{
  "day": "2026-06-11",
  "boundary": "UTC calendar day",
  "published_count": 194,
  "by_severity": {
    "CRITICAL": 20,
    "HIGH": 96,
    "MEDIUM": 71,
    "LOW": 7
  },
  "kev_count": 1,
  "exploit_reference_count": 7,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-10520",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.99902,
      "epss_percentile": 0.99966,
      "kev": true,
      "kev_due_at": "2026-06-14",
      "vendor": "ivanti",
      "product": "Sentry",
      "cwe": "CWE-78",
      "title": "Ivanti Sentry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10520"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-10795",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.03578,
      "epss_percentile": 0.88453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "davidanderson",
      "product": "UpdraftPlus: WP Backup & Migration Plugin",
      "cwe": "CWE-347",
      "title": "UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10795"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-49261",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01582,
      "epss_percentile": 0.73556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MariaDB",
      "product": "server",
      "cwe": "CWE-78",
      "title": "MariaDB server has unsafe parameter handling in `wsrep_notify_cmd`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49261"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-42647",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01323,
      "epss_percentile": 0.68628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Beardev",
      "product": "JoomSport",
      "cwe": "CWE-89",
      "title": "WordPress JoomSport plugin <= 5.7.7 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42647"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-44494",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01041,
      "epss_percentile": 0.61313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axios",
      "product": "axios",
      "cwe": "CWE-441",
      "title": "Axios: Full Man-in-the-Middle via Prototype Pollution Gadget in `config.proxy`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44494"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-44249",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.01025,
      "epss_percentile": 0.60852,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-284",
      "title": "Netty has an IPv6 Subnet Filter Bypass via Incorrect Comparator Masking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44249"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-48547",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0091,
      "epss_percentile": 0.57195,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lingdojo",
      "product": "kana-dojo",
      "cwe": "CWE-78",
      "title": "KanaDojo < 0.1.18 Command Injection via patchNotesData.json in release.yml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48547"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-44492",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0087,
      "epss_percentile": 0.55997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axios",
      "product": "axios",
      "cwe": "CWE-918",
      "title": "Axios: shouldBypassProxy does not recognize IPv4-mapped IPv6 addresses, allowing NO_PROXY bypass (incomplete fix for CVE-2025-62718)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44492"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-11774",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00796,
      "epss_percentile": 0.53595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11.5 E4S for RHEL 8",
      "cwe": "CWE-190",
      "title": "389-ds-base: 389-ds-base: integer overflow in sasl packet length bypasses size limit leading to heap buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11774"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-44495",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00777,
      "epss_percentile": 0.53019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axios",
      "product": "axios",
      "cwe": "CWE-94",
      "title": "Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44495"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-44487",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00664,
      "epss_percentile": 0.48978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axios",
      "product": "axios",
      "cwe": "CWE-201",
      "title": "Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect in Axios Node.js HTTP Adapter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44487"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-44486",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0066,
      "epss_percentile": 0.488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axios",
      "product": "axios",
      "cwe": "CWE-200",
      "title": "Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to direct connection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44486"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-44488",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00622,
      "epss_percentile": 0.47141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axios",
      "product": "axios",
      "cwe": "CWE-770",
      "title": "Axios: Allocation of Resources Without Limits or Throttling in axios",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44488"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-44496",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00622,
      "epss_percentile": 0.47142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axios",
      "product": "axios",
      "cwe": "CWE-400",
      "title": "Axios: Regular Expression Denial of Service (ReDoS) via Cookie Name Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44496"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-42846",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00603,
      "epss_percentile": 0.46201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MacWarrior",
      "product": "clipbucket-v5",
      "cwe": "CWE-78",
      "title": "ClipBucket: Remote Play URL Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42846"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-11816",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00563,
      "epss_percentile": 0.44373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "keras-team",
      "product": "keras-team/keras",
      "cwe": "CWE-22",
      "title": "Path Traversal in keras-team/keras",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11816"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-45172",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0055,
      "epss_percentile": 0.43667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CyberArk Software, a Palo Alto Networks Company",
      "product": "PAM Self-Hosted, Privilege Cloud",
      "cwe": "CWE-78",
      "title": "Idira Privileged Session Manager for SSH (PSMP): Arbitrary Command Execution via Improper Neutralization of Special Elements used in an OS Command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45172"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-45171",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00544,
      "epss_percentile": 0.43307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CyberArk Software, a Palo Alto Networks Company",
      "product": "Privileged Session Manager, Vault",
      "cwe": "CWE-22",
      "title": "Idira Privileged Session Manager (PSM): Potential Code Execution due to an Incomplete Input Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45171"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-49973",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00543,
      "epss_percentile": 0.43298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nesquena",
      "product": "hermes-webui",
      "cwe": "CWE-306",
