta Sort Posts",
      "cwe": "CWE-352",
      "title": "WP Meta Sort Posts <= 0.9 - Cross-Site Request Forgery to Plugin Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8940"
    },
    {
      "rank": 669,
      "cve_id": "CVE-2025-54509",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "AMD EPYC™ 9004 Series Processors",
      "cwe": "CWE-1262",
      "title": "Improper access control for register interface in the Input-Output Memory Management Unit (IOMMU) could allow a privileged attacker to cause non-coherent accesses by the AMD Secure Processor (ASP), potentially resulting in loss of integrity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-54509"
    },
    {
      "rank": 670,
      "cve_id": "CVE-2026-46319",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "net/sched: act_ct: Only release RCU read lock after ct_ft",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46319"
    },
    {
      "rank": 671,
      "cve_id": "CVE-2026-8902",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02545,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tierrainnovation",
      "product": "AJAX Report Comments",
      "cwe": "CWE-352",
      "title": "AJAX Report Comments <= 2.0.4 - Cross-Site Request Forgery to Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8902"
    },
    {
      "rank": 672,
      "cve_id": "CVE-2026-8904",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02545,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yuluma",
      "product": "FastPicker, an order picker and order management system (oms) for WooCommerce on steroids",
      "cwe": "CWE-352",
      "title": "FastPicker, an order picker and order management system (oms) for WooCommerce on steroids <= 1.0.2 - Cross-Site Request Forgery via Settings Save",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8904"
    },
    {
      "rank": 673,
      "cve_id": "CVE-2026-11623",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00124,
      "epss_percentile": 0.02558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "tmux",
      "cwe": "CWE-119",
      "title": "tmux image.c image_free use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11623"
    },
    {
      "rank": 674,
      "cve_id": "CVE-2023-29146",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00123,
      "epss_percentile": 0.02494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-190",
      "title": "The utility functions used by Malwarebytes EDR 1.0.11 on Linux for calculating a cryptographic hash of data bytes truncate the hashed data if it exceeds 4GB. This leads to an integer wrap-around if the data is larger than the maximum unsigned integer value (32-bit). Attackers could create a colliding hash value for two different strings by attaching 4GB of data to a string that is less than 4GB in size.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-29146"
    },
    {
      "rank": 675,
      "cve_id": "CVE-2026-41854",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Framework",
      "cwe": "CWE-918",
      "title": "Spring Framework Server-Side Request Forgery via UriComponentsBuilder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41854"
    },
    {
      "rank": 676,
      "cve_id": "CVE-2026-52906",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "9p: fix access mode flags being ORed instead of replaced",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52906"
    },
    {
      "rank": 677,
      "cve_id": "CVE-2026-46749",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "SINEC INS",
      "cwe": "CWE-760",
      "title": "A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a password hashing implementation with a static, hardcoded salt shared across all users and installations, and is configured with an insufficient number of iterations. This could allow an attacker to efficiently recover user passwords using brute-force or precomputed attacks, potentially resulting in unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46749"
    },
    {
      "rank": 678,
      "cve_id": "CVE-2026-52902",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-22",
      "title": "Awxkit: path traversal via yaml !include directive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52902"
    },
    {
      "rank": 679,
      "cve_id": "CVE-2026-46327",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm: fix unlocked test for dm_suspended_md",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46327"
    },
    {
      "rank": 680,
      "cve_id": "CVE-2026-8910",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rahulbhangale",
      "product": "WP Emoticon Rating",
      "cwe": "CWE-352",
      "title": "WP Emoticon Rating <= 1.0.1 - Cross-Site Request Forgery to Reflected Cross-Site Scripting via 'emo_settings' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8910"
    },
    {
      "rank": 681,
      "cve_id": "CVE-2026-46324",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00119,
      "epss_percentile": 0.02048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nf_tables: use list_del_rcu for netlink hooks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46324"
    },
    {
      "rank": 682,
      "cve_id": "CVE-2026-9735",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-532",
      "title": "Keyfile contents are in MongoDB Server logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9735"
    },
    {
      "rank": 683,
      "cve_id": "CVE-2026-8907",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rahulbhangale",
      "product": "WP-Ultimate-Map",
      "cwe": "CWE-352",
      "title": "WP-Ultimate-Map <= 1.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'zoom-level' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8907"
    },
    {
      "rank": 684,
      "cve_id": "CVE-2023-43686",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.01996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-755",
      "title": "An issue was discovered in Malwarebytes 4.x and 5.x (and Nebula 2020-10-21 and later). A large number of Firefox preference files can cause the parser to ignore other browser configuration files, leading to a denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-43686"
    },
    {
      "rank": 685,
      "cve_id": "CVE-2026-47838",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.0188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Security",
      "cwe": "CWE-287",
      "title": "Unauthorized User Impersonation when Using X.509 Client Certificates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47838"
