{
  "day": "2026-06-12",
  "boundary": "UTC calendar day",
  "published_count": 280,
  "by_severity": {
    "CRITICAL": 34,
    "HIGH": 111,
    "MEDIUM": 124,
    "LOW": 11
  },
  "kev_count": 1,
  "exploit_reference_count": 20,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-35273",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.95473,
      "epss_percentile": 0.99864,
      "kev": true,
      "kev_due_at": "2026-06-15",
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PeopleTools",
      "cwe": "CWE-306",
      "title": "Oracle PeopleSoft Enterprise PeopleTools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35273"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-53787",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.05216,
      "epss_percentile": 0.91834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amasty",
      "product": "Order Attributes for Magento 2",
      "cwe": "CWE-434",
      "title": "Amasty Order Attributes for Magento 2 < 4.0.0 Unauthenticated Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53787"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-48611",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0386,
      "epss_percentile": 0.89319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phpBB",
      "product": "phpBB",
      "cwe": "CWE-287",
      "title": "Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48611"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-53519",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01852,
      "epss_percentile": 0.77419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nezhahq",
      "product": "nezha",
      "cwe": "CWE-22",
      "title": "Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53519"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-47210",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01801,
      "epss_percentile": 0.76731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-913",
      "title": "vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47210"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-48165",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.01506,
      "epss_percentile": 0.72315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MariaDB",
      "product": "server",
      "cwe": "CWE-78",
      "title": "MariaDB: unsafe usage of `wsrep_sst_receive_address` values on the joiner side",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48165"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-44170",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01334,
      "epss_percentile": 0.68887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MariaDB",
      "product": "server",
      "cwe": "CWE-78",
      "title": "MariaDB: Argument injection in CONNECT REST Xcurl on Windows via unsanitized URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44170"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-11442",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01258,
      "epss_percentile": 0.67212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Allegra",
      "product": "Allegra",
      "cwe": "CWE-22",
      "title": "Allegra exportReport Directory Traversal Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11442"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-53822",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00982,
      "epss_percentile": 0.59522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-77",
      "title": "OpenClaw < 2026.5.18 - Command Argument Modification via Shell Wrapper Between Approval and Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53822"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-11845",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00951,
      "epss_percentile": 0.58527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IEI Integration Corp",
      "product": "iVEC TANK-XM811",
      "cwe": "CWE-78",
      "title": "IEI Integration Corp｜iVEC-IEI Virtualization Edge Computer - OS Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11845"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-48163",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00914,
      "epss_percentile": 0.57349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MariaDB",
      "product": "server",
      "cwe": "CWE-78",
      "title": "MariaDB: wsrep SST unsafe parameter handling on the donor side (rsync)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48163"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-50633",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00861,
      "epss_percentile": 0.55688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-20",
      "title": "Apache CXF: JNDI Injection vulnerability in DispatchMDBMessageListenerImpl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50633"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-45416",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00856,
      "epss_percentile": 0.55556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-770",
      "title": "Netty: SNI handler pre-allocates up to 16 MiB from nine attacker bytes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45416"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-47370",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00834,
      "epss_percentile": 0.54843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi OS Server",
      "cwe": "CWE-20",
      "title": "A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47370"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-47367",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00825,
      "epss_percentile": 0.54559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UID Enterprise Agent",
      "cwe": "CWE-20",
      "title": "A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47367"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-11443",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00819,
      "epss_percentile": 0.54366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Allegra",
      "product": "Allegra",
      "cwe": "CWE-79",
      "title": "Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11443"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-47140",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00817,
      "epss_percentile": 0.54309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-693",
      "title": "vm2: NodeVM builtin denylist bypass via process and inspector/promises allows host code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47140"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-47208",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00762,
      "epss_percentile": 0.5252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-913",
      "title": "vm2: Sandbox Breakout Using Promise Species",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47208"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-48006",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0074,
      "epss_percentile": 0.51807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-401",
      "title": "Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48006"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-9271",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00707,
      "epss_percentile": 0.50615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "KeepInMind Dashboard Notes",
      "cwe": null,
      "title": "KeepInMind - Dashboard Notes < 0.8.4.2 - Contributor+ Stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9271"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-50628",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00692,
      "epss_percentile": 0.50079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-20",
      "title": "Apache CXF: OAuth2: Inverted IP Binding Check Defeats Security Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50628"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-50632",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00646,
      "epss_percentile": 0.48204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-20",
      "title": "Apache CXF: JNDI Injection Vulnerability in JMSConfigFactory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50632"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-48059",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0063,
      "epss_percentile": 0.47468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-401",
      "title": "Netty HAProxy: Unbalanced Reference Count in Nested PP2_TYPE_SSL TLV Parsing Leads to Memory Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48059"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-44173",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0062,
      "epss_percentile": 0.47033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MariaDB",
      "product": "server",
      "cwe": "CWE-863",
      "title": "MariaDB: FILE privilege was not checked for subqueries in the FROM clause",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44173"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-47131",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00619,
      "epss_percentile": 0.46981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-913",
      "title": "vm2: Sandbox Escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47131"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-44893",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00617,
      "epss_percentile": 0.46876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-703",
      "title": "Netty: HAProxy SSL TLV parsing leaks retained slice on invalid TLV length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44893"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-48043",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00617,
      "epss_percentile": 0.46876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-400",
      "title": "netty-codec-http2: ByteBuf Reference-Count Leak in DelegatingDecompressorFrameListener Leads to Memory Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48043"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-44172",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00591,
      "epss_percentile": 0.45659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MariaDB",
      "product": "server",
      "cwe": "CWE-89",
      "title": "MariaDB: mysql_real_escape_string() incorrectly handled big5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44172"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-44168",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00588,
      "epss_percentile": 0.45525,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MariaDB",
      "product": "server",
      "cwe": "CWE-78",
      "title": "MariaDB: wsrep SST unsafe parameter handling on the donor side",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44168"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-47138",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00584,
      "epss_percentile": 0.45374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "parse-community",
      "product": "parse-server",
      "cwe": "CWE-1333",
      "title": "Parse Server: Pre-authentication denial of service via client version header regex backtracking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47138"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-12143",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00535,
      "epss_percentile": 0.42888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "form-data",
      "product": "form-data",
      "cwe": "CWE-93",
      "title": "form-data does not escape CR/LF/quote in multipart field names and filenames (CRLF injection)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12143"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-49875",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00527,
      "epss_percentile": 0.42391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-611",
      "title": "Apache CXF: XML External Entity (XXE) Injection in W3CMultiSchemaFactory and EndpointReferenceUtils",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49875"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-44990",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00514,
      "epss_percentile": 0.41576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apostrophecms",
      "product": "sanitize-html",
      "cwe": "CWE-79",
