{
  "day": "2026-06-10",
  "boundary": "UTC calendar day",
  "published_count": 250,
  "by_severity": {
    "CRITICAL": 16,
    "HIGH": 98,
    "MEDIUM": 116,
    "LOW": 20
  },
  "kev_count": 0,
  "exploit_reference_count": 16,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-53435",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.19035,
      "epss_percentile": 0.97078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-502",
      "title": "In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.xml` submission in a way that allows them to handle HTTP requests afterwards. This can be used to impersonate any user and send HTTP requests on their behalf, up to and including use of the Script Console to run arbitrary code, or to read arbitrary files from the Jenkins controller.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53435"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-20251",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.18991,
      "epss_percentile": 0.97073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-502",
      "title": "Remote Code Execution through Deserialization of Untrusted Data in Splunk Secure Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20251"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-3326",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01866,
      "epss_percentile": 0.77604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Xstore",
      "cwe": "CWE-89",
      "title": "XStore < 9.7.3 - Unauthenticated SQLi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3326"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-46522",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01849,
      "epss_percentile": 0.77378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-400",
      "title": "ImageMagick: Infinite Loop in the MIFF decoder can lead to CPU exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46522"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-3018",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01382,
      "epss_percentile": 0.69964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "contrid",
      "product": "Newsletters",
      "cwe": "CWE-89",
      "title": "Newsletters <= 4.13 - Unauthenticated SQL Injection via wpmlsubscriber_id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3018"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-0273",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01339,
      "epss_percentile": 0.69023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cloud NGFW",
      "cwe": "CWE-78",
      "title": "PAN-OS: Authenticated Admin Command Injection Vulnerability via CLI or Web UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0273"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-6893",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01089,
      "epss_percentile": 0.62694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-78",
      "title": "Dracut: dracut: root code execution via dhcp options command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6893"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-22893",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01088,
      "epss_percentile": 0.62674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "QTS",
      "cwe": "CWE-78",
      "title": "QTS, QuTS hero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22893"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-9151",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01069,
      "epss_percentile": 0.62172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Archer AX12 V1",
      "cwe": "CWE-78",
      "title": "Command Injection Vulnerability in OpenVPN on Multiple TP-Link Archer Routers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9151"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2025-66273",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01049,
      "epss_percentile": 0.61569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "QTS",
      "cwe": "CWE-78",
      "title": "QTS, QuTS hero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66273"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2025-66279",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01049,
      "epss_percentile": 0.61569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "QTS",
      "cwe": "CWE-78",
      "title": "QTS, QuTS hero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66279"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-42568",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01027,
      "epss_percentile": 0.60893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yamcs",
      "product": "yamcs",
      "cwe": "CWE-90",
      "title": "Yamcs Vulnerable to LDAP Injection in LdapAuthModule",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42568"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-24719",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00977,
      "epss_percentile": 0.59374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "QTS",
      "cwe": "CWE-78",
      "title": "QTS, QuTS hero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24719"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-11417",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00936,
      "epss_percentile": 0.58038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "AWS Cloud Development Kit library",
      "cwe": "CWE-78",
      "title": "OS Command Injection in NodejsFunction Bundling in aws-cdk-lib",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11417"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-52751",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0071,
      "epss_percentile": 0.50709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nationalsecurityagency",
      "product": "ghidra",
      "cwe": "CWE-502",
      "title": "Ghidra < 12.1 - Remote Code Execution via Unfiltered RMI Deserialization in Shared Project Connection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52751"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-50223",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00657,
      "epss_percentile": 0.48706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache OFBiz",
      "cwe": "CWE-94",
      "title": "Apache OFBiz: DataResource Low-Privileged Authenticated FreeMarker Template Injection Leads to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50223"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-42305",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00635,
      "epss_percentile": 0.47722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jelmer",
      "product": "dulwich",
      "cwe": "CWE-22",
      "title": "Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42305"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-2049",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00615,
      "epss_percentile": 0.46797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GIMP",
      "product": "GIMP",
      "cwe": "CWE-122",
      "title": "GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2049"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-9067",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00572,
      "epss_percentile": 0.4476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Schema & Structured Data for WP & AMP",
      "cwe": "CWE-434",
      "title": "Schema & Structured Data for WP & AMP < 1.60 - Unauthenticated Arbitrary Media Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9067"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-45062",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00568,
      "epss_percentile": 0.44577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "php",
      "product": "frankenphp",
      "cwe": "CWE-20",
      "title": "FrankenPHP: Unsafe Unicode Handling in CGI Path Splitting Allows Execution of Non-PHP Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45062"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-42563",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00555,
      "epss_percentile": 0.43901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jelmer",
      "product": "dulwich",
      "cwe": "CWE-78",
      "title": "Dulwich Vulnerable to Command Injection via Merge Driver Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42563"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-42542",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00539,
      "epss_percentile": 0.43066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "taosdata",
      "product": "TDengine",
      "cwe": "CWE-191",
      "title": "TDengine has an integer underflow in uvConnMayGetUserInfo() allows unauthenticated remote crash (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42542"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-46529",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00529,
      "epss_percentile": 0.42508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mate-desktop",
      "product": "atril",
      "cwe": "CWE-77",
      "title": "PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46529"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-10143",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00517,
      "epss_percentile": 0.41823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dana Powers",
      "product": "kafka-python",
      "cwe": "CWE-400",
      "title": "kafka-python prior to 2.3.2 DoS via SCRAM Iteration Count in scram.py",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10143"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-46625",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00512,
      "epss_percentile": 0.41499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "js-cookie",
      "product": "js-cookie",
      "cwe": "CWE-1321",
      "title": "JavaScript Cookie: Per-instance prototype hijack in assign() enables cookie-attribute injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46625"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-52750",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00503,
      "epss_percentile": 0.40961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nationalsecurityagency",
      "product": "ghidra",
      "cwe": "CWE-88",
      "title": "Ghidra < 12.1- Command Injection via URL Annotation Click",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52750"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-49759",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00497,
      "epss_percentile": 0.40617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-121",
      "title": "Stack buffer overflow in SCTP error cause parsing in inet_drv allows remote VM crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49759"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-45031",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00495,
      "epss_percentile": 0.40472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-400",
      "title": "ImageMagick: Policy Bypass in PSD decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45031"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2025-6254",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00494,
      "epss_percentile": 0.40406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AmentoTech",
      "product": "Doctreat Core",
      "cwe": "CWE-269",
      "title": "Doctreat Core <= 1.6.8 - Unauthenticated Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-6254"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-46703",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00482,