    },
    {
      "rank": 686,
      "cve_id": "CVE-2026-46328",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00114,
      "epss_percentile": 0.01755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "apparmor: fix rlimit for posix cpu timers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46328"
    },
    {
      "rank": 687,
      "cve_id": "CVE-2026-46315",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "io_uring/waitid: clear waitid info before copying it to userspace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46315"
    },
    {
      "rank": 688,
      "cve_id": "CVE-2026-46329",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "erofs: handle end of filesystem properly for file-backed mounts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46329"
    },
    {
      "rank": 689,
      "cve_id": "CVE-2026-52904",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "drm/nouveau: fix nvkm_device leak on aperture removal failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52904"
    },
    {
      "rank": 690,
      "cve_id": "CVE-2026-46330",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "Revert \"net/smc: Introduce TCP ULP support\"",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46330"
    },
    {
      "rank": 691,
      "cve_id": "CVE-2026-52907",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-193",
      "title": "media: rockchip: rkcif: fix off by one bugs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52907"
    },
    {
      "rank": 692,
      "cve_id": "CVE-2026-52905",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-1284",
      "title": "mm/damon/core: disallow non-power of two min_region_sz on damon_start()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52905"
    },
    {
      "rank": 693,
      "cve_id": "CVE-2026-8863",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "OracleLinux(7.2) shim",
      "cwe": null,
      "title": "CVE-2026-8863",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8863"
    },
    {
      "rank": 694,
      "cve_id": "CVE-2026-41986",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.0011,
      "epss_percentile": 0.01446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-606",
      "title": "Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41986"
    },
    {
      "rank": 695,
      "cve_id": "CVE-2026-9751",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-532",
      "title": "Sensitive data could be written to mongod.log",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9751"
    },
    {
      "rank": 696,
      "cve_id": "CVE-2026-44755",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP Business Objects Business Intelligence Platform",
      "cwe": "CWE-346",
      "title": "Email Spoofing vulnerability in SAP Business Objects Business Intelligence Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44755"
    },
    {
      "rank": 697,
      "cve_id": "CVE-2026-6899",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Systerel",
      "product": "S2OPC",
      "cwe": "CWE-299",
      "title": "Improper Check for Certificate Revocation in S2OPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6899"
    },
    {
      "rank": 698,
      "cve_id": "CVE-2026-39170",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-352",
      "title": "SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/semcms_user.php.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39170"
    },
    {
      "rank": 699,
      "cve_id": "CVE-2026-9741",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00103,
      "epss_percentile": 0.0112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-319",
      "title": "Client side encryption fails to encrypt values in a $vectorSearch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9741"
    },
    {
      "rank": 700,
      "cve_id": "CVE-2026-0466",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "AMD µProf",
      "cwe": "CWE-497",
      "title": "Improper access control in AMD uProf may allow a local attacker with user privileges to write to the kernel-shared memory section, potentially resulting in crash or denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0466"
    },
    {
      "rank": 701,
      "cve_id": "CVE-2026-46318",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.0098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Revert \"mm/hugetlbfs: update hugetlbfs to use mmap_prepare\"",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46318"
    },
    {
      "rank": 702,
      "cve_id": "CVE-2026-28237",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00098,
      "epss_percentile": 0.00875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "AMD µProf",
      "cwe": "CWE-770",
      "title": "Unrestricted resource allocation in AMD uProf may be exploitable to consume excessive system resources, potentially leading to a loss of availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28237"
    },
    {
      "rank": 703,
      "cve_id": "CVE-2026-44275",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00097,
      "epss_percentile": 0.00862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Dell/Alienware Purchased Apps",
      "cwe": "CWE-59",
      "title": "Dell/Alienware Purchased Apps, versions prior to 1.1.32.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44275"
    },
    {
      "rank": 704,
      "cve_id": "CVE-2026-28262",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "iDRAC Tools",
      "cwe": "CWE-59",
      "title": "Dell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28262"
    },
    {
      "rank": 705,
      "cve_id": "CVE-2026-41980",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00087,
      "epss_percentile": 0.00428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-200",
      "title": "Permission control vulnerability in the file preview module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41980"
    },
    {
      "rank": 706,
      "cve_id": "CVE-2026-2638",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00085,
      "epss_percentile": 0.00376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "X-VPN",
      "product": "X-VPN macOS website",
      "cwe": "CWE-367",
      "title": "X-VPN macOS website versions - Local Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2638"
    },
    {
      "rank": 707,
      "cve_id": "CVE-2026-41116",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00085,