      "title": "Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44990"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-50629",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0047,
      "epss_percentile": 0.38853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-93",
      "title": "Apache CXF: OAuth2: Log Injection via Unsanitized Client Identifier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50629"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-46340",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00461,
      "epss_percentile": 0.38289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-770",
      "title": "Netty: SCTP reassembly nests buffers without bound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46340"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-50011",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00461,
      "epss_percentile": 0.3829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-400",
      "title": "Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50011"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-50645",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00459,
      "epss_percentile": 0.38182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-400",
      "title": "Apache CXF: No restriction on attachment headers per message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50645"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-50010",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00456,
      "epss_percentile": 0.38014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-347",
      "title": "Netty's wrapping plain trust manager silently disables hostname verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50010"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-53836",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00451,
      "epss_percentile": 0.37627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-184",
      "title": "OpenClaw < 2026.5.12 - Allowlist Bypass via PowerShell Encoded-Command Aliases",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53836"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-12059",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0045,
      "epss_percentile": 0.37567,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cellopoint",
      "product": "CelloOS",
      "cwe": "CWE-1284",
      "title": "Cellopoint｜CelloOS - Improper Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12059"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-50627",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00445,
      "epss_percentile": 0.37203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-289",
      "title": "Apache CXF: OAuth2: Missing JWT Audience and Issuer Validation in Access Token Validator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50627"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-40677",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "AMD Management Console (AMC)",
      "cwe": "CWE-1428",
      "title": "The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle attack, potentially leading to arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40677"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-46716",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0043,
      "epss_percentile": 0.36028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nezhahq",
      "product": "nezha",
      "cwe": "CWE-78",
      "title": "Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46716"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-42853",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00428,
      "epss_percentile": 0.35867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apostrophecms",
      "product": "@apostrophecms/cli",
      "cwe": "CWE-78",
      "title": "@apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42853"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-50085",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00412,
      "epss_percentile": 0.34552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aqara",
      "product": "Board service",
      "cwe": "CWE-306",
      "title": "Aqara Board IoT insecure debug API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50085"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-47365",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00409,
      "epss_percentile": 0.34262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "WordPress-Toolkit",
      "cwe": "CWE-88",
      "title": "Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47365"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-11844",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00407,
      "epss_percentile": 0.34127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IEI Integration Corp",
      "product": "iVEC TANK-XM811",
      "cwe": "CWE-22",
      "title": "IEI Integration Corp｜iVEC-IEI Virtualization Edge Computer - Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11844"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-50630",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00404,
      "epss_percentile": 0.33801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-113",
      "title": "Apache CXF: OAuth2: HTTP Response Splitting via WWW-Authenticate Realm Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50630"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-11846",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00401,
      "epss_percentile": 0.33493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IEI Integration Corp",
      "product": "iVEC TANK-XM811",
      "cwe": "CWE-22",
      "title": "IEI Integration Corp｜iVEC-IEI Virtualization Edge Computer - Arbitrary File Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11846"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-42604",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.004,
      "epss_percentile": 0.33372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "actualbudget",
      "product": "actual",
      "cwe": "CWE-863",
      "title": "Actual has an OpenID `client_secret` Disclosure via Broken Authorization Guard in `/openid/config`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42604"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-48748",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-770",
      "title": "Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48748"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-11933",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB",
      "cwe": "CWE-416",
      "title": "Post-authentication use-after-free in server-side JavaScript BSON-to-array conversion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11933"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-47137",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00382,
      "epss_percentile": 0.31468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-913",
      "title": "vm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require still allows full RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47137"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-54393",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00377,
      "epss_percentile": 0.30984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-79",
      "title": "MISP Overmind theme stored XSS via unvalidated homepage setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54393"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-53825",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.30747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-22",
      "title": "OpenClaw < 2026.4.7 - Arbitrary Local File Read via memory-wiki Ingest with operator.write Scope",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53825"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-50623",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.3036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-287",
      "title": "Apache CXF: Authentication Bypass in OAuth2 TokenIntrospectionService",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50623"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-50083",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00364,
      "epss_percentile": 0.29627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aqara",
      "product": "Aquara IAM/SSO Gateway",
      "cwe": "CWE-798",
      "title": "Aqara hardcoded OAuth client credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50083"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-50287",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00359,
      "epss_percentile": 0.29097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "agenticmail",
      "product": "agenticmail",
      "cwe": "CWE-306",
      "title": "Missing Authentication for Critical Function in @agenticmail/mcp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50287"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-41157",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.29009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-787",
      "title": "GPU DDK - OOB Write in CalculateNPOTTwiddleSparsePageMap3D",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41157"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-47368",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.28704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi OS Server",
      "cwe": "CWE-22",
      "title": "A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from such UniFi OS devices or instances.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47368"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-9125",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00355,
      "epss_percentile": 0.28761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "2winfactor",
      "product": "Presto Player",
      "cwe": "CWE-79",
      "title": "The Ultimate Video Player For WordPress <= 4.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'link_url' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9125"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-10557",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00353,
      "epss_percentile": 0.28579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yarbo",
      "product": "Yarbo Android/IOS mobile application",
      "cwe": "CWE-798",
      "title": "Yarbo Android/iOS Mobile Application and Cloud Infrastructure Use of Hard-coded Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10557"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-12043",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "aws-c-http",
      "cwe": "CWE-415",
      "title": "Heap double-free in AWS Common Runtime aws-c-http",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12043"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-11849",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0035,
      "epss_percentile": 0.282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IEI Integration Corp",
      "product": "iRM-TSi410X",
      "cwe": "CWE-798",
      "title": "IEI Integration Corp｜iRM-IEI Remote Management - Hard-coded Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11849"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-45169",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.28223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CyberArk Software, a Palo Alto Networks Company",
      "product": "PAM SH Vault",
      "cwe": "CWE-400",
      "title": "Idira Privileged Access Manager (PAM) Self-Hosted Vault: Denial of Service due to Unexpected Input Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45169"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-6853",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00346,
      "epss_percentile": 0.27756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Başbelen Group Food Cafe Businesses Industry and Trade Ltd. Co.",
      "product": "Pause+ Mobile App",
      "cwe": "CWE-307",
      "title": "OTP Bypass in Başbelen Group's Pause+ Mobile App",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6853"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-45830",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chroma",
      "product": "ChromaDB",
      "cwe": "CWE-639",
      "title": "A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45830"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-50008",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "parse-community",
      "product": "parse-server",