      "epss_percentile": 0.39671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boxlite-ai",
      "product": "boxlite",
      "cwe": "CWE-22",
      "title": "BoxLite: Path Traversal Vulnerability in boxlite Leads to Arbitrary File Write on the Host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46703"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-49069",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00476,
      "epss_percentile": 0.39289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPZOOM",
      "product": "WPZOOM Portfolio",
      "cwe": "CWE-79",
      "title": "WordPress WPZOOM Portfolio plugin <= 1.4.21 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49069"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-26241",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00459,
      "epss_percentile": 0.38151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "File Station 5",
      "cwe": "CWE-121",
      "title": "File Station 5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26241"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-52756",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00457,
      "epss_percentile": 0.38021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nationalsecurityagency",
      "product": "ghidra",
      "cwe": "CWE-22",
      "title": "Ghidra < 12.2 - Unauthenticated Path Traversal in Debugger ISF Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52756"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2025-66281",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00456,
      "epss_percentile": 0.37974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "QTS",
      "cwe": "CWE-476",
      "title": "QTS, QuTS hero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66281"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-52726",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00448,
      "epss_percentile": 0.37468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jelmer",
      "product": "dulwich",
      "cwe": "CWE-22",
      "title": "Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurse_submodules=True) yields RCE via attacker-dropped .git/hooks payload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52726"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-25700",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00448,
      "epss_percentile": 0.37422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Answer",
      "cwe": "CWE-1259",
      "title": "Apache Answer: AdminToken not invalidated after admin deactivation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25700"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-26240",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00442,
      "epss_percentile": 0.36976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "File Station 5",
      "cwe": "CWE-121",
      "title": "File Station 5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26240"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-46520",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-122",
      "title": "ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46520"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-45664",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00441,
      "epss_percentile": 0.36847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-400",
      "title": "ImageMagick: Policy Bypass in MNG coder could",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45664"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-45558",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00439,
      "epss_percentile": 0.36708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "roxy-wi",
      "product": "roxy-wi",
      "cwe": "CWE-20",
      "title": "Roxy-WI: Authenticated RCE on every managed HAProxy load balancer via `option` field config injection in section save",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45558"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-45541",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00439,
      "epss_percentile": 0.36707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "espressif",
      "product": "esp-idf",
      "cwe": "CWE-476",
      "title": "ESF-IDF: Remote Null Pointer Dereference in WebSocket Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45541"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2025-66280",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00435,
      "epss_percentile": 0.36449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "QTS",
      "cwe": "CWE-121",
      "title": "QTS, QuTS hero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66280"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2025-71329",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0043,
      "epss_percentile": 0.36049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "image-size",
      "product": "image-size",
      "cwe": "CWE-835",
      "title": "image-size 2.0.2 Denial of Service via Infinite Loop in JXL/HEIF Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71329"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2025-71330",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0043,
      "epss_percentile": 0.36049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "image-size",
      "product": "image-size",
      "cwe": "CWE-835",
      "title": "image-size 2.0.2 Denial of Service via Malformed ICNS Image Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71330"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-26239",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00421,
      "epss_percentile": 0.35329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "File Station 5",
      "cwe": "CWE-121",
      "title": "File Station 5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26239"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-8071",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.34694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Anti-Spam by CleanTalk. Spam protection",
      "cwe": "CWE-79",
      "title": "Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.79 - Unauthenticated Stored XSS via Comment Shortcode Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8071"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-20254",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00408,
      "epss_percentile": 0.34172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-20",
      "title": "Information Disclosure through External Content Restriction Bypass in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20254"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-47342",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00407,
      "epss_percentile": 0.34106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache OFBiz",
      "cwe": "CWE-285",
      "title": "Apache OFBiz: Privilege Escalation via updateOrRemove Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47342"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-29116",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00395,
      "epss_percentile": 0.32858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dahua",
      "product": "IPC/SD/NVR/XVR/EVS/VTO/VTH/ASI/TPC",
      "cwe": "CWE-617",
      "title": "A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially crafted packet, triggering an exception that causes the system to reboot unexpectedly, resulting in a denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29116"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-24717",
      "cvss_base": 1.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00392,
      "epss_percentile": 0.32532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "QTS",
      "cwe": "CWE-22",
      "title": "QTS, QuTS hero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24717"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-22899",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00381,
      "epss_percentile": 0.31453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "File Station 5",
      "cwe": "CWE-476",
      "title": "File Station 5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22899"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-24720",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00381,
      "epss_percentile": 0.31453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "File Station 5",
      "cwe": "CWE-770",
      "title": "File Station 5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24720"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-45556",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.30523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "roxy-wi",
      "product": "roxy-wi",
      "cwe": "CWE-20",
      "title": "Roxy-WI: Authenticated arbitrary file write on every managed load balancer (and downstream RCE) via WAF rule save `config_file_name`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45556"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2025-59382",
      "cvss_base": 1.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00369,
      "epss_percentile": 0.30116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "QTS",
      "cwe": "CWE-472",
      "title": "QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59382"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-46618",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00364,
      "epss_percentile": 0.29649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fission",
      "product": "fission",
      "cwe": "CWE-78",
      "title": "Fission builder accepts arbitrary buildcmd strings from Environment.spec.builder.command, allowing the builder pod to invoke arbitrary executables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46618"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-53437",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00364,
      "epss_percentile": 0.29598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-601",
      "title": "Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between `//`, allowing attackers to perform phishing attacks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53437"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-29115",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00362,
      "epss_percentile": 0.29422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dahua",
      "product": "IPC/SD",
      "cwe": "CWE-617",
      "title": "A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially crafted packet, triggering an exception that causes the system to reboot unexpectedly, resulting in a denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29115"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-20256",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00361,
      "epss_percentile": 0.29351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-20",
      "title": "Improper Input Validation through Protocol-Relative URL in Classic Dashboards in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20256"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-45783",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libp2p",
      "product": "js-libp2p",
      "cwe": "CWE-20",