      "title": "Hermes WebUI < 0.51.358 Unauthenticated Password Takeover via /api/settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49973"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-5497",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00543,
      "epss_percentile": 0.43294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm-project/vllm",
      "cwe": "CWE-400",
      "title": "Unbounded Frame Count in video/jpeg Base64 Data URL Processing Leads to OOM DoS in vllm-project/vllm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5497"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-49060",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00514,
      "epss_percentile": 0.41603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hippoo",
      "product": "Hippoo Mobile App for WooCommerce",
      "cwe": "CWE-266",
      "title": "WordPress Hippoo Mobile App for WooCommerce plugin <= 1.9.4 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49060"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-45177",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00503,
      "epss_percentile": 0.40952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CyberArk Software, a Palo Alto Networks Company",
      "product": "Conjur Cloud (Edge Finding only)",
      "cwe": "CWE-284",
      "title": "Idira Secrets Manager SaaS Edge: Authentication Bypass of an internal validation mechanism",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45177"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-49982",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00496,
      "epss_percentile": 0.40517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "raszi",
      "product": "node-tmp",
      "cwe": "CWE-20",
      "title": "tmp: Type-confusion bypass of _assertPath in tmp@0.2.6 allows path traversal via non-string prefix/postfix/template",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49982"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-48546",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00487,
      "epss_percentile": 0.4,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lingdojo",
      "product": "kana-dojo",
      "cwe": "CWE-693",
      "title": "KanaDojo < 0.1.18 Sandbox Escape RCE via messages.cjs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48546"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-6250",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00463,
      "epss_percentile": 0.38451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Tapo C110 v2",
      "cwe": "CWE-134",
      "title": "Authenticated Format String Injection on TP-Link Tapo C110",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6250"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-44250",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00461,
      "epss_percentile": 0.38289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-400",
      "title": "Netty: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44250"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-44890",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00461,
      "epss_percentile": 0.38289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-400",
      "title": "Netty has Unbounded Direct Memory Consumption in its RedisDecoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44890"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-11561",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00449,
      "epss_percentile": 0.37534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Soagen Informatics Technologies Software and Consulting Inc.",
      "product": "Apinizer",
      "cwe": "CWE-917",
      "title": "SSTI in Soagen Informatics' Apinizer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11561"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-3329",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonatype",
      "product": "Nexus Repository Manager",
      "cwe": "CWE-307",
      "title": "Nexus Repository Manager - Improper Restriction of Excessive Authentication Attempts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3329"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-41699",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0043,
      "epss_percentile": 0.36035,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring for GraphQL",
      "cwe": "CWE-502",
      "title": "Unsafe Deserialization in Spring GraphQL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41699"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-53806",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00419,
      "epss_percentile": 0.35107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-367",
      "title": "OpenClaw < 2026.5.12 - Shell Option Parsing Bypass in Exec Revalidation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53806"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-53810",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00419,
      "epss_percentile": 0.35157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-829",
      "title": "OpenClaw < 2026.5.18 - Arbitrary Code Execution via Unscanned Marketplace Runtime Extension Metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53810"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-39494",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0039,
      "epss_percentile": 0.3228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WBW Plugins",
      "product": "Product Filter by WBW",
      "cwe": "CWE-89",
      "title": "WordPress Product Filter by WBW plugin <= 3.1.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39494"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-40999",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00383,
      "epss_percentile": 0.31584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Web Services",
      "cwe": "CWE-918",
      "title": "Spring WS SSRF via unvalidated WS-Addressing reply destinations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40999"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-53777",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00379,
      "epss_percentile": 0.31192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PerryTS",
      "product": "perry",
      "cwe": "CWE-22",
      "title": "Perry < 0.5.1159 Path Traversal via ArtifactReady WebSocket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53777"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-46519",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flux159",
      "product": "mcp-server-kubernetes",
      "cwe": "CWE-863",
      "title": "mcp-server-kubernetes Affected By Tool Access Control Bypass: Presentation-Layer Filtering Without Execution-Layer Enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46519"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-7250",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.3022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7250"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-40997",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00366,
      "epss_percentile": 0.29793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Web Services",
      "cwe": "CWE-209",
      "title": "SOAP security faults leak Spring Security account state",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40997"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-45060",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00364,
      "epss_percentile": 0.2966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MacWarrior",
      "product": "clipbucket-v5",
      "cwe": "CWE-89",
      "title": "ClipBucket: Blind SQL Injection in progress_video.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45060"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-45178",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CyberArk Software, a Palo Alto Networks Company",
      "product": "Conjur Enterprise",
      "cwe": "CWE-284",