      "cwe": "CWE-863",
      "title": "Parse Server: Server option routeAllowList is bypassable through batch sub-requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50008"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-45833",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00342,
      "epss_percentile": 0.27376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chroma",
      "product": "ChromaDB",
      "cwe": "CWE-94",
      "title": "A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary code on the server by sending a malicious model repository and trust_remote_code set to true in the /api/v2/tenants/default_tenant/databases/default_database/collections/{collection_id} if they have the UPDATE_COLLECTION permission.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45833"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-47216",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00336,
      "epss_percentile": 0.26635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "typesense",
      "product": "typesense",
      "cwe": "CWE-754",
      "title": "Typesense: Unauthenticated Denial of Service in the Typesense /multi_search Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47216"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-47190",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00333,
      "epss_percentile": 0.26263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "metal3-io",
      "product": "ip-address-manager",
      "cwe": "CWE-250",
      "title": "IPAM controller service account granted unnecessary full access to Secrets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47190"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-28742",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0033,
      "epss_percentile": 0.26024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Naxclow",
      "product": "Smart Doorbell X3",
      "cwe": "CWE-321",
      "title": "Naxclow IoT Platform Use of hard-coded cryptographic key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28742"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-53982",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo",
      "cwe": "CWE-645",
      "title": "Cap-go Console < 12.28.2 Account Deletion DoS via Device Identifier Association",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53982"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-34195",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-787",
      "title": "GPU DDK - Kernel heap OOB write in PMRChangeSparseMemOSMem due to incorrect physical page translation from virtual page indexes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34195"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-45775",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.2522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-22",
      "title": "Discourse: Cross-site backup access via path traversal in multisite local backups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45775"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-47260",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.25001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "koel",
      "product": "koel",
      "cwe": "CWE-918",
      "title": "Koel Vulnerable to SSRF via Podcast Episode Enclosure URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47260"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-44207",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00321,
      "epss_percentile": 0.24999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-639",
      "title": "Frappe: Insecure Direct Object Reference for email accounts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44207"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-44208",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00321,
      "epss_percentile": 0.24999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-284",
      "title": "Frappe: IDOR in `submit_discussion()`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44208"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-54133",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0032,
      "epss_percentile": 0.24906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jmespath",
      "product": "jmespath.php",
      "cwe": "CWE-20",
      "title": "jmespath.php has CompilerRuntime code injection via unescaped function names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54133"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2017-20240",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ARODLAND",
      "product": "Crypt::PBKDF2",
      "cwe": "CWE-208",
      "title": "Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timing attacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20240"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-54394",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-22",
      "title": "MISP organisation logo path traversal allows retrieval of arbitrary PNG/SVG files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54394"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-47691",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00318,
      "epss_percentile": 0.24615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-345",
      "title": "Netty has Insufficient Bailiwick Validation for NS Records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47691"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-12060",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hepta Platforms",
      "product": "Heptabase",
      "cwe": "CWE-749",
      "title": "Hepta Platforms｜Heptabase - Exposed Dangerous",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12060"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-42947",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.23997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Naxclow",
      "product": "Smart Doorbell X3",
      "cwe": "CWE-639",
      "title": "Naxclow IoT Platform Authorization bypass through User-Controlled key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42947"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-44206",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.23945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-200",
      "title": "Frappe: DB Schema Enumeration via Frappe-Authorization-Source",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44206"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-7387",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-863",
      "title": "Mattermost group syncable endpoints allow privilege escalation via scheme_admin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7387"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-47141",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.2352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-668",
      "title": "vm2: NodeVM observability builtins leak host process and HTTP request data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47141"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-50108",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00306,
      "epss_percentile": 0.23307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Naxclow",
      "product": "Smart Doorbell X3",
      "cwe": "CWE-862",
      "title": "Naxclow IoT Platform Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50108"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-6961",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-22",
      "title": "CVE-2026-6961: Path traversal via unsanitized FileInfo.Name in Mattermost federation sync",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6961"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-9638",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ARODLAND",
      "product": "Crypt::PBKDF2",
      "cwe": "CWE-338",
      "title": "Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9638"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-47369",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.23002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi OS Server",
      "cwe": "CWE-20",
      "title": "A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47369"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-43872",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00303,
      "epss_percentile": 0.23033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "actualbudget",
      "product": "actual",
      "cwe": "CWE-22",
      "title": "actual-server has a path traversal vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43872"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-50560",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.22814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-770",
      "title": "Netty susceptible to HTTP/2 Reset Attack with different on-the-wire signature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50560"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-47366",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00299,
      "epss_percentile": 0.22513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phpBB",
      "product": "phpBB",
      "cwe": "CWE-284",
      "title": "Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized for their account, resulting in privilege escalation within the administrative interface.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47366"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-11848",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.2232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IEI Integration Corp",
      "product": "iRM-TSi410X",
      "cwe": "CWE-306",
      "title": "IEI Integration Corp｜ iRM-IEI Remote Management - Missing Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11848"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-53721",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.22032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxt",
      "product": "nuxt",
      "cwe": "CWE-178",
      "title": "Nuxt: Route-rule middleware bypass via case-sensitivity mismatch between vue-router and the routeRules matcher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53721"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-50631",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.21984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-367",
      "title": "Apache CXF: OAuth2: TOCTOU Race Condition in Refresh Token Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50631"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-47244",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-400",
      "title": "Netty HTTP/2: Advertised MAX_CONCURRENT_STREAMS are not enforced",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47244"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-47248",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.2173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "parse-community",
      "product": "parse-server",
      "cwe": "CWE-209",
      "title": "Parse Server: GraphQL \"Did you mean\" validation suggestions disclose schema to unauthenticated callers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47248"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-50086",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0029,
      "epss_percentile": 0.2161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aqara",
      "product": "Aqara IAM/SSO Gateway",
      "cwe": "CWE-327",
      "title": "Aqara unauthenticated AES oracle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50086"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-53522",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nezhahq",
      "product": "nezha",
      "cwe": "CWE-770",
      "title": "Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53522"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-53821",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-862",
      "title": "OpenClaw < 2026.5.18 - Scope Elevation in trusted-proxy Control UI WebSocket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53821"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-12066",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "PbootCMS",
      "cwe": "CWE-640",
      "title": "PbootCMS Password MemberController.php retrieve password recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12066"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-11847",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IEI Integration Corp",