      "title": "libp2p: Unvalidated PUT_VALUE records allow unbounded disk exhaustion on DHT server nodes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45783"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-48859",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00354,
      "epss_percentile": 0.28674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-208",
      "title": "SSH server timing side-channel in ssh_auth:check_password/3 allows unauthenticated username enumeration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48859"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-46614",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00353,
      "epss_percentile": 0.28517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fission",
      "product": "fission",
      "cwe": "CWE-284",
      "title": "Fission router exposes /fission-function/<ns>/<name> on its public listener, allowing invocation of any function without an HTTPTrigger",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46614"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-53461",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-787",
      "title": "ImageMagick: Out-of-bounds write in ICON decoder due to incorrect loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53461"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-50131",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fedify-dev",
      "product": "fedify",
      "cwe": "CWE-918",
      "title": "Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl allows special-use IPv4 ranges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50131"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-20255",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00351,
      "epss_percentile": 0.28277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-20",
      "title": "Improper Input Validation through Classic Dashboards in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20255"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-11884",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00349,
      "epss_percentile": 0.2813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11",
      "cwe": "CWE-122",
      "title": "389-ds-base: 389-ds-base: heap buffer overflow in schema objectclass serialization due to missing oc_superior in size calculation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11884"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-10142",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dana Powers",
      "product": "kafka-python",
      "cwe": "CWE-789",
      "title": "kafka-python prior to 2.3.2 Denial of Service via Protocol Parser Frame Length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10142"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-20252",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF) through Dashboard Studio PDF Export in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20252"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-46617",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fission",
      "product": "fission",
      "cwe": "CWE-250",
      "title": "Fission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46617"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-49218",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-20",
      "title": "ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49218"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-53460",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-770",
      "title": "ImageMagick: Policy Bypass can trigger out-of-Memory condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53460"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-46612",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fission",
      "product": "fission",
      "cwe": "CWE-306",
      "title": "Fission StorageSvc /v1/archive endpoint exposes unauthenticated CRUD over all function archives",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46612"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-50638",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00343,
      "epss_percentile": 0.27436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PEVANS",
      "product": "Metrics::Any::Adapter::DogStatsd",
      "cwe": "CWE-93",
      "title": "Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50638"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-11604",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00338,
      "epss_percentile": 0.26845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "ovpn-dco-win",
      "cwe": "CWE-122",
      "title": "An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kernel memory corruption via a crafted data packet, resulting in a system crash (denial of service).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11604"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-24724",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00337,
      "epss_percentile": 0.26806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "File Station 5",
      "cwe": "CWE-863",
      "title": "File Station 5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24724"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-48856",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-601",
      "title": "httpc leaks Authorization header to cross-origin redirect targets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48856"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2025-62850",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.2611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "QuTS hero",
      "cwe": "CWE-476",
      "title": "QuTS hero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62850"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-24716",
      "cvss_base": 1.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00331,
      "epss_percentile": 0.26109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "QTS",
      "cwe": "CWE-476",
      "title": "QTS, QuTS hero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24716"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-53698",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00327,
      "epss_percentile": 0.25679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silverpeas",
      "product": "Silverpeas",
      "cwe": "CWE-36",
      "title": "Silverpeas through 6.4.6 mishandles the \"Personal space\" feature that is selected when no componentId is set.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53698"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-45542",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "espressif",
      "product": "esp-idf",
      "cwe": "CWE-122",
      "title": "ESF-IDF: Heap buffer overflow in protocomm Security2 over Bluetooth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45542"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-50637",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PEVANS",
      "product": "Metrics::Any::Adapter::Statsd",
      "cwe": "CWE-93",
      "title": "Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50637"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-26237",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.25061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "QuMagie",
      "cwe": "CWE-862",
      "title": "QuMagie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26237"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-46689",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kanidm",
      "product": "kanidm",
      "cwe": "CWE-248",
      "title": "Kanidm: Unauthenticated process abort via SCIM filter stack exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46689"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-11815",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00317,
      "epss_percentile": 0.24571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Broadcom",
      "product": "Layer 7 API Gateway",
      "cwe": "CWE-502",
      "title": "Insecure Deserialization via MITM in Layer 7 Policy Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11815"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-45569",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "roxy-wi",
      "product": "roxy-wi",
      "cwe": "CWE-22",
      "title": "Roxy-WI: Path-traversal patch in commit d4d10006 is a no-op (tuple-membership bug)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45569"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-52758",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nationalsecurityagency",
      "product": "ghidra",
      "cwe": "CWE-89",
      "title": "Ghidra < 12.1 - SQL Injection via Unescaped Filter Values in BSim Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52758"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-50127",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WeblateOrg",
      "product": "weblate",
      "cwe": "CWE-918",
      "title": "Weblate SSRF: outbound URL guard misses the NAT64 well-known prefix (64:ff9b::/96)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50127"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-45564",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "roxy-wi",
      "product": "roxy-wi",
      "cwe": "CWE-78",
      "title": "Roxy-WI: Authenticated RCE via 'configver' URL parameter (os.system sink in /config/versions/.../save)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45564"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-45565",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "roxy-wi",
      "product": "roxy-wi",
      "cwe": "CWE-20",
      "title": "Roxy-WI: EscapedString validator skips its '..' block when stripping (root cause for several path-traversal/RCE vectors)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45565"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-50567",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fission",
      "product": "fission",
      "cwe": "CWE-22",
      "title": "Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50567"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-46523",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00301,
      "epss_percentile": 0.22786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-416",
      "title": "ImageMagick: Use-After-Free in MSL decoder.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46523"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-50545",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.003,
      "epss_percentile": 0.22624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fission",
      "product": "fission",
      "cwe": "CWE-269",
      "title": "Fission Environment CRD PodSpec Injection Leading to Node Escape and Cluster Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50545"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-53474",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00298,
      "epss_percentile": 0.22434,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "migration-planner",
      "cwe": "CWE-89",
      "title": "Migration-planner: second-order sql injection via rvtools upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53474"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-1220",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.22314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1220"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-53469",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.21999,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "migration-planner",
