{
  "day": "2026-06-16",
  "boundary": "UTC calendar day",
  "published_count": 546,
  "by_severity": {
    "CRITICAL": 156,
    "HIGH": 272,
    "MEDIUM": 101,
    "LOW": 17
  },
  "kev_count": 1,
  "exploit_reference_count": 14,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-48907",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.6883,
      "epss_percentile": 0.99289,
      "kev": true,
      "kev_due_at": "2026-06-19",
      "vendor": "joomlacontenteditor.net",
      "product": "Joomla Content Editor (JCE) extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for Joomla < 2.9.99.5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48907"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-50656",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.10749,
      "epss_percentile": 0.95463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Malware Protection Engine",
      "cwe": "CWE-59",
      "title": "Microsoft Defender Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50656"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-11409",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.02787,
      "epss_percentile": 0.85256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "TL-WR940N v6",
      "cwe": "CWE-78",
      "title": "OS Command Injection in IPv6 PPPoE Configuration in TP-Link TL-WR940N",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11409"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-11410",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.02787,
      "epss_percentile": 0.85255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "TL-WR940N v6",
      "cwe": "CWE-78",
      "title": "OS Command Injection in BigPond Cable (BPA) Configuration in TP-Link TL-WR940N",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11410"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-48294",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.01906,
      "epss_percentile": 0.78086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Acrobat PDF Extension (Chrome)",
      "cwe": "CWE-79",
      "title": "Adobe Acrobat PDF Extension (Chrome) versions 26.5.2.2 and earlier are affected by a UXSS-class cross-origin data disclosure vulnerability. An attacker could exploit this vulnerability to gain access to data regarding the victim's session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48294"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-22313",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00921,
      "epss_percentile": 0.57521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Radiflow",
      "product": "iSAP Smart Collector",
      "cwe": "CWE-78",
      "title": "OS Commands Executed with Administrative Permissions in Radiflow iSAP Smart Collector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22313"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-12398",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00889,
      "epss_percentile": 0.56539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-78",
      "title": "Galaxy_ng: shell injection in legacy role import via unsanitized git ref names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12398"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-6933",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00847,
      "epss_percentile": 0.55229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "premmerce",
      "product": "Premmerce Dev Tools",
      "cwe": "CWE-434",
      "title": "Premmerce Dev Tools <= 2.0 - Missing Authorization to Authenticated (Subscriber+) Remote Code Execution via Plugin Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6933"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-48779",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00782,
      "epss_percentile": 0.53175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "websockets",
      "product": "ws",
      "cwe": "CWE-400",
      "title": "ws: Memory exhaustion DoS from tiny fragments and data chunks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48779"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-5416",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00771,
      "epss_percentile": 0.52828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TURCK",
      "product": "TBEN-LL-SE-M2",
      "cwe": "CWE-78",
      "title": "Command Injection via name parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5416"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-10303",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00757,
      "epss_percentile": 0.52336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ServerCo",
      "product": "getssl",
      "cwe": "CWE-73",
      "title": "ServerCo getssl ACME shell script path injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10303"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-48929",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00723,
      "epss_percentile": 0.51164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rocket.Chat",
      "product": "Rocket.Chat",
      "cwe": "CWE-287",
      "title": "Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletion. The deleteFileMessage Meteor method permanently deletes any uploaded file by ID without requiring authentication. When called via an unauthenticated DDP WebSocket connection, Meteor.userId() returns null, causing the authorization check to be skipped. Execution falls through to FileUpload.getStore('Uploads').deleteById(fileID), which removes the file from storage and database unconditionally. File IDs are discoverable from public channel message payloads and download URLs.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48929"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-35278",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00644,
      "epss_percentile": 0.48133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PT PeopleTools",
      "cwe": "CWE-306",
      "title": "Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Performance Monitor). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35278"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-48055",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00621,
      "epss_percentile": 0.47104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "truelockmc",
      "product": "streambert",
      "cwe": "CWE-20",
      "title": "Streambert: Arbitrary File Write (Zip Slip) via Subtitle Extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48055"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-35300",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00565,
      "epss_percentile": 0.44422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebLogic Server",
      "cwe": "CWE-502",
      "title": "Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise WebLogic Server. Successful attacks of this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35300"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-10649",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00561,
      "epss_percentile": 0.44229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-190",
      "title": "Pacemaker: pacemaker: denial of service via integer overflow in remote message decompression",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10649"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-27429",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00556,
      "epss_percentile": 0.43951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BoldThemes",
      "product": "Nifty",
      "cwe": "CWE-502",
      "title": "WordPress Nifty theme <= 1.4.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27429"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2025-69139",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00533,
      "epss_percentile": 0.42752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AivahThemes",
      "product": "Car Zone",
      "cwe": "CWE-22",
      "title": "WordPress Car Zone theme <= 3.7 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69139"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2025-69108",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00525,
      "epss_percentile": 0.42323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Hot Coffee",
      "cwe": "CWE-502",
      "title": "WordPress Hot Coffee theme <= 1.7 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69108"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2025-69122",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00525,
      "epss_percentile": 0.42323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "SeaFood Company",
      "cwe": "CWE-502",
      "title": "WordPress SeaFood Company theme <= 1.4 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69122"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-46331",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00525,
      "epss_percentile": 0.42295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-190",
      "title": "net/sched: fix pedit partial COW leading to page cache corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46331"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-46850",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00521,
      "epss_percentile": 0.4208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Shell",
      "cwe": "CWE-94",
      "title": "Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.0+9.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise MySQL Shell. While the vulnerability is in MySQL Shell, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Shell. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46850"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-46807",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00519,
      "epss_percentile": 0.41916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Identity Manager",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46807"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-35268",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00518,
      "epss_percentile": 0.41873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Identity Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Identity Manager. While the vulnerability is in Identity Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35268"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-35312",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00518,
      "epss_percentile": 0.41878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Virtual Directory",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Virtual Directory product of Oracle Fusion Middleware (component: Virtual Directory Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Virtual Directory. Successful attacks of this vulnerability can result in takeover of Oracle Virtual Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35312"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-46773",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00518,
      "epss_percentile": 0.41878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46773"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-46774",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00518,
      "epss_percentile": 0.41878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in takeover of Oracle Unified Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46774"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-46857",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00508,