      "title": "Idira Secrets Manager Self-Hosted: Improper Access Control in Internal Cluster Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45178"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-7852",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.2901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Limatek System Inc.",
      "product": "LimRAD NAC",
      "cwe": "CWE-434",
      "title": "Unrestricted File Upload in Limatek's LimRAD NAC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7852"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-44705",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "raszi",
      "product": "node-tmp",
      "cwe": "CWE-22",
      "title": "tmp: Path Traversal via unsanitized prefix/postfix enables directory escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44705"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-40998",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Web Services",
      "cwe": "CWE-611",
      "title": "Jaxp13 XPath XXE via StreamSource and SAXSource",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40998"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-41856",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.2838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring for GraphQL",
      "cwe": "CWE-284",
      "title": "Spring GraphQL Annotation Detection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41856"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-7870",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-427",
      "title": "IBM i is Affected by Privilege Escalation []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7870"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-53816",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-862",
      "title": "OpenClaw < 2026.5.18 - Exec Lifecycle Event Forgery via Paired Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53816"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-11839",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00335,
      "epss_percentile": 0.26557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Başarsoft Information Technologies Inc.",
      "product": "Rotaban",
      "cwe": "CWE-434",
      "title": "Arbitrary File Upload in Basarsoft's Rotaban",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11839"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-38581",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00329,
      "epss_percentile": 0.25894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFormMain parameter to /substudy/ezform.php (line 14) and the id parameter (line 49). The parameters are concatenated directly into SQL queries without sanitization or parameterized statements.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38581"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-53781",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00329,
      "epss_percentile": 0.25866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "steipete",
      "product": "summarize",
      "cwe": "CWE-770",
      "title": "Summarize < 0.17.0 Disk Exhaustion via Uncapped Media Download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53781"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-47172",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00324,
      "epss_percentile": 0.25298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "duck-organization",
      "product": "quest-bot",
      "cwe": "CWE-829",
      "title": "Quest Bot: Untrusted pull request code can be built and deployed by privileged `workflow_run` deployment.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47172"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-47171",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "duck-organization",
      "product": "quest-bot",
      "cwe": "CWE-116",
      "title": "Quest Bot: Reminder messages allow stored mass mentions through `@everyone` and `@here`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47171"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-1500",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00321,
      "epss_percentile": 0.25026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1500"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-47174",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00312,
      "epss_percentile": 0.23944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "duck-organization",
      "product": "duck-site",
      "cwe": "CWE-829",
      "title": "Duck Site: Untrusted pull request code can trigger privileged production deployment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47174"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-53901",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.23944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cerebrate",
      "product": "cerebrate",
      "cwe": "CWE-20",
      "title": "Cerebrate before v1.37 allows mass assignment of record identifiers during object creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53901"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-53807",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.23998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw < 2026.5.6 - Authorization Bypass in Telegram Interactive Callbacks via commands.allowFrom",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53807"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-46489",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolidInvoice",
      "product": "SolidInvoice",
      "cwe": "CWE-79",
      "title": "SolidInvoice: Unrestricted file upload with no MIME validation allows stored XSS via malicious SVG logo",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46489"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-53817",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-290",
      "title": "OpenClaw < 2026.5.22 - Control UI Locality Spoofing in Device Pairing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53817"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-53811",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-290",
      "title": "OpenClaw < 2026.5.7 - Privilege Escalation via Mutable Display Names in Matrix allowFrom",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53811"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-45418",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MacWarrior",
      "product": "clipbucket-v5",
      "cwe": "CWE-89",
      "title": "ClipBucket: Blind SQL Injection in subtitle_edit.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45418"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-47189",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "duck-organization",
      "product": "quest-bot",
      "cwe": "CWE-639",
      "title": "Quest Bot: AutoMod removal can delete rules from another guild by global rule ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47189"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-52859",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00303,
      "epss_percentile": 0.22953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-125",
      "title": "Vim: Out-of-bounds Read in Terminal Screen Snapshot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52859"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-11986",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00301,
      "epss_percentile": 0.2273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.6",
      "cwe": "CWE-425",
      "title": "Keycloak-rest-admin-ui-ext: authorization bypass vulnerability in the admin-ui-ext bulk role-mapping-delete endpoints of keycloak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11986"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-53819",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-426",
      "title": "OpenClaw < 2026.5.27 - Arbitrary Homebrew Executable Execution via Workspace .env Override",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53819"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-12007",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Core in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12007"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-44490",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axios",