      "cwe": "CWE-306",
      "title": "Migration-planner: unprotected delete endpoint wipes all tenant data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53469"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-8853",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.2197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "websoudan",
      "product": "MW WP Form",
      "cwe": "CWE-79",
      "title": "MW WP Form <= 5.1.3 - Authenticated (Editor+) Stored Cross-Site Scripting via 'memo' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8853"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-44693",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.2194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pi-hole",
      "product": "FTL",
      "cwe": "CWE-362",
      "title": "Pi-hole FTL: Unauthenticated Session Hijacking via Race Condition on Global Session Buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44693"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-20257",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-20",
      "title": "Improper Input Validation through Classic Dashboard CSS in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20257"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-53476",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21737,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "assisted-migration-agent",
      "cwe": "CWE-22",
      "title": "Assisted-migration-agent: vddk tarball chained-symlink arbitrary file write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53476"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-10740",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "s2n-quic",
      "cwe": "CWE-770",
      "title": "Excessive memory allocation in s2n-quic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10740"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-50566",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0029,
      "epss_percentile": 0.21578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fission",
      "product": "fission",
      "cwe": "CWE-250",
      "title": "Fission: Environment Runtime.Container and Builder.Container SecurityContext bypass allows privileged pod creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50566"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2025-66276",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0029,
      "epss_percentile": 0.21616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "QTS",
      "cwe": null,
      "title": "QTS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66276"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-46695",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00289,
      "epss_percentile": 0.21469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boxlite-ai",
      "product": "boxlite",
      "cwe": "CWE-284",
      "title": "BoxLite: Permission Bypass in boxlite Allows Modification of Read-Only Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46695"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-53471",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21202,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "migration-planner",
      "cwe": "CWE-639",
      "title": "Migration-planner: agent api ignores jwt source_id claim",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53471"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-46497",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00286,
      "epss_percentile": 0.21182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apify",
      "product": "crawlee-python",
      "cwe": "CWE-918",
      "title": "SSRF via sitemap-derived URLs in Crawlee for Python",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46497"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-0274",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.21125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cortex XSIAM CommvaultSecurityIQ Marketplace",
      "cwe": "CWE-1390",
      "title": "Cortex XSOAR: Improper Validation of Credentials in CommvaultSecurityIQ integration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0274"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-53436",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-601",
      "title": "Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains relative path segments (`./` or `../`), allowing attackers to perform phishing attacks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53436"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-46558",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "makeplane",
      "product": "plane",
      "cwe": "CWE-639",
      "title": "Plane: Cross-workspace asset authorization bypass lets any authenticated user read, copy, delete, and overwrite assets in other Plane workspaces",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46558"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-53470",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20569,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "migration-planner",
      "cwe": "CWE-639",
      "title": "Migration-planner: getsourcedownloadurl missing organization check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53470"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-46645",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.20458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smithyhq",
      "product": "sqladmin",
      "cwe": "CWE-862",
      "title": "SQLAdmin: Authorization Bypass on `ajax_lookup`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46645"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-46679",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libp2p",
      "product": "js-libp2p",
      "cwe": "CWE-20",
      "title": "libp2p: Memory DoS via subscription flood of unique topics",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46679"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-53693",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "bsimvis",
      "cwe": "CWE-79",
      "title": "MISP BSimVis stored cross-site scripting in tag and cluster rendering paths via unescaped tag metadata and UI labels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53693"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-48108",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eugeny",
      "product": "russh",
      "cwe": "CWE-20",
      "title": "Russh: SSH identification parsing accepted non-canonical client banners and did not bound pre-banner input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48108"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-48855",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00277,
      "epss_percentile": 0.20177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-200",
      "title": "SFTP READLINK Leaks Absolute Backend Filesystem Path When Root Is Configured",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48855"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-46668",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00276,
      "epss_percentile": 0.20155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "authzed",
      "product": "spicedb",
      "cwe": "CWE-285",
      "title": "SpiceDB: Caveat structures with nested lists can result in improper cache reuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46668"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-50563",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00274,
      "epss_percentile": 0.19903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fission",
      "product": "fission",
      "cwe": "CWE-269",
      "title": "Fission Container Executor Function PodSpec Injection Leading to Node Escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50563"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-50564",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00274,
      "epss_percentile": 0.19903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fission",
      "product": "fission",
      "cwe": "CWE-269",
      "title": "Fission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50564"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-50570",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.1982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fission",
      "product": "fission",
      "cwe": "CWE-269",
      "title": "Fission: Incomplete capability denylist in Environment/Function PodSpec validation allows tenant-added CAP_SYS_TIME and cross-tenant node wall-clock corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50570"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-11853",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Debian",
      "product": "debusine",
      "cwe": "CWE-59",
      "title": "Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages (.dsc) and upload artifacts (.changes) are manifest files that name the files that make up the artifact. The parser used to read these files in Debusine accepted arbitrary fully user-controlled paths. The mergeuploads task could be abused to create arbitrary symbolic links on a worker, overwriting any file that the worker user has access to.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11853"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-46702",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eugeny",
      "product": "russh",
      "cwe": "CWE-770",
      "title": "Russh: Post-decompression SSH packet size was not bounded, allowing remote oversized compressed packets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46702"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-48110",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eugeny",
      "product": "russh",
      "cwe": "CWE-20",
      "title": "Russh: SSH message fields were decoded through allocation-first parsers before field-specific bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48110"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-47213",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boxlite-ai",
      "product": "boxlite",
      "cwe": "CWE-404",
      "title": "BoxLite: Timeout Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47213"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-45552",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00267,
      "epss_percentile": 0.18922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "roxy-wi",
      "product": "roxy-wi",
      "cwe": "CWE-639",
      "title": "Roxy-WI: Cross-tenant authorization bypass on /install/* — guest can run Ansible / SSH on every registered server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45552"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-49823",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.18576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fission",
      "product": "fission",
      "cwe": "CWE-284",
      "title": "Fission: Cross-namespace Package read via unvalidated PackageRef in Function admission webhook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49823"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-50639",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PEVANS",
      "product": "Metrics::Any::Adapter::SignalFx",
      "cwe": "CWE-93",
      "title": "Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50639"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-46673",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.1824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eugeny",