      "product": "iVEC TANK-XM811",
      "cwe": "CWE-22",
      "title": "Integration Corp｜iVEC-IEI Virtualization Edge Computer - Arbitrary File Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11847"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-47209",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-693",
      "title": "vm2: Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47209"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-42850",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kovidgoyal",
      "product": "kitty",
      "cwe": "CWE-77",
      "title": "Kitty has a shell command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42850"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-50091",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aqara",
      "product": "com.lumiunited.aqarahome",
      "cwe": "CWE-798",
      "title": "Aqara Home Android SDK hardcoded keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50091"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-45014",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.21198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apostrophecms",
      "product": "apostrophe",
      "cwe": "CWE-79",
      "title": "Apostrophe Vulnerable to Stored Cross-Site Scripting via Unsanitized User Display Name in Draft Version Tooltip",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45014"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-45832",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.2094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chroma",
      "product": "ChromaDB",
      "cwe": "CWE-639",
      "title": "All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorization layer, allowing attackers to bypass authorization controls by using the V1 endpoints.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45832"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-47139",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-693",
      "title": "vm2: NodeVM network builtin exclusions bypass via internal _http_client and _http_server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47139"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-53520",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nezhahq",
      "product": "nezha",
      "cwe": "CWE-284",
      "title": "Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53520"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-50101",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00281,
      "epss_percentile": 0.20633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Naxclow",
      "product": "Smart Doorbell X3",
      "cwe": "CWE-262",
      "title": "Naxclow IoT Platform Not using password aging",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50101"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-53724",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00281,
      "epss_percentile": 0.2067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "parse-community",
      "product": "parse-server",
      "cwe": "CWE-79",
      "title": "Parse Server: Stored XSS via trailing-dot filename bypassing file upload extension blocklist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53724"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-49993",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxt",
      "product": "nuxt",
      "cwe": "CWE-749",
      "title": "@nuxt/webpack-builder and @nuxt/rspack-builder dev server same-origin check bypassed when Sec-Fetch-Site, Origin, and Referer are all absent (incomplete fix for GHSA-6m52-m754-pw2g)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49993"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-8828",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chroma",
      "product": "ChromaDB",
      "cwe": "CWE-639",
      "title": "A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users to arbitrarily read, write, update, or delete data in any tenant's collection regardless of which tenant they belong to.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8828"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-44892",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-400",
      "title": "Netty has a Vulnerable Default Configuration Which Leads to Denial of Service via Unbounded HTTP/3 Header Size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44892"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-50634",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache CXF",
      "cwe": "CWE-347",
      "title": "Apache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50634"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-20746",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ping Identity",
      "product": "PingDirectory",
      "cwe": "CWE-401",
      "title": "PingDirectory copying of virtual attributes leads to memory exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20746"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-44975",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.2028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-862",
      "title": "Frappe: Missing authorization on reset form tours",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44975"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-44976",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.2028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-284",
      "title": "Frappe: IDOR in update_onboarding_step",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44976"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-47182",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.2028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-284",
      "title": "Frappe: Broken Access Control on Private Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47182"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-53726",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.2016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "parse-community",
      "product": "parse-server",
      "cwe": "CWE-639",
      "title": "Parse Server: Relation `$relatedTo` query bypasses `protectedFields` and owning-object ACL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53726"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-46717",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nezhahq",
      "product": "nezha",
      "cwe": "CWE-863",
      "title": "Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46717"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-47124",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nezhahq",
      "product": "nezha",
      "cwe": "CWE-200",
      "title": "Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47124"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-4870",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Qiskit SDK",
      "cwe": "CWE-674",
      "title": "Qiskit SDK is vulnerable to specific functions may recurse too deeply and overflow the available stack space, when encountering certain classical expressions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4870"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-54056",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kovidgoyal",
      "product": "kitty",
      "cwe": "CWE-59",
      "title": "Kitty has an arbitrary file overwrite via symlink following in `kitten dnd` remote drop staging",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54056"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-53828",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw < 2026.5.6 - Native Command Authorization Bypass via Owner-Command Enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53828"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-53981",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "Cap-go",
      "cwe": "CWE-306",
      "title": "Cap-go < v12.128.2 Account Takeover via Unauthenticated Email Change Mechanism",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53981"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-47135",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "patriksimek",
      "product": "vm2",
      "cwe": "CWE-693",
      "title": "vm2: Sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47135"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-48119",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nezhahq",
      "product": "nezha",
      "cwe": "CWE-862",
      "title": "Nezha Monitoring: Authenticated agents can forge service-monitor results for other users' services",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48119"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-50082",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18587,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aqara",
      "product": "Cloud Developer Portal",
      "cwe": "CWE-306",
      "title": "Aqara Developer Portal insecure authentication token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50082"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-53839",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.18539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-1023",
      "title": "OpenClaw < 2026.5.7 - Hostname Prefix Matching Bypass in Trusted Retry Endpoint Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53839"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-48610",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.18433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UDM",
      "cwe": "CWE-284",
      "title": "Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48610"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-12068",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gen Digital",
      "product": "Avira Password Manager",
      "cwe": "CWE-669",
      "title": "Avira Password Manager credential disclosure via cross-origin autofill in Firefox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12068"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-54361",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-639",
      "title": "MISP mass assignment vulnerabilities allow unauthorized modification of ownership and delegation records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54361"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-47120",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.18029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nezhahq",
      "product": "nezha",
      "cwe": "CWE-862",
      "title": "Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47120"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-50026",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-862",
      "title": "Frappe: Lack of permissions checks in 'relink' and 'set_email_password' endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50026"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-7368",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yarbo",
      "product": "Yarbo Android/IOS mobile application",
      "cwe": "CWE-862",
      "title": "Yarbo Android/iOS Mobile Application and Cloud Infrastructure Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7368"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-44786",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-200",
      "title": "Discourse: Public chat MessageBus broadcasts are not restricted to chat-eligible users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44786"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-53868",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-306",
      "title": "Capgo < 12.128.2 - Denial of Service via Unverified Email Account Registration and Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53868"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-44205",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-79",
      "title": "Frappe: Stored Cross-Site Scripting (XSS) in User Profile through Image Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44205"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-47739",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-79",
      "title": "Frappe: Stored XSS in Note",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47739"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-53568",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-79",