      "product": "axios",
      "cwe": "CWE-1321",
      "title": "Axios: DoS & Header Injection via Prototype Pollution Read-Side Gadgets in axios merge functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44490"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-53814",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-266",
      "title": "OpenClaw < 2026.5.20 - Privilege Escalation via Hook-Triggered CLI MCP Tool Authority",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53814"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-12010",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12010"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2023-33999",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPVibes",
      "product": "WP Mail Log",
      "cwe": "CWE-79",
      "title": "WordPress WP Mail Log plugin <= 1.0.2 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-33999"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2025-46315",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-284",
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.1. An app may be able to access protected user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-46315"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-47250",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00267,
      "epss_percentile": 0.18923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flux159",
      "product": "mcp-server-kubernetes",
      "cwe": "CWE-88",
      "title": "mcp-server-kubernetes: kubectl-generic flag injection enables Kubernetes bearer token exfiltration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47250"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-53782",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.18498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "steipete",
      "product": "summarize",
      "cwe": "CWE-918",
      "title": "Summarize < 0.17.0 SSRF via podcast:transcript URL fetch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53782"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-47173",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "duck-organization",
      "product": "quest-bot",
      "cwe": "CWE-116",
      "title": "Quest Bot: Ticket reason allows mass-mention injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47173"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-11850",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-191",
      "title": "Krb5: krb5: integer underflow in berval2tl_data() leads to heap out-of-bounds read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11850"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-53661",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.1775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "malach-it",
      "product": "boruta-server",
      "cwe": "CWE-614",
      "title": "boruta-server sent sensitive session cookies without the Secure attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53661"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-45802",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Setasign",
      "product": "FPDI",
      "cwe": "CWE-400",
      "title": "FPDI: Memory Exhaustion and Endless Loop in FPDI leads to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45802"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-8589",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-79",
      "title": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8589"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-12019",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.17042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Heap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12019"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-49949",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.1704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "steipete",
      "product": "CodexBar",
      "cwe": "CWE-522",
      "title": "CodexBar < 0.33.0 Credential Leakage via HTTP Redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49949"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-6338",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.16992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kong",
      "product": "Kong Enterprise Gateway",
      "cwe": "CWE-444",
      "title": "HTTP request smuggling in Kong Enteprise Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6338"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-47181",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PenguinMod",
      "product": "PenguinMod-BackendApi",
      "cwe": "CWE-20",
      "title": "PenguinMod-BackendApi: NoSQL Injection in Password Reset Endpoint Allows Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47181"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-47176",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "duck-organization",
      "product": "quest-bot",
      "cwe": "CWE-200",
      "title": "Quest Bot: Logging module can disclose private-channel message contents to a lower-visibility log channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47176"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-47177",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "duck-organization",
      "product": "quest-bot",
      "cwe": "CWE-200",
      "title": "Quest Bot: Ticket transcripts can disclose private ticket contents to a lower-visibility channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47177"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-47162",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-74",
      "title": "Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47162"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-10087",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-79",
      "title": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10087"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-7787",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-639",
      "title": "Unauthenticated Session History Access via Public Flow Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7787"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-11945",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DALIBO",
      "product": "PostgreSQL Anonymizer",
      "cwe": "CWE-89",
      "title": "PostgreSQL Anonymizer: SQL injection in the rules import functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11945"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-9204",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF) in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9204"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-53812",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-918",
      "title": "OpenClaw < 2026.5.18 - Private-Network Navigation Bypass via Browser Act Interactions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53812"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-12008",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12008"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-12009",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12009"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-12011",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebMIDI in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12011"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-53912",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cerebrate",
      "product": "cerebrate",
      "cwe": "CWE-200",
      "title": "Cerebrate self-registration password hash exposure via inbox and audit log views",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53912"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-47169",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "duck-organization",
      "product": "quest-bot",
      "cwe": "CWE-266",