      "product": "russh",
      "cwe": "CWE-770",
      "title": "Russh: Unchecked CryptoVec allocation and growth handling is reachable from local agent inputs in current russh releases and from remote SSH traffic in historical pre-0.58.0 releases",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46673"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-44692",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.1815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code16",
      "product": "sharp",
      "cwe": "CWE-639",
      "title": "Authenticated Sharp users can download unrelated Laravel Storage objects through the generic download endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44692"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-0272",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cloud NGFW",
      "cwe": "CWE-863",
      "title": "PAN-OS: Privilege Escalation (PE) Vulnerability in the Command Line Interface (CLI)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0272"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-53441",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-79",
      "title": "Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the `POST config.xml` API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53441"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-49498",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.1777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nationalsecurityagency",
      "product": "ghidra",
      "cwe": "CWE-89",
      "title": "Ghidra 11.0 < 12.1 - SQL Injection in PostgreSQL Password Change via Unescaped Username",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49498"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2025-62851",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "License Center",
      "cwe": "CWE-22",
      "title": "License Center",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62851"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-11859",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00258,
      "epss_percentile": 0.17644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thinkst Applied Research",
      "product": "Canarytokens",
      "cwe": "CWE-74",
      "title": "HTML injection in the Canarytoken links email",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11859"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-50565",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fission",
      "product": "fission",
      "cwe": "CWE-250",
      "title": "Fission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder container",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50565"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-53475",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.17004,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "assisted-migration-agent",
      "cwe": "CWE-295",
      "title": "Assisted-migration-agent: tls verification disabled on all vcenter connections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53475"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-52754",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nationalsecurityagency",
      "product": "ghidra",
      "cwe": "CWE-347",
      "title": "Ghidra < 12.1 - Authentication Bypass via Null Signature in PKIAuthenticationModule",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52754"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-46683",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KnpLabs",
      "product": "snappy",
      "cwe": "CWE-918",
      "title": "Snappy: SSRF and local file read via the xsl-style-sheet option",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46683"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-53738",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Inisev",
      "product": "Copy & Delete Posts",
      "cwe": "CWE-863",
      "title": "Copy & Delete Posts through 1.5.4 Privilege Escalation via cdp_action_handling Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53738"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-45160",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "espressif",
      "product": "esp-idf",
      "cwe": "CWE-125",
      "title": "ESF-IDF: Out-of-bounds Read in lwIP DHCP Server Option Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45160"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-45567",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.15837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "roxy-wi",
      "product": "roxy-wi",
      "cwe": "CWE-287",
      "title": "Roxy-WI: Authentication bypass via 'api' substring in URL + unauthenticated /api/gpt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45567"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-45358",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.1546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-125",
      "title": "ImageMagick: Out-of-Bounds Read of a single byte in meta encoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45358"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-53440",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.1525,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-601",
      "title": "Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the \"from\" parameter in the \"Delegate to servlet container\" security realm is safe to redirect to after login, allowing attackers to perform phishing attacks by redirecting users to an attacker-controlled domain.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53440"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-11596",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.1501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ConnectWise",
      "product": "ScreenConnect",
      "cwe": "CWE-1284",
      "title": "In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration duration beyond the intended maximum when generating delegated access tokens.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11596"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-49824",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fission",
      "product": "fission",
      "cwe": "CWE-284",
      "title": "Fission: Cross-namespace Environment reference via unvalidated EnvironmentRef in Function admission webhook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49824"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-20258",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) through Classic Dashboard in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20258"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-48858",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-918",
      "title": "ftp client PASV response IP not validated against control peer, enabling SSRF and FTP bounce attacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48858"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-45559",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.1462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "roxy-wi",
      "product": "roxy-wi",
      "cwe": "CWE-90",
      "title": "Roxy-WI: LDAP injection in /user/ldap/<username> (admin-only)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45559"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-53439",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-862",
      "title": "Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other users' configured timezone and to enumerate view names of other users' \"My Views\".",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53439"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-48107",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eugeny",
      "product": "russh",
      "cwe": "CWE-20",
      "title": "Russh: Unchecked keyboard-interactive prompt count in client auth path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48107"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-49821",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fission",
      "product": "fission",
      "cwe": "CWE-441",
      "title": "Fission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49821"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-49822",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fission",
      "product": "fission",
      "cwe": "CWE-284",
      "title": "Fission: Cross-namespace event leakage via KubernetesWatchTrigger allows persistent tenant surveillance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49822"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-46532",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "espressif",
      "product": "esp-idf",
      "cwe": "CWE-125",
      "title": "ESF-IDF: Heap Out-of-Bounds Read in Bluedroid AVRCP Target Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46532"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-48994",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-122",
      "title": "ImageMagick: Heap Buffer Over-Write in MAT decoder on 32-bit systems",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48994"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-53462",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-416",
      "title": "ImageMagick: Use-After-Free when allocation in CheckPrimitiveExtent fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53462"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-50569",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fission",
      "product": "fission",
      "cwe": "CWE-20",
      "title": "Fission: HTTPTrigger admission omits RelativeURL / Prefix validation; kubectl apply bypasses CLI checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50569"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-46669",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openvm-org",
      "product": "openvm",
      "cwe": "CWE-20",
      "title": "`openvm-pairing` pairing check missing proper subfield check on scaling factor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46669"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-0269",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.1327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cloud NGFW",
      "cwe": "CWE-754",
      "title": "PAN-OS: Denial of Service (DoS) in Tunnel Traffic Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0269"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-48011",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00223,
      "epss_percentile": 0.13157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shopware",
      "product": "shopware",
      "cwe": "CWE-208",
      "title": "Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48011"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2024-21944",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "AMD EPYC™ 7003 Series Processors",
      "cwe": "CWE-20",
      "title": "Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to potentially overwrite guest memory resulting in loss of guest data integrity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-21944"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-46642",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jgraph",
      "product": "drawio",
      "cwe": "CWE-79",
      "title": "draw.io: XSS via crafted cell label when opening a .drawio file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46642"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-45561",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "roxy-wi",