      "title": "Frappe: Stored XSS in Frappe Report/List View via 'set_link_title_field_value'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53568"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-6739",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17567,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-863",
      "title": "Mattermost: Delegated admins could patch protected default system roles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6739"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-45673",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-330",
      "title": "Netty: DNS Cache Poisoning due to Predictable PRNG and Default Static Source Port",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45673"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-54395",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-79",
      "title": "MISP UiBeta event index reflected XSS in advanced filter popup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54395"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-7184",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-201",
      "title": "Mattermost Remote Cluster PATCH API Leaks Authentication Tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7184"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-53827",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-918",
      "title": "OpenClaw < 2026.5.2 - Credential Exposure via Model-Supplied Loopback URLs in message.action Forwarding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53827"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-54357",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-639",
      "title": "MISP improper authorization allows organization administrators to modify site administrator user settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54357"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-49397",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.1703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nezhahq",
      "product": "nezha",
      "cwe": "CWE-200",
      "title": "Nezha Monitoring: Private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49397"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-53725",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "parse-community",
      "product": "parse-server",
      "cwe": "CWE-200",
      "title": "Parse Server: Endpoints `/login` and `/verifyPassword` disclose MFA secrets and protected fields when `_User` get is denied",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53725"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-48485",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00251,
      "epss_percentile": 0.16825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "duck-organization",
      "product": "questbot",
      "cwe": "CWE-116",
      "title": "Quest Bot: Stored warn reasons can still trigger bot-powered mass mentions through `/warns`.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48485"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-45013",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apostrophecms",
      "product": "apostrophe",
      "cwe": "CWE-20",
      "title": "Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45013"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-12131",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0025,
      "epss_percentile": 0.16639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Human Resource Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Human Resource Management System Payroll Invoice Payroll.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12131"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-45674",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00248,
      "epss_percentile": 0.16426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-345",
      "title": "Netty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45674"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-54396",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-200",
      "title": "MISP AuthKey edit endpoint allows authenticated user email enumeration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54396"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-50084",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.1593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aqara",
      "product": "Cloud Production API",
      "cwe": "CWE-862",
      "title": "Aqara API cross-account access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50084"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-53523",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nezhahq",
      "product": "nezha",
      "cwe": "CWE-601",
      "title": "Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53523"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-10715",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Camaleon CMS",
      "product": "Camaleon CMS",
      "cwe": "CWE-862",
      "title": "Camaleon CMS 2.9.2 - Improper authorization in draft autosave endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10715"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-53609",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00237,
      "epss_percentile": 0.14982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apostrophecms",
      "product": "apostrophe",
      "cwe": "CWE-1321",
      "title": "Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53609"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-45831",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chroma",
      "product": "ChromaDB",
      "cwe": "CWE-863",
      "title": "The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project evaluates whether a user holds a given permission but never checks which tenant, database, or collection that permission applies to allowing users to perform cross tenant actions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45831"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-44169",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.15009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MariaDB",
      "product": "server",
      "cwe": "CWE-863",
      "title": "MariaDB: Authorization bypass in role-based routine-level privilege check exposes stored routine definitions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44169"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-47196",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "duck-organization",
      "product": "questbot",
      "cwe": "CWE-20",
      "title": "Quest Bot: Empty automod rule causes every guild message to be deleted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47196"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-49347",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "duck-organization",
      "product": "questbot",
      "cwe": "CWE-770",
      "title": "Quest Bot: Ticket creation has no per-user open-ticket limit or cooldown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49347"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-44779",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-200",
      "title": "Discourse: Bot debug endpoints disclose whisper translation audit logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44779"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-42932",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.14493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Naxclow",
      "product": "Smart Doorbell X3",
      "cwe": "CWE-340",
      "title": "Naxclow IoT Platform Generation of Predictable Numbers or Identifiers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42932"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-53829",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-451",
      "title": "OpenClaw < 2026.5.18 - Command Truncation in Exec Approval Display",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53829"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-50020",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.1438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-444",
      "title": "Netty's HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50020"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-53407",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00231,
      "epss_percentile": 0.14148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zoom Communications",
      "product": "Zoom Workplace",
      "cwe": "CWE-939",
      "title": "Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53407"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-44784",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-200",
      "title": "Discourse: Non-staff group owners can see email password in plaintext through group history",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44784"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-47200",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxt",
      "product": "nuxt",
      "cwe": "CWE-284",
      "title": "Nuxt: Route middleware not enforced when rendering `.server.vue` pages via `/__nuxt_island/page_*`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47200"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-53838",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-367",
      "title": "OpenClaw < 2026.5.27 - Node Pairing State Mutation via Reconnection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53838"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-54358",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.13973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-863",
      "title": "MISP organization administrators can target site administrator accounts for password reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54358"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-47197",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "duck-organization",
      "product": "questbot",
      "cwe": "CWE-862",
      "title": "Quest Bot: Discord moderation role hierarchy bypass in ban, kick, mute, unmute, warn, and nickname commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47197"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-41581",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-89",
      "title": "Frappe Vulnerable to Possible SQL Injection via get_blog_list",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41581"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-53521",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nezhahq",
      "product": "nezha",
      "cwe": "CWE-863",
      "title": "Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53521"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-50090",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aqara",
      "product": "Cloud OAuth Authorization Endpoint",
      "cwe": "CWE-1289",
      "title": "Aqara OAuth redirect_uri validation bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50090"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-54360",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-639",
      "title": "MISP sharing group creation mass assignment allows unauthorized takeover of existing sharing groups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54360"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-54397",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-863",
      "title": "MISP event editing allows unauthorized assignment to undisclosed sharing groups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54397"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-47225",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "typesense",
      "product": "typesense",
      "cwe": "CWE-524",
      "title": "Improper Search Cache Isolation for Scoped Search API Keys in Typesense",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47225"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-9641",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ARODLAND",
      "product": "Crypt::PBKDF2",
      "cwe": "CWE-916",
      "title": "Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9641"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-53607",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00226,
      "epss_percentile": 0.13602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apostrophecms",
      "product": "apostrophe",
      "cwe": "CWE-918",