      "title": "Quest Bot: Manage Server users can configure AutoRole to grant Administrator to controlled joining accounts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47169"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-8406",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OS4ED",
      "product": "openSIS-Classic",
      "cwe": "CWE-639",
      "title": "openSIS Classic 9.3 - Insecure Direct Object Reference in Sent Mail",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8406"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-12026",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Video in Google Chrome on ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12026"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-3553",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00236,
      "epss_percentile": 0.14839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3553"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-47175",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00235,
      "epss_percentile": 0.14642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "duck-organization",
      "product": "quest-bot",
      "cwe": "CWE-116",
      "title": "Quest Bot: Moderation reason fields allow bot-powered `@everyone` / `@here` pings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47175"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-47188",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00235,
      "epss_percentile": 0.14643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "duck-organization",
      "product": "quest-bot",
      "cwe": "CWE-116",
      "title": "Quest Bot: Unban and unwarn reason fields still allow bot-powered mass mentions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47188"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-46697",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stefanbohacek",
      "product": "fediverse-embeds-wordpress-plugin",
      "cwe": "CWE-918",
      "title": "Fediverse Embeds: Unauthenticated SSRF / open proxy via REST media-proxy endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46697"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2022-45813",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.1403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BeRocket",
      "product": "Advanced AJAX Product Filters",
      "cwe": "CWE-862",
      "title": "WordPress Advanced AJAX Product Filters plugin <= 1.6.3.3 - Broken Access Control + CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-45813"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2025-46308",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-284",
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. An app may be able to leak sensitive user information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-46308"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-12016",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.13992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12016"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-12023",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.13992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in GPU in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12023"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-12028",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.13992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12028"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-40994",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.14014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Web Services",
      "cwe": "CWE-1188",
      "title": "Wss4jSecurityInterceptor disables WS-I BSP validation by default",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40994"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-46698",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.1399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stefanbohacek",
      "product": "fediverse-embeds-wordpress-plugin",
      "cwe": "CWE-918",
      "title": "Fediverse Embeds: Public-nonce SSRF via ftf_get_site_info AJAX action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46698"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-53702",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-787",
      "title": "Gstreamer1-plugins-bad-free: gstreamer: stack buffer overflow in h.265 buffering period sei parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53702"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-44489",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axios",
      "product": "axios",
      "cwe": "CWE-113",
      "title": "Axios: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44489"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-12015",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12015"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-12025",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12025"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-12012",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12012"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-40985",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Web Flow",
      "cwe": "CWE-917",
      "title": "Data Binding Vulnerability in Spring Web Flow with Unified EL Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40985"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-12027",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00224,
      "epss_percentile": 0.13328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-250",
      "title": "Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12027"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-12020",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12020"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-52860",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-94",
      "title": "Vim: Arbitrary Code Execution via Python Omni-Completion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52860"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-9648",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00223,
      "epss_percentile": 0.13164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Haskell Programming Language",
      "product": "crypton-certificate",
      "cwe": null,
      "title": "CVE-2026-9648",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9648"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-41000",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00223,
      "epss_percentile": 0.1316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Web Services",
      "cwe": "CWE-294",
      "title": "WSS4J validation does not use configured replay cache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41000"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-10733",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.1282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-1021",
      "title": "Improper Restriction of Rendered UI Layers or Frames in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10733"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-53723",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.1271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guzzle",
      "product": "guzzle-services",
      "cwe": "CWE-20",
      "title": "guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53723"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-47163",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "duck-organization",
      "product": "quest-bot",
      "cwe": "CWE-862",
      "title": "Quest Bot: Unprivileged users can create and remove AutoMod rules.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47163"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-53815",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-862",
      "title": "OpenClaw < 2026.5.19 - Channel Allowlist Bypass in Message Read Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53815"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-9694",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-153",