      "product": "roxy-wi",
      "cwe": "CWE-918",
      "title": "Roxy-WI: SSRF in /smon/agent/<endpoint>/<server_ip> reachable to cloud metadata IPs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45561"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-46705",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eugeny",
      "product": "russh",
      "cwe": "CWE-287",
      "title": "russh server userauth state is not reset when authentication principal changes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46705"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-52752",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nationalsecurityagency",
      "product": "ghidra",
      "cwe": "CWE-22",
      "title": "Ghidra < 12.0.2 - Path Traversal in Extension Installer via ZIP Entry Names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52752"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-52755",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nationalsecurityagency",
      "product": "ghidra",
      "cwe": "CWE-22",
      "title": "Ghidra < 12.0.4 - Path Traversal via Zip Slip in Theme Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52755"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-53438",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.1195,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-862",
      "title": "A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permission, but lacking Item/Read permission, to cancel queue items they do not have permission to view.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53438"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-53634",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code16",
      "product": "sharp",
      "cwe": "CWE-862",
      "title": "Sharp: Missing Authorization Check in Quick Creation Command Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53634"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-53689",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sahlberg",
      "product": "libnfs",
      "cwe": "CWE-1284",
      "title": "libnfs through 6.0.2 before 55c18ea does not validate a string size, leading to an integer overflow during a connection to a crafted NFS server. This occurs in libnfs_zdr_string in lib/libnfs-zdr.c.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53689"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-45106",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WeblateOrg",
      "product": "weblate",
      "cwe": "CWE-79",
      "title": "Weblate: Stored HTML injection in editor search preview",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45106"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-8613",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "aThemes Addons for Elementor",
      "cwe": "CWE-79",
      "title": "aThemes Addons for Elementor <= 1.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title_tag' Widget Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8613"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-45549",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "roxy-wi",
      "product": "roxy-wi",
      "cwe": "CWE-862",
      "title": "Roxy-WI: Authorization bypass on POST /smon/agent/action/<action> — guest can stop or restart smon-agent on any host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45549"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-11852",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Debian",
      "product": "debusine",
      "cwe": "CWE-862",
      "title": "Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debusine are organized into artifacts. The endpoints that create and delete relationships between artifacts enforced no permissions checks beyond being able to see the artifacts in question.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11852"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-0270",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cortex XSOAR",
      "cwe": "CWE-22",
      "title": "Cortex XSOAR: Path Traversal Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0270"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-20260",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk SOAR",
      "cwe": "CWE-117",
      "title": "Log Injection through HTTP Request Paths in Splunk SOAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20260"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-45550",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00196,
      "epss_percentile": 0.09718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "roxy-wi",
      "product": "roxy-wi",
      "cwe": "CWE-639",
      "title": "Roxy-WI: IDOR on PUT /smon/check — any user can rewrite any tenant's monitoring URL/IP/body",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45550"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-8335",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00195,
      "epss_percentile": 0.09618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aix-DB",
      "product": "Aix-DB",
      "cwe": "CWE-306",
      "title": "Missing authentication in Aix-DB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8335"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-9019",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brechtvds",
      "product": "Easy Image Collage",
      "cwe": "CWE-79",
      "title": "Easy Image Collage <= 1.13.6 - Authenticated (Author+) Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][attachment_url]' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9019"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-48860",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.09513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-863",
      "title": "Distribution-over-TLS LAN allowlist silently bypassed due to sockname/peername confusion in inet_tls_dist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48860"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-53442",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.08968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins",
      "cwe": "CWE-311",
      "title": "Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job configurations unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission, or access to the Jenkins controller file system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53442"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-29114",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0019,
      "epss_percentile": 0.08957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dahua",
      "product": "IPC",
      "cwe": "CWE-538",
      "title": "A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that CA is installed and trusted on client systems, the attacker could issue fraudulent certificates trusted by those clients and undermine the certificate trust chain.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29114"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-20259",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-284",
      "title": "Improper Access Control in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20259"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-47734",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jelmer",
      "product": "dulwich",
      "cwe": "CWE-400",
      "title": "Dulwich has unbounded memory allocation in receive-pack from crafted thin packs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47734"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-53473",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08626,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "migration-planner-ui-app",
      "cwe": "CWE-79",
      "title": "Migration-planner-ui-app: stored xss via javascript: url in agent credential link",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53473"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-53463",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-476",
      "title": "ImageMagick: Null Pointer Dereference in distort operation when passing incorrect arguments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53463"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-49497",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nationalsecurityagency",
      "product": "ghidra",
      "cwe": "CWE-22",
      "title": "Ghidra < 12.1 - Path Traversal via .gnu_debuglink in DWARF External Debug File Resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49497"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-46616",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "umbraco",
      "product": "Umbraco-CMS",
      "cwe": "CWE-601",
      "title": "Umbraco.Cms: Open Redirect Vulnerability in Surface Controllers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46616"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-45563",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "roxy-wi",
      "product": "roxy-wi",
      "cwe": "CWE-639",
      "title": "Roxy-WI: IDOR — any authenticated user can read another user's full action history",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45563"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-42462",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fedify-dev",
      "product": "fedify",
      "cwe": "CWE-180",
      "title": "Fedify has an LD-Signature Bypass via JSON-LD Named-Graph Restructuring",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42462"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-7516",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "Application",
      "cwe": "CWE-749",
      "title": "A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese market, that could allow a website visited by the built-in browser to overwrite system clipboard contents.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7516"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-49496",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nationalsecurityagency",
      "product": "ghidra",
      "cwe": "CWE-416",
      "title": "Ghidra < 12.1 - Heap-Use-After-Free in SleighBuilder::generatePointerAdd via Vector Reallocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49496"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-11837",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00161,
      "epss_percentile": 0.05784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-59",
      "title": "Ansible-collection-ansible-posix: ansible.posix authorized_key: local privilege escalation via symlink-following chown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11837"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-53737",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "saas.group",
      "product": "Juicer",
      "cwe": "CWE-79",
      "title": "Juicer through 1.12.18 Stored Cross-Site Scripting via Unescaped API Response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53737"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2025-58468",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QNAP Systems Inc.",
      "product": "Notification Center",
      "cwe": "CWE-352",
      "title": "Notification Center",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58468"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2025-8444",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wealcoder",