      "title": "@apostrophecms/file pretty-URL Vulnerable to Unauthenticated SSRF via Host header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53607"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-50244",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.1294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Naxclow",
      "product": "Smart Doorbell X3",
      "cwe": "CWE-862",
      "title": "Naxclow IoT Platform Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50244"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-8694",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "PowerShell Universal",
      "cwe": "CWE-306",
      "title": "Improper access control on the API documentation endpoint in PowerShell Universal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8694"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-54398",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-863",
      "title": "MISP object edit authorization bypass allows unauthorized sharing group assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54398"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-47264",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-200",
      "title": "Discourse: Don't leak restricted tag group names via tag info",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47264"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-47195",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "duck-organization",
      "product": "questbot",
      "cwe": "CWE-863",
      "title": "Quest Bot: Per-channel permission overwrite bypass in purge and slowmode commands.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47195"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-50088",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aqara",
      "product": "Aqara Developer Portal",
      "cwe": "CWE-942",
      "title": "Aqara Developer Portal cross-origin resource sharing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50088"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-45085",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-200",
      "title": "Discourse: Chat misauthorization and information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45085"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-53408",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zoom Communications",
      "product": "Zoom Workplace",
      "cwe": "CWE-939",
      "title": "Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privilege via network access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53408"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-45011",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apostrophecms",
      "product": "apostrophe",
      "cwe": "CWE-79",
      "title": "Apostrophe has stored XSS via javascript: URL in Image Widget Link",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45011"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-47263",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-200",
      "title": "Discourse: Prevent webhook payload disclosure on event redelivery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47263"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-6211",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Global IT Informatics Services Inc.",
      "product": "WEOLL",
      "cwe": "CWE-434",
      "title": "Arbitrary File Upload in Global IT's WEOLL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6211"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-53608",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apostrophecms",
      "product": "@apostrophecms/seo",
      "cwe": "CWE-79",
      "title": "@apostrophecms/seo Vulnerable to Stored XSS via Unsanitized Google Analytics / GTM ID Injected into Script Tag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53608"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-5792",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.1153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hedef Media Promotion Interactive Media Marketing Inc.",
      "product": "Related Marketing Cloud (RMC)",
      "cwe": "CWE-290",
      "title": "Authentication Bypass in Hedef Media's Related Marketing Cloud (RMC)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5792"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-53823",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.11314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-290",
      "title": "OpenClaw < 2026.5.3 - Privilege Escalation via Mutable Slack Display Names in allowFrom",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53823"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-53830",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-613",
      "title": "OpenClaw < 2026.4.22 - Webhook Secret Revocation Bypass via secrets.reload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53830"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-54362",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-863",
      "title": "MISP template builder exposes non-visible custom galaxies across organisations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54362"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-44967",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.11034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-cpp",
      "cwe": "CWE-789",
      "title": "opentelemetry-cpp: OTLP HTTP exporters read unbounded HTTP response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44967"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-45670",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxt",
      "product": "nuxt",
      "cwe": "CWE-749",
      "title": "Nuxt: Dev server exposes built source over LAN to malicious sites (incomplete fix for GHSA-4gf7-ff8x-hq99)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45670"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-50087",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aqara",
      "product": "Aqara IAM/SSO Gateway",
      "cwe": "CWE-942",
      "title": "Aqara IAM/SSO Gateway cross-origin resource sharing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50087"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-50009",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-200",
      "title": "Netty QUIC stateless reset token material exposed through header-visible connection IDs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50009"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-12129",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00203,
      "epss_percentile": 0.10579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Human Resource Management System",
      "cwe": "CWE-79",
      "title": "CodeAstro Human Resource Management System Dashboard add_tod cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12129"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-12130",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00203,
      "epss_percentile": 0.1058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Human Resource Management System",
      "cwe": "CWE-79",
      "title": "CodeAstro Human Resource Management System Projects Management Add_Projects cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12130"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-53834",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw < 2026.4.27 - Authorization Bypass in QQBot Pre-dispatch Slash Commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53834"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-53831",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-367",
      "title": "OpenClaw < 2026.5.18 - Arbitrary File Read via Shell Expansion in system.run Safe-bin Allowlist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53831"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-53722",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxt",
      "product": "nuxt",
      "cwe": "CWE-79",
      "title": "Nuxt: Reflected XSS in `<NuxtLink>` via unsanitised `javascript:` or `data:` URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53722"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-45012",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00197,
      "epss_percentile": 0.099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apostrophecms",
      "product": "apostrophe",
      "cwe": "CWE-918",
      "title": "Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45012"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-50089",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aqara",
      "product": "Aqara IAM/SSO Gateway",
      "cwe": "CWE-601",
      "title": "Aqara IAM/SSO Gateway open redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50089"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-6046",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.09009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-200",
      "title": "Plugin bot username conflict allows user account to be used as bot identity in Mattermost Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6046"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-54359",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-352",
      "title": "MISP automation endpoints may be exposed to CSRF when Sec-Fetch-Site protection is disabled by default",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54359"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-53837",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-636",
      "title": "OpenClaw < 2026.5.6 - Missing Channel Type Validation in Mattermost Event Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53837"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-44780",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-200",
      "title": "Discourse: Category queue reviewers can read raw incoming emails from queued posts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44780"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-44782",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-200",
      "title": "Discourse: GroupPostSerializer leaks hidden full names through reaction post association",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44782"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-44785",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-200",
      "title": "Discourse: Hidden reply-to post raw can be disclosed through AI explain prompts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44785"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-47224",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.0862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "M2Team",
      "product": "NanaZip",
      "cwe": "CWE-125",
      "title": "NanaZip: Heap buffer-overflow read in NanaZip LVM metadata CRC check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47224"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-53826",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00187,
      "epss_percentile": 0.08689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-668",
      "title": "OpenClaw < 2026.4.26 - Information Disclosure via Sandboxed Session Spawn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53826"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-3840",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kedro-org",
      "product": "kedro-org/kedro",
      "cwe": "CWE-22",
      "title": "Path Traversal in kedro-org/kedro",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3840"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-53867",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-459",
      "title": "Capgo < 12.128.2 - Orphaned File Retention via Profile Image Replacement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53867"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-47236",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "solidtime-io",
      "product": "solidtime",
      "cwe": "CWE-863",
      "title": "Solidtime team page exposes pending invitation and member emails to employees who lack invitations:view/members:view permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47236"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-47268",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nezhahq",
      "product": "nezha",
      "cwe": "CWE-918",
      "title": "Nezha Monitoring: Authenticated DDNS webhook configuration allows blind SSRF from the dashboard host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47268"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-53824",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.08015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-613",