      "title": "Improper Neutralization of Substitution Characters in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9694"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-40987",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Integration",
      "cwe": "CWE-22",
      "title": "Remote-file synchronizer in Spring Integration writes server-supplied filename under localDirectory without canonicalization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40987"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-47170",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.11315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "garlic-signage",
      "product": "garlic-hub",
      "cwe": "CWE-918",
      "title": "Garlic-Hub: SSRF vulnerability in uploadFromUrl endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47170"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-12017",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00208,
      "epss_percentile": 0.11309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12017"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-4764",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00207,
      "epss_percentile": 0.11121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google Cloud",
      "product": "Dialogflow CX",
      "cwe": "CWE-862",
      "title": "Privilege Escalation in Dialogflow CX via Playbook Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4764"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-53911",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cerebrate",
      "product": "cerebrate",
      "cwe": "CWE-639",
      "title": "Cerebrate primary key mass assignment in CRUD edit operations allows authenticated users to overwrite unrelated records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53911"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-53701",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.11026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-787",
      "title": "Gstreamer1-plugins-bad-free: gstreamer: out-of-bounds write in h.266/vvc pps picture partition parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53701"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-8464",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.10753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Neuron Soft",
      "product": "Golem OEE MES",
      "cwe": "CWE-22",
      "title": "Path traversal in Neuron Soft Golem OEE MES",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8464"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-52858",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.10382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-94",
      "title": "Vim: Arbitrary Code Execution via Python Omni-Completion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52858"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-40986",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Web Flow",
      "cwe": "CWE-79",
      "title": "Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40986"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-47238",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MacWarrior",
      "product": "clipbucket-v5",
      "cwe": "CWE-639",
      "title": "ClipBucket: IDOR in videos subtitle editor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47238"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-48998",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guzzle",
      "product": "psr7",
      "cwe": "CWE-918",
      "title": "guzzlehttp/psr7 has Host Confusion via Authority Reinterpretation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48998"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-50005",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00197,
      "epss_percentile": 0.09849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brickcom",
      "product": "Cube",
      "cwe": "CWE-1392",
      "title": "Brickcom Cameras Use of Default Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50005"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-46622",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00197,
      "epss_percentile": 0.09766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolidInvoice",
      "product": "SolidInvoice",
      "cwe": "CWE-312",
      "title": "SolidInvoice: API tokens stored as plaintext in the database allowing full credential compromise on database breach",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46622"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-47157",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "subzeroid",
      "product": "aiograpi",
      "cwe": "CWE-918",
      "title": "aiograpi: Unsafe signup challenge path handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47157"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-53808",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw < 2026.5.6 - Approval Policy Bypass in Skill Workshop Apply Flow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53808"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-12029",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.09133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Video in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12029"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-12030",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.09132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12030"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-12031",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.09133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12031"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-11956",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TwiN",
      "product": "gatus",
      "cwe": "CWE-614",
      "title": "TwiN gatus OIDC Session Cookie oidc.go setSessionCookie missing secure attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11956"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-49214",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.08975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guzzle",
      "product": "psr7",
      "cwe": "CWE-20",
      "title": "guzzlehttp/psr7 has CRLF Injection via URI Host Component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49214"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-41700",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.0886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring for GraphQL",
      "cwe": "CWE-346",
      "title": "Cross-Site WebSocket Hijacking in Spring for GraphQL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41700"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-12033",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the GPU process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12033"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2023-40200",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Essential Plugin",
      "product": "WP Logo Showcase Responsive Slider and Carousel",
      "cwe": "CWE-639",
      "title": "WordPress WP Logo Showcase Responsive Slider and Carousel plugin <= 3.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-40200"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-2827",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "100plugins",
      "product": "Open User Map PRO",
      "cwe": "CWE-79",
      "title": "Open User Map PRO <= 1.4.31 - Unauthenticated Stored Cross-Site Scripting via 'oum_location_notification'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2827"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-12035",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00187,
      "epss_percentile": 0.08626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12035"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-6269",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6269"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2023-32959",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sparkle WP",