      "epss_percentile": 0.00344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Inventory Collector Client",
      "cwe": "CWE-1386",
      "title": "Dell Inventory Collector Client, versions prior to 13.8.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41116"
    },
    {
      "rank": 708,
      "cve_id": "CVE-2026-49958",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00081,
      "epss_percentile": 0.00251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nesquena",
      "product": "hermes-webui",
      "cwe": "CWE-367",
      "title": "Hermes WebUI < 0.51.303 TOCTOU Race Condition via git_discard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49958"
    },
    {
      "rank": 709,
      "cve_id": "CVE-2026-41976",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00079,
      "epss_percentile": 0.0017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-275",
      "title": "Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affect service confidentiality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41976"
    },
    {
      "rank": 710,
      "cve_id": "CVE-2026-41973",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00078,
      "epss_percentile": 0.00151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-840",
      "title": "Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41973"
    },
    {
      "rank": 711,
      "cve_id": "CVE-2026-41984",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00078,
      "epss_percentile": 0.00154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-284",
      "title": "UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41984"
    },
    {
      "rank": 712,
      "cve_id": "CVE-2026-41979",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00075,
      "epss_percentile": 0.00108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-701",
      "title": "Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect integrity and confidentiality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41979"
    },
    {
      "rank": 713,
      "cve_id": "CVE-2026-41977",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00075,
      "epss_percentile": 0.00103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-190",
      "title": "DoS vulnerability in the log service. Impact: Successful exploitation of this vulnerability may affect availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41977"
    },
    {
      "rank": 714,
      "cve_id": "CVE-2026-41978",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00075,
      "epss_percentile": 0.00095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-275",
      "title": "Permission control vulnerability in the clone module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41978"
    },
    {
      "rank": 715,
      "cve_id": "CVE-2026-41974",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00074,
      "epss_percentile": 0.00082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-264",
      "title": "Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may affect availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41974"
    },
    {
      "rank": 716,
      "cve_id": "CVE-2026-41985",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00073,
      "epss_percentile": 0.00073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-284",
      "title": "UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41985"
    },
    {
      "rank": 717,
      "cve_id": "CVE-2026-41981",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00072,
      "epss_percentile": 0.00059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-122",
      "title": "Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41981"
    },
    {
      "rank": 718,
      "cve_id": "CVE-2026-41975",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00067,
      "epss_percentile": 0.00027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-701",
      "title": "Permission management vulnerability in the network management module. Impact: Successful exploitation of this vulnerability may affect service integrity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41975"
    },
    {
      "rank": 719,
      "cve_id": "CVE-2026-24349",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00057,
      "epss_percentile": 0.00006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "SIMATIC WinCC Unified PC Runtime V16",
      "cwe": "CWE-313",
      "title": "A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Runtime V17 (All versions), SIMATIC WinCC Unified PC Runtime V18 (All versions), SIMATIC WinCC Unified PC Runtime V19 (All versions), SIMATIC WinCC Unified PC Runtime V20 (All versions), SIMATIC WinCC Unified PC Runtime V21 (All versions < V21 Update 2). Insufficient protection of key material in WinCC Certificate Manager that could allow an attacker to extract sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24349"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-52292",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-52292. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-52293",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-52293. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-55657",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-55657. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-55658",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-55658. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-55659",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-55659. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10520",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10520 (ivanti Sentry). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44716",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44716 (pipecat-ai pipecat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46492",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46492 (commenthol md-fileserver). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46518",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46518 (openemr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-5067",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-5067 (zephyrproject-rtos Zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-5068",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-5068 (zephyrproject-rtos Zephyr). Public exploit reference added."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-10520",
      "detail": "PATCH SHIPPED — CVE-2026-10520 (ivanti Sentry). Fixed in Sentry R10.5.2."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