      "title": "Mattermost plugin for OpenClaw < 2026.4.24 - Slash Token Revocation Lag via Monitor Refresh Delay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53824"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-47223",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.0788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "M2Team",
      "product": "NanaZip",
      "cwe": "CWE-125",
      "title": "NanaZip: Heap out-of-bounds read in NanaZip AVB hashtree descriptor parser via 32-bit unsigned integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47223"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-3433",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-200",
      "title": "Mattermost fails to scope role_updated websocket events to authorized team and channel members",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3433"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-53833",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00179,
      "epss_percentile": 0.07706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-290",
      "title": "QQBot for OpenClaw < 2026.4.29 - Authorization Bypass via QQBot Streaming Command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53833"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-45669",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxt",
      "product": "nuxt",
      "cwe": "CWE-83",
      "title": "Nuxt: Reflected XSS in `navigateTo()` external redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45669"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-44171",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MariaDB",
      "product": "server",
      "cwe": "CWE-22",
      "title": "MariaDB: path traversal in mbstream",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44171"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-24618",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.0726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashThemes",
      "product": "Hash Elements",
      "cwe": "CWE-497",
      "title": "WordPress Hash Elements plugin <= 1.5.4 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24618"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-50099",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Naxclow",
      "product": "Smart Doorbell X3",
      "cwe": "CWE-538",
      "title": "Naxclow IoT Platform Insertion of sensitive information into Externally-Accessible file or directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50099"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-47222",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "M2Team",
      "product": "NanaZip",
      "cwe": "CWE-125",
      "title": "NanaZip: Heap out-of-bounds read in NanaZip AVB property descriptor parser via unsigned integer underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47222"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-12058",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vivo",
      "product": "PcSuite",
      "cwe": "CWE-807",
      "title": "The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12058"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-50552",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.0667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "koel",
      "product": "koel",
      "cwe": "CWE-918",
      "title": "Koel: Server-Side Request Forgery (SSRF) in radio station creation due to missing validation bail",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50552"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-54057",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.06364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kovidgoyal",
      "product": "kitty",
      "cwe": "CWE-94",
      "title": "Kitty vulnerable to command injection via unsanitized OSC 21 query reply",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54057"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-53835",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00166,
      "epss_percentile": 0.06289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw < 2026.5.6 - Config-Write Enforcement Bypass in Feishu Dynamic-Agent Bindings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53835"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-42851",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kovidgoyal",
      "product": "kitty",
      "cwe": "CWE-94",
      "title": "@kitty-edit DCS + --color=geninclude vulnerable to Unauthenticated in-process RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42851"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-48914",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05535,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "qemu",
      "cwe": "CWE-122",
      "title": "Qemu-kvm: heap buffer overflow in virtio-blk scsi request handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48914"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-48613",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phpBB",
      "product": "phpBB",
      "cwe": "CWE-89",
      "title": "SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field data during migration, allowing execution of arbitrary SQL queries. Only applies to phpBB forums that had been updated from versions prior to phpBB 3.3.8 and have not been updated to 3.3.11 or newer yet.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48613"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-6689",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-862",
      "title": "*Missing* {{invite_user}} *permission check on team creation allows unprivileged users to set open-invite and allowed-domains team settings*",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6689"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-11535",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00151,
      "epss_percentile": 0.04843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vivo",
      "product": "PcSuite",
      "cwe": "CWE-306",
      "title": "An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to the victim’s device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11535"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-47965",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-787",
      "title": "Acrobat Reader | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47965"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-44783",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-284",
      "title": "Discourse: Replying to a whisper lets non-whisperers create staff-only whisper posts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44783"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2025-7004",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gen Digital",
      "product": "Avast Antivirus",
      "cwe": "CWE-787",
      "title": "Avast antivirus heap buffer OOB write when scanning a malformed PE file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7004"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2025-7008",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gen Digital",
      "product": "Avast Antivirus",
      "cwe": "CWE-125",
      "title": "Avast antivirus heap buffer OOB read when scanning a malformed PE file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7008"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2025-7009",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gen Digital",
      "product": "Avast Antivirus",
      "cwe": "CWE-125",
      "title": "Avast antivirus heap buffer OOB read when scanning a malformed PE file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7009"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2025-7011",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gen Digital",
      "product": "Avast Antivirus",
      "cwe": "CWE-125",
      "title": "Avast antivirus heap OOB when scanning a malformed zip file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7011"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-9269",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00145,
      "epss_percentile": 0.04313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Secure Copy Content Protection and Content Locking",
      "cwe": null,
      "title": "Secure Copy Content Protection and Content Locking < 5.1.5 - Admin+ Stored XSS via ays_sccp_sub_icon_image Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9269"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-44894",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00143,
      "epss_percentile": 0.04075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-940",
      "title": "Netty's Default QUIC token handler accepts any client-supplied token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44894"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-53606",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apostrophecms",
      "product": "sanitize-html",
      "cwe": "CWE-79",
      "title": "sanitize-html has an incomplete URI scheme validation that allows javascript: URIs through action, formaction, data, poster, and background attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53606"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-45536",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-200",
      "title": "Netty: Unix-socket fd receive leaks descriptors when peer sends two at once",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45536"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2025-7002",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gen Digital",
      "product": "Avira Antivirus",
      "cwe": "CWE-125",
      "title": "Avira antivirus engine heap buffer OOB read when scanning a malformed PDF file (variant 2)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7002"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2025-7003",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gen Digital",
      "product": "Avira Antivirus",
      "cwe": "CWE-125",
      "title": "Avira antivirus engine heap buffer OOB read when scanning a malformed PDF file (variant 1)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7003"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2025-7017",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gen Digital",
      "product": "Avira Antivirus",
      "cwe": "CWE-125",
      "title": "Avira antivirus engine heap buffer OOB read when scanning a malformed Windows MSI file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7017"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-46690",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "spearman",
      "product": "unbounded-spsc",
      "cwe": "CWE-125",
      "title": "unbounded-spsc: Sender::send pointer-as-value transmute causes OOB read and fake-Arc drop under TX/RX race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46690"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-42890",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "actualbudget",
      "product": "actual",
      "cwe": "CWE-94",
      "title": "actual Allows Electron to Run As Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42890"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-49396",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00123,
      "epss_percentile": 0.02479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nezhahq",
      "product": "nezha",
      "cwe": "CWE-352",
      "title": "Nezha Monitoring: Cross-site GET request can trigger stored cron commands on a victim's agents",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49396"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2025-9032",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gen Digital",
      "product": "Avira Antivirus",
      "cwe": "CWE-125",
      "title": "Avira antivirus engine heap buffer OOB read when scanning a malformed PE file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-9032"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2025-9033",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gen Digital",
      "product": "Avira Antivirus",
      "cwe": "CWE-125",
      "title": "Avira antivirus engine heap buffer OOB read when scanning a malformed PDF file (variant 3)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-9033"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2025-14098",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gen Digital",