      "product": "MetroStore",
      "cwe": "CWE-862",
      "title": "WordPress MetroStore theme <= 1.3.2 - Broken Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-32959"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-6277",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6277"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-12034",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12034"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2022-42479",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TemplateHouse",
      "product": "Soledad",
      "cwe": "CWE-862",
      "title": "WordPress Soledad premium theme <= 8.2.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-42479"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2023-25969",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeHunk",
      "product": "Contact Form & Lead Form Elementor Builder",
      "cwe": "CWE-862",
      "title": "WordPress Contact Form & Lead Form Elementor Builder plugin <= 1.8.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-25969"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-12014",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.07185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Cast in Google Chrome prior to 149.0.7827.115 allowed an attacker on the local network segment to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12014"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-49482",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MacWarrior",
      "product": "clipbucket-v5",
      "cwe": "CWE-155",
      "title": "ClipBucket: SQL Wildcard Injection in Subtitle Edit Endpoint Allows Mass Subtitle Overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49482"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-12022",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.06283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12022"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-45173",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00161,
      "epss_percentile": 0.05849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CyberArk Software, a Palo Alto Networks Company",
      "product": "Identity Browser Extensions",
      "cwe": "CWE-346",
      "title": "Idira Identity Browser Extension: Unauthorized Application Interaction via Origin Validation Failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45173"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-12018",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12018"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-12024",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in DevTools in Google Chrome prior to 149.0.7827.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12024"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-6976",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00158,
      "epss_percentile": 0.05478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-639",
      "title": "Authorization Bypass Through User-Controlled Key in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6976"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-50245",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.05333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brickcom",
      "product": "Cube",
      "cwe": "CWE-306",
      "title": "Brickcom Cameras Missing Authentication for Critical Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50245"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-12032",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00155,
      "epss_percentile": 0.05184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Passwords in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12032"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2025-43278",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.0483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-61",
      "title": "This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-43278"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-4096",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DevOps Plan",
      "cwe": "CWE-644",
      "title": "A vulnerability has been identified in IBM DevOps Plan that allows a Host Header Injection attack due to improper handling of the Host header in HTTP requests.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4096"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-40995",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Web Services",
      "cwe": "CWE-287",
      "title": "X.509 authentication bypasses Spring Security account checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40995"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2022-44630",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.0422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YITH",
      "product": "YITH WooCommerce Product Slider Carousel",
      "cwe": "CWE-352",
      "title": "WordPress YITH WooCommerce Product Slider Carousel plugin <= 1.16.0 - Cross-Site Request Forgery (CSRF)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-44630"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-42653",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iova.mihai",
      "product": "SliceWP",
      "cwe": "CWE-79",
      "title": "WordPress SliceWP plugin <= 1.2.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42653"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2025-24268",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-22",
      "title": "A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-24268"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2025-46293",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-59",
      "title": "This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-46293"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-3341",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow Desktop",
      "cwe": "CWE-918",
      "title": "IBM Langflow Desktop 1.0.0 - 1.9.2 DNS Rebinding Bypasses SSRF Protection Allowing Access to Internal Services",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3341"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-47167",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-94",
      "title": "Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regex",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47167"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-41005",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00131,
      "epss_percentile": 0.03141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloud Foundry",
      "product": "UAA",
      "cwe": "CWE-347",
      "title": "UAA accepts SAML Encrypted Assertions authentication bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41005"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2025-46313",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-532",
      "title": "A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-46313"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-40996",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.0296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Web Services",
      "cwe": "CWE-327",
      "title": "Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40996"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-45175",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CyberArk Software, a Palo Alto Networks Company",
      "product": "Idira Endpoint Privilege Manager",
      "cwe": "CWE-295",
      "title": "Idira Endpoint Privilege Manager Agent: Security Control and Cryptographic Validation Bypass in Internal Agent Validation Processes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45175"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2025-24284",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.0282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-693",
