{
  "day": "2026-06-13",
  "boundary": "UTC calendar day",
  "published_count": 22,
  "by_severity": {
    "CRITICAL": 2,
    "HIGH": 7,
    "MEDIUM": 9,
    "LOW": 4
  },
  "kev_count": 0,
  "exploit_reference_count": 0,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-12174",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00582,
      "epss_percentile": 0.45273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DCS-935L",
      "cwe": "CWE-119",
      "title": "D-Link DCS-935L HTTP rhea snprintf format string",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12174"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-9848",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0051,
      "epss_percentile": 0.41398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "emarket-design",
      "product": "Customer Support Ticket System & Helpdesk",
      "cwe": "CWE-89",
      "title": "WP Ticket <= 6.0.4 - Unauthenticated SQL Injection via WordPress Search 's' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9848"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-12183",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00441,
      "epss_percentile": 0.36883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nefteprodukttekhnika LLC",
      "product": "BUK TS-G Gas Station Automation System",
      "cwe": "CWE-287",
      "title": "Nefteprodukttekhnika BUK TS-G Gas Station Automation System Authentication Bypass via ajax-login.php Accepting Arbitrary Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12183"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-5513",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00437,
      "epss_percentile": 0.36582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ladela",
      "product": "Online Scheduling and Appointment Booking System – Bookly",
      "cwe": "CWE-79",
      "title": "Online Scheduling and Appointment Booking System – Bookly <= 27.2 - Unauthenticated Stored Cross-Site Scripting via 'bookly-customer-full-name' Cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5513"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-11769",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00361,
      "epss_percentile": 0.2935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana Operator",
      "cwe": "CWE-22",
      "title": "Operator - Namespaced User Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11769"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-12089",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.26681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aurelienlws",
      "product": "LWS Optimize – All-in-One Speed Booster & Cache Tools",
      "cwe": "CWE-22",
      "title": "WS Optimize – All-in-One Speed Booster & Cache Tools <= 3.3.19 - Authenticated (Editor+) Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12089"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-9109",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "john-dagelmore",
      "product": "GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites",
      "cwe": "CWE-79",
      "title": "GPTranslate <= 2.31 - Unauthenticated Stored Cross-Site Scripting via REST API Translation Storage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9109"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-9134",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00301,
      "epss_percentile": 0.22757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fooplugins",
      "product": "Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel",
      "cwe": "CWE-79",
      "title": "Photo Gallery by FooGallery : Responsive Image Gallery, Masonry Gallery & Carousel <= 3.1.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'custom_attribute_key' Shortcode Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9134"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-2470",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "softaculous",
      "product": "Page Builder: Pagelayer – Drag and Drop website builder",
      "cwe": "CWE-863",
      "title": "Pagelayer <= 2.0.9 - Incorrect Authorization to Authenticated (Contributor+) Mail Relay Configuration via 'contacts'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2470"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-12176",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00265,
      "epss_percentile": 0.18547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "CET Automated Grading System with AI Predictive Analytics",
      "cwe": "CWE-79",
      "title": "SourceCodester CET Automated Grading System with AI Predictive Analytics index.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12176"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-9062",
      "cvss_base": 3.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00248,
      "epss_percentile": 0.1645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Store Locator WordPress",
      "cwe": "CWE-22",
      "title": "Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9062"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-6428",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Koha Community",
      "product": "Koha",
      "cwe": "CWE-89",
      "title": "Koha SQL Injection in reports/catalogue_out.pl via Filter URL Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6428"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-3297",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.12995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "softaculous",
      "product": "Page Builder: Pagelayer – Drag and Drop website builder",
      "cwe": "CWE-79",
      "title": "Page Builder: Pagelayer – Drag and Drop website builder <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Anchor Block",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3297"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-1291",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tigroumeow",
      "product": "Meow Gallery",
      "cwe": "CWE-639",
      "title": "Meow Gallery <= 5.4.4 - Missing Authorization to Authenticated (Author+) Shortcode creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1291"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-12175",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00214,
      "epss_percentile": 0.12128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Student Attendance Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Student Attendance Management System createStudents.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12175"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-9629",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codesupplyco",
      "product": "Canvas",
      "cwe": "CWE-79",
      "title": "Canvas <= 2.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'tag' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9629"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-11624",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00153,
      "epss_percentile": 0.04976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "MCP Toolbox for Databases",
      "cwe": "CWE-346",
      "title": "The Model Context Protocol has a security warning advising servers to validate the \"Origin\" header on all incoming connections to prevent DNS rebinding attacks. Prior to the v0.25.0 release, users had no way to validate the origin's host. In v0.25.0, a new \"--allowed-hosts\" flag was introduced alongside the existing \"--allowed-origins\" flag, enabling users to specify permitted hosts at server startup. Both flags default to \"*\", allowing users to implement strict access controls as needed without breaking existing setups. If either flag is set to \"*\", the server will output a startup warning about potential vulnerabilities. Documentation has also been updated to highlight these security considerations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11624"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-9061",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00145,
      "epss_percentile": 0.04336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Store Locator WordPress",
      "cwe": "CWE-79",
      "title": "Agile Store Locator < 1.6.9 - Admin+ Stored XSS via logo_name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9061"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-54230",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00141,
      "epss_percentile": 0.03951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 8",
      "cwe": "CWE-59",
      "title": "Abrt: event handler scripts follow symlinks when writing output files, allowing arbitrary file overwrites",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54230"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-54231",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 8",
      "cwe": "CWE-74",
      "title": "Abrt: unsanitized systemd journal content written to dump directory files enables content injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54231"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-54228",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00103,
      "epss_percentile": 0.01139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
      "cwe": "CWE-367",
      "title": "Abrt: toctou race condition in abrt-dbus setelement allows arbitrary file writes to dump directories",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54228"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-54229",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00093,
      "epss_percentile": 0.00628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 7 Extended Lifecycle Support",
      "cwe": "CWE-362",
      "title": "Abrt: chownproblemdir succeeds during active post-create event processing due to inadequate locking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54229"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-12183",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-12183 (Nefteprodukttekhnika LLC BUK TS-G Gas Station Automation System). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