      "product": "Avira Antivirus",
      "cwe": "CWE-190",
      "title": "Avira antivirus engine heap buffer OOB write when scanning a malformed MS-DOS executable file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14098"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-6676",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gen Digital",
      "product": "Avira Antivirus",
      "cwe": "CWE-787",
      "title": "Avira antivirus engine heap buffer OOB write when scanning a malformed POSIX tar archive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6676"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-48612",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phpBB",
      "product": "phpBB",
      "cwe": "CWE-352",
      "title": "Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s account to be linked to an attacker-controlled account. This can result in unauthorized account linking and potential account takeover.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48612"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-41158",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.02034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-416",
      "title": "GPU DDK - Backed sparse PMRs are not handled by deferred free mechanism after shrink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41158"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2025-7010",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gen Digital",
      "product": "Avast Antivirus",
      "cwe": "CWE-674",
      "title": "Avast antivirus stack overflow when scanning a malformed PDF file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7010"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2025-7019",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gen Digital",
      "product": "Avast Antivirus",
      "cwe": "CWE-121",
      "title": "Avast antivirus stack overflow when scanning a malformed Office Open XML file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7019"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2025-7005",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gen Digital",
      "product": "Avast Antivirus",
      "cwe": "CWE-674",
      "title": "Avast antivirus infinite recursion when scanning a malformed PE file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7005"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2025-7006",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.0153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gen Digital",
      "product": "Avast Antivirus",
      "cwe": "CWE-590",
      "title": "Avast antivirus use of stack memory after free when scanning a malformed PE file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7006"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2025-7018",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gen Digital",
      "product": "Avira Antivirus",
      "cwe": "CWE-476",
      "title": "Avira antivirus engine null pointer dereference when scanning a malformed PE file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7018"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-11879",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00108,
      "epss_percentile": 0.01392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mobatek",
      "product": "MobaXterm Personal Edition (Portable)",
      "cwe": "CWE-427",
      "title": "Arbitrary code execution in MobaXterm Personal Edition (Portable)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11879"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-11967",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00108,
      "epss_percentile": 0.01392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mobatek",
      "product": "MobaXterm Personal Edition (Portable)",
      "cwe": "CWE-427",
      "title": "Arbitrary code execution in MobaXterm Personal Edition (Portable)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11967"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-41568",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "moby",
      "cwe": "CWE-81",
      "title": "Moby: Race condition in docker cp allows creation of arbitrary empty files on the host via symlink swap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41568"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-41155",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-653",
      "title": "GPU DDK - SharedSecMem mapped into all GPU virtual address spaces",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41155"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-12065",
      "cvss_base": 0.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00106,
      "epss_percentile": 0.01242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Groww",
      "product": "Stock, Mutual Fund, Gold App",
      "cwe": "CWE-285",
      "title": "Groww Stock, Mutual Fund, Gold App WebView URL improper authorization in handler for custom url scheme",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12065"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-45170",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00105,
      "epss_percentile": 0.01231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CyberArk Software, a Palo Alto Networks Company",
      "product": "Vendor PAM",
      "cwe": "CWE-295",
      "title": "Idira Vendor PAM - Self-Hosted Connector: Potential Security Bypass due to Incomplete TLS Certificate Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45170"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-1836",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Redmine",
      "product": "Redmine",
      "cwe": "CWE-257",
      "title": "Stored credentials in Redmine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1836"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-42306",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00104,
      "epss_percentile": 0.01186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "moby",
      "cwe": "CWE-61",
      "title": "Moby: Race condition in docker cp allows bind mount redirection to host path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42306"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-53832",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00102,
      "epss_percentile": 0.01066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-290",
      "title": "OpenClaw < 2026.5.18 - Identity Header Forgery via Trusted-Proxy Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53832"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-53820",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.00691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-862",
      "title": "OpenClaw < 2026.5.12 - Exec Denylist Bypass in Bundle MCP Loopback Session Spawn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53820"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-46342",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00091,
      "epss_percentile": 0.00566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxt",
      "product": "nuxt",
      "cwe": "CWE-79",
      "title": "Nuxt: `__nuxt_island` endpoint does not bind responses to request props, enabling shared-cache poisoning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46342"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-53406",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0008,
      "epss_percentile": 0.00216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zoom Communications",
      "product": "Remote Control for Zoom Contact Center",
      "cwe": "CWE-345",
      "title": "Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53406"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-54055",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00072,
      "epss_percentile": 0.00058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kovidgoyal",
      "product": "kitty",
      "cwe": "CWE-59",
      "title": "Kitty has an Arbitrary File Write via Symlink Race Condition in File Transmission Protocol",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54055"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-9266",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0007,
      "epss_percentile": 0.00041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Moxa",
      "product": "UC-1200A Series",
      "cwe": "CWE-325",
      "title": "A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability represents an incomplete remediation of CVE-2026-0714. The firmware introduced TPM2 parameter encryption as a countermeasure against CVE-2026-0714. However, an omission in the authorization session configuration causes the parameter encryption to provide no effective protection. An attacker with invasive physical access to the device can still capture TPM communications on the SPI bus and derive the LUKS disk encryption key in plaintext. While successful exploitation results in full compromise of the encrypted disk volume, the attack requires invasive physical access, including opening the device and attaching external equipment to the SPI bus. Remote exploitation is not possible, and the attack does not affect any downstream systems.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9266"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3840",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3840 (kedro-org/kedro). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42850",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42850 (kovidgoyal kitty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42851",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42851 (kovidgoyal kitty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45669",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45669 (nuxt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45670",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45670 (nuxt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46690",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46690 (spearman unbounded-spsc). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47200",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47200 (nuxt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48558",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48558 (SimpleHelp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49993",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49993 (nuxt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50082",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50082 (Aqara Cloud Developer Portal). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50083",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50083 (Aqara Aquara IAM/SSO Gateway). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50084",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50084 (Aqara Cloud Production API). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50085",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50085 (Aqara Board service). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50086",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50086 (Aqara IAM/SSO Gateway). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50087",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50087 (Aqara IAM/SSO Gateway). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50088",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50088 (Aqara Developer Portal). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50089",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50089 (Aqara IAM/SSO Gateway). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50090",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50090 (Aqara Cloud OAuth Authorization Endpoint). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50091",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50091 (Aqara com.lumiunited.aqarahome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54056",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54056 (kovidgoyal kitty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54057",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54057 (kovidgoyal kitty). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-50751",
      "detail": "DUE DATE PASSED — CVE-2026-50751 (checkpoint Quantum Security Gateway). CISA remediation deadline was June 11, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