      "title": "This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-24284"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2025-30431",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-693",
      "title": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access private information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-30431"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-45174",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CyberArk Software, a Palo Alto Networks Company",
      "product": "Idira Endpoint Privilege Manager",
      "cwe": "CWE-404",
      "title": "Idira Endpoint Privilege Manager Linux Agent: Potential bypass of Agent Daemon Initialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45174"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-53423",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "membraneframework",
      "product": "membrane_mp4_plugin",
      "cwe": "CWE-770",
      "title": "Unauthenticated denial-of-service via BEAM atom table exhaustion in membrane_mp4_plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53423"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-45176",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CyberArk Software, a Palo Alto Networks Company",
      "product": "Idira Endpoint Privilege Manager",
      "cwe": "CWE-269",
      "title": "Idira Endpoint Privilege Manager Agent: Local Privilege Escalation via Internal Communication or File Operation Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45176"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-10847",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "checkpoint",
      "product": "Identity Agent",
      "cwe": "CWE-427",
      "title": "Local Privilege Escalation vulnerability in Check Point Identity Agent Full for Windows OS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10847"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-40992",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Boot",
      "cwe": "CWE-295",
      "title": "Mail Auto-Configuration Does Not Enable SSL Hostname Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40992"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2025-30459",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-359",
      "title": "A privacy issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.4. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-30459"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2025-24165",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-284",
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-24165"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2025-7064",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ABB",
      "product": "Freelance",
      "cwe": "CWE-305",
      "title": "Freelance Security Lock – Access to Windows OS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7064"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2025-31272",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-269",
      "title": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4. An app may be able to bypass launch constraint protections and execute malicious code with elevated privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-31272"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-53813",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-427",
      "title": "OpenClaw < 2026.4.25 - Arbitrary Artifact Loading via Fake Package Root Resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53813"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2022-47150",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weDevs",
      "product": "WooCommerce Conversion Tracking",
      "cwe": "CWE-352",
      "title": "WordPress WooCommerce Conversion Tracking plugin <= 2.0.10 - Cross-Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-47150"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2025-43339",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-284",
      "title": "An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.1. A malicious app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-43339"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2024-32110",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Magepeople inc.",
      "product": "WpEvently",
      "cwe": "CWE-352",
      "title": "WordPress Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 4.1.2 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-32110"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-53818",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00096,
      "epss_percentile": 0.0082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-862",
      "title": "OpenClaw < 2026.4.24 - Owner-Only Tool Policy Bypass via MCP Loopback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53818"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-41001",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.0072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Boot",
      "cwe": "CWE-377",
      "title": "Predictable Temp Directory in Artemis Auto-configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41001"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2024-45636",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.00719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Security QRadar EDR",
      "cwe": "CWE-522",
      "title": "IBM Security QRadar EDR Software has a vulnerability where user credentials may be stored in plain text, potentially exposing sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-45636"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-53809",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw < 2026.4.25 - Provider Alias Confusion in Embedded Runner Policy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53809"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-11816",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-11816 (keras-team/keras). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-11945",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-11945 (DALIBO PostgreSQL Anonymizer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44486",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44486 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44487",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44487 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44488",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44488 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44489",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44489 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44490",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44490 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44492",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44492 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44494",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44494 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44495",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44495 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44496",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44496 (axios). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44705",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44705 (raszi node-tmp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49982",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49982 (raszi node-tmp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-5497",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-5497 (vllm-project/vllm). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-45321",
      "detail": "DUE DATE PASSED — CVE-2026-45321 (@tanstack arktype-adapter). CISA remediation deadline was June 10, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-48027",
      "detail": "DUE DATE PASSED — CVE-2026-48027 (nrwl nx-console). CISA remediation deadline was June 10, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