      "product": "Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates",
      "cwe": "CWE-79",
      "title": "Animation Addons for Elementor – GSAP Powered Elementor Addons & Website Templates <= 2.6.7 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting via Multiple Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-8444"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-45566",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "roxy-wi",
      "product": "roxy-wi",
      "cwe": "CWE-601",
      "title": "Roxy-WI: Open redirect on /login?next= via basic-auth userinfo syntax bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45566"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2022-48575",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00153,
      "epss_percentile": 0.0498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS Monterey",
      "cwe": "CWE-287",
      "title": "A person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-48575"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-46643",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.04919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KnpLabs",
      "product": "snappy",
      "cwe": "CWE-78",
      "title": "Snappy: Binary path is never shell-escaped due to an inverted is_executable check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46643"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-49495",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.04761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nationalsecurityagency",
      "product": "ghidra",
      "cwe": "CWE-835",
      "title": "Ghidra 10.2 < 12.1 - Denial of Service via Circular Reference in Mach-O Export Trie Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49495"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-52753",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.04761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nationalsecurityagency",
      "product": "ghidra",
      "cwe": "CWE-789",
      "title": "Ghidra < 12.0.3 - Out-of-Memory in Rust Symbol Demangler via Malformed Symbol",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52753"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-52759",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.04761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ghidra",
      "product": "Ghidra",
      "cwe": "CWE-789",
      "title": "Ghidra < 12.1.1 - Denial of Service via Uncontrolled Memory Allocation in Mach-O Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52759"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-45560",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "roxy-wi",
      "product": "roxy-wi",
      "cwe": "CWE-79",
      "title": "Roxy-WI: Stored XSS in log viewer (wrap_line/highlight_word produce unescaped HTML)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45560"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-10846",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00147,
      "epss_percentile": 0.04473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "ldns",
      "cwe": "CWE-346",
      "title": "Insufficient verification that responses belong to a query",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10846"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-52757",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nationalsecurityagency",
      "product": "ghidra",
      "cwe": "CWE-416",
      "title": "Ghidra < 12.1 - Heap-use-after-free in HighVariable::merge() during decompilation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52757"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-53740",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yoast",
      "product": "Yoast Duplicate Post",
      "cwe": "CWE-79",
      "title": "Yoast Duplicate Post through 4.6 Stored Cross-Site Scripting via Scheduled Republish Notice",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53740"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-53741",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quantumcloud",
      "product": "Simple Link Directory",
      "cwe": "CWE-79",
      "title": "Simple Link Directory through 9.0.4 Stored XSS via sld_no_results_found Option",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53741"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-53742",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quantumcloud",
      "product": "Simple Link Directory",
      "cwe": "CWE-79",
      "title": "Simple Link Directory through 9.0.4 Stored XSS via Embed Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53742"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-10721",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.03805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Concrete CMS",
      "product": "Concrete CMS",
      "cwe": "CWE-502",
      "title": "Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and Search components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10721"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-47712",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00139,
      "epss_percentile": 0.03721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jelmer",
      "product": "dulwich",
      "cwe": "CWE-22",
      "title": "Dulwich doesn't sanitize commit subjects in `porcelain.format_patch`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47712"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-9060",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00138,
      "epss_percentile": 0.0369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Store Locator WordPress",
      "cwe": "CWE-79",
      "title": "Agile Store Locator < 1.6.6 - Admin+ Stored XSS via map_style",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9060"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-49760",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-121",
      "title": "Stack Buffer Overflow in ei_s_print_term at Very Large Integer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49760"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-46609",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.035,
      "kev": false,
      "kev_due_at": null,
      "vendor": "umbraco",
      "product": "Umbraco-CMS",
      "cwe": "CWE-79",
      "title": "Umbraco.Cms: XSS/HTML Injection in Umbraco Backoffice confirmation dialog",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46609"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-53694",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NoMachine",
      "product": "NoMachine",
      "cwe": "CWE-88",
      "title": "Potential local privileges escalation through argument injection in the nxchmod.sh script",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53694"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-24067",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Slate Digital LLC",
      "product": "Slate Digital Connect",
      "cwe": "CWE-367",
      "title": "Slate Digital Connect macOS XPC PID validation privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24067"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-8637",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.03055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "LanSchool Classic",
      "cwe": "CWE-427",
      "title": "A potential uncontrolled search path vulnerability was reported in the LanSchool Classic client application that could allow a local authenticated user to execute arbitrary code with elevated privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8637"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-0266",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00129,
      "epss_percentile": 0.02981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cloud NGFW",
      "cwe": "CWE-79",
      "title": "PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0266"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-49219",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-22",
      "title": "ImageMagick: Policy Bypass can read disallowed files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49219"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-45328",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.0274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "espressif",
      "product": "esp-idf",
      "cwe": "CWE-787",
      "title": "ESF-IDF: Out-of-Bounds Write in ESP-TEE Secure Service Wrappers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45328"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-45384",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rikyoz",
      "product": "bit7z",
      "cwe": "CWE-59",
      "title": "bit7z: Arbitrary File Overwrite via Symlink Attack on Predictable Temp File During Archive Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45384"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-24066",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Slate Digital LLC",
      "product": "Slate Digital Connect",
      "cwe": "CWE-296",
      "title": "Slate Digital Connect macOS XPC certificate validation privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24066"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-45359",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-125",
      "title": "ImageMagick: Out-of-Bounds Read in connected components when the user supplies an invalid keep-top define",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45359"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2025-10238",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "X13 Gen 6 (Type 21RK, 21RL) Laptops (ThinkPad) BIOS",
      "cwe": "CWE-787",
      "title": "During an internal security assessment, a potential out-of-bounds write vulnerability was discovered in the BIOS of some ThinkPad products could allow a privileged local user to execute code in System Management Mode (SMM).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-10238"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-46557",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-674",
      "title": "ImageMagick: Stack overflow in fx operation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46557"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-42326",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-125",
      "title": "ImageMagick: Heap Buffer Over-Read in IPTC encoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42326"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-45624",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-125",
      "title": "ImageMagick: Heap Buffer Over-Read of a 4 bytes in distort operation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45624"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-9758",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00119,
      "epss_percentile": 0.0209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Systerel",
      "product": "S2OPC",
      "cwe": "CWE-295",
      "title": "Improper Certificate Validation in S2OPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9758"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-45329",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "espressif",
      "product": "esp-idf",
      "cwe": "CWE-20",
      "title": "ESF-IDF: Out-of-Bounds Read in ESP-TEE Secure Service Wrappers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45329"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-46559",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-193",
      "title": "ImageMagick: Heap Buffer Over-Write of a single byte in the JP2 encoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46559"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-45380",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00116,
      "epss_percentile": 0.0187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rikyoz",
      "product": "bit7z",
      "cwe": "CWE-22",
      "title": "bit7z: Path Traversal via Null Byte Injection from `gcount()` Off-by-One in `restoreSymlink()`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45380"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-50568",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00114,
      "epss_percentile": 0.01768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fission",
      "product": "fission",
      "cwe": "CWE-41",
      "title": "Fission: SanitizeFilePath lexical HasPrefix bypass permits sibling-directory escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50568"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-53465",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-122",
      "title": "ImageMagick: Heap Buffer Over-Write in SF3 encoder when writing multi-frame image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53465"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-46521",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-131",
      "title": "ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46521"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-53464",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-401",
      "title": "ImageMagick: Memory Leak in wand option parser when providing invalid arguments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53464"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-42558",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xibosignage",
      "product": "xibo-cms",
      "cwe": "CWE-79",
      "title": "Xibo Vulnerable to Stored XSS and Iframe Sandbox Escape via Data Connector Script in DataSet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42558"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2024-58350",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0011,
      "epss_percentile": 0.01469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nationalsecurityagency",
      "product": "ghidra",
      "cwe": "CWE-758",
      "title": "Ghidra < 11.2 - Use After Free in Sleigh Backend via Static Initialization Order",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-58350"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-0271",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Prisma Access Agent",
      "cwe": "CWE-732",
      "title": "Prisma Access Agent: Local Privilege Escalation by Authorized Users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0271"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-47165",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-200",
      "title": "ImageMagick: Information Disclosure in distributed pixel cache server because it is not using a challenge–response authentication model",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47165"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-46654",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00108,
      "epss_percentile": 0.01388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Plonky3",
      "product": "Plonky3",
      "cwe": "CWE-345",
      "title": "Plonky3 MultiField32Challenger: transcript malleability and challenge entropy loss",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46654"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-6090",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00108,
      "epss_percentile": 0.01381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "Smart Connect",
      "cwe": "CWE-290",
      "title": "A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6090"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-48734",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-674",
      "title": "ImageMagick: Stack Overflow in MVG decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48734"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-11626",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Broadcom",
      "product": "Symantec Endpoint Protection CleanWipe Removal Tool",
      "cwe": "CWE-250",
      "title": "Local Privilege Escalation in Symantec Endpoint Protection macOS CleanWipe Removal Tool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11626"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-48724",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.01149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-787",
      "title": "ImageMagick: Heap Buffer Underwrite in Floyd-Steinberg depth dithering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48724"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-53736",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.01164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bplugins",
      "product": "Easy Twitter Feeds",
      "cwe": "CWE-352",
      "title": "Easy Twitter Feeds before 1.2.13 Cross-Site Request Forgery via duplicate_post Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53736"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-53739",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.01164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yoast",
      "product": "Yoast Duplicate Post",
      "cwe": "CWE-352",
      "title": "Yoast Duplicate Post through 4.6 Cross-Site Request Forgery via duplicate_post_dismiss_notice",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53739"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-0267",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.0118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "GlobalProtect App",
      "cwe": "CWE-532",
      "title": "GlobalProtect App: Information Exposure Vulnerability on macOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0267"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-9045",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00102,
      "epss_percentile": 0.01065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "Accessories and Display Manager for Enterprise",
      "cwe": "CWE-306",
      "title": "During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9045"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-48096",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.01025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openfga",
      "product": "openfga",
      "cwe": "CWE-345",
      "title": "OpenFGA: Cache-key delimiter injection in openfga/openfga shared-iterator and v2 iterator caches enables intra-store authorization-decision poisoning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48096"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2022-26758",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00099,
      "epss_percentile": 0.00934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS Monterey",
      "cwe": "CWE-362",
      "title": "A malicious application may cause unexpected changes in memory shared between processes. A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.4.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-26758"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-0268",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Prisma Access Agent",
      "cwe": "CWE-424",
      "title": "Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0268"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-47166",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-125",
      "title": "ImageMagick: Heap Buffer Over-Read in distributed pixel cache server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47166"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-48733",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-835",
      "title": "ImageMagick: Infinite Loop in subimage-search with crafted image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48733"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-46692",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00092,
      "epss_percentile": 0.00608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-122",
      "title": "ImageMagick: Heap Buffer Over-Write in distributed pixel cache server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46692"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2025-10237",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00077,
      "epss_percentile": 0.00132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "X13 Gen 6 (Type 21RK, 21RL) Laptops (ThinkPad) BIOS",
      "cwe": "CWE-327",
      "title": "During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform arbitrary reads or writes to privileged memory regions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-10237"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-46693",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00077,
      "epss_percentile": 0.00132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-362",
      "title": "ImageMagick: Race Condition in distributed pixel cache server can result in file descriptor hijacking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46693"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-1220",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-1220 (Google Chrome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42542",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42542 (taosdata TDengine). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46558",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46558 (makeplane plane). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46642",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46642 (jgraph drawio). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49495",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49495 (nationalsecurityagency ghidra). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49496",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49496 (nationalsecurityagency ghidra). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49497",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49497 (nationalsecurityagency ghidra). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-52751",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-52751 (nationalsecurityagency ghidra). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-52752",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-52752 (nationalsecurityagency ghidra). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-52753",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-52753 (nationalsecurityagency ghidra). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-52755",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-52755 (nationalsecurityagency ghidra). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-52756",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-52756 (nationalsecurityagency ghidra). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-52757",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-52757 (nationalsecurityagency ghidra). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-52759",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-52759 (Ghidra). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