      "epss_percentile": 0.4122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Oracle Management Service). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46857"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-46859",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00508,
      "epss_percentile": 0.41221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Agile PLM",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security). The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM. Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46859"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-8442",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00501,
      "epss_percentile": 0.40848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "https://wpreviewslider.com/",
      "product": "WP Review Slider Pro",
      "cwe": "CWE-22",
      "title": "WP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) Arbitrary File Deletion via 'myaction' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8442"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-35270",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00496,
      "epss_percentile": 0.4053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35270"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-12292",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00493,
      "epss_percentile": 0.40375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Incorrect boundary conditions in the Web Audio component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12292"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-35292",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise WebLogic Server. While the vulnerability is in WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35292"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-35301",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise WebLogic Server. While the vulnerability is in WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35301"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-46798",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46798"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-46800",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46800"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-35286",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35286"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-35293",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35293"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-35296",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35296"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-35310",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35310"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-35319",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35319"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-46783",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebCenter Content: Imaging",
      "cwe": "CWE-306",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46783"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-46797",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46797"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-46801",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46801"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-46878",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46878"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-46879",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": "CWE-306",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46879"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-46880",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46880"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-46890",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel Apps - Marketing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46890"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-46905",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": "CWE-306",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46905"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-46909",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46909"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-46853",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-79",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46853"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-35280",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00482,
      "epss_percentile": 0.39683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35280"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-35281",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00482,
      "epss_percentile": 0.39683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35281"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-12225",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00481,
      "epss_percentile": 0.39633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "syracom AG",
      "product": "Secure Login (2FA) for Jira",
      "cwe": "CWE-288",
      "title": "syracom Secure Login (2FA) for Confluence allows 2FA bypass via spoofed User-Agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12225"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-12328",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00476,
      "epss_percentile": 0.39265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-120",
      "title": "Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12328"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-35307",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00474,
      "epss_percentile": 0.39141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35307"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-35308",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00474,
      "epss_percentile": 0.39142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35308"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-46803",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00474,
      "epss_percentile": 0.39143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46803"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-35304",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00474,
      "epss_percentile": 0.39141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35304"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-46845",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00474,
      "epss_percentile": 0.39143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle WebCenter Portal. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46845"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-46884",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00474,
      "epss_percentile": 0.39143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel Apps - Marketing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46884"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-46887",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00474,
      "epss_percentile": 0.39142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel Apps - Marketing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46887"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-46889",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00474,
      "epss_percentile": 0.39142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel Apps - Marketing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46889"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2025-69177",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00474,
      "epss_percentile": 0.39186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "THEMELOGI",
      "product": "Roneous",
      "cwe": "CWE-98",
      "title": "WordPress Roneous theme <= 2.1.5 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69177"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-46778",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46778"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-46781",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via RMI to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46781"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-35309",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35309"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-46766",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46766"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-46799",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46799"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-46813",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46813"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-46860",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Router",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Router. Successful attacks of this vulnerability can result in takeover of MySQL Router. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46860"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-46881",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46881"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-46882",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46882"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-46883",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46883"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-46902",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Command Center Framework",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Command Center Framework. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46902"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-46904",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46904"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-46856",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-79",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46856"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-10829",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00472,
      "epss_percentile": 0.39006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Moxa",
      "product": "NPort W2150A-W4/W2250A-W4 Series",
      "cwe": "CWE-121",
      "title": "A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earlier. This vulnerability stems from insufficient input validation of user-supplied input in the \"Server location\" parameter on the Basic settings page. An attacker could exploit this vulnerability by sending crafted input to the web service, resulting in memory corruption. Successful exploitation of this vulnerability could allow remote code execution on the target system with root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10829"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-8176",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00472,
      "epss_percentile": 0.3898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "latepoint",
      "product": "LatePoint – Calendar Booking Plugin for Appointments and Events",
      "cwe": "CWE-269",
      "title": "LatePoint <= 5.5.1 - Authenticated (Agent+) Privilege Escalation to Administrator via IDOR in OsOrdersController::create_or_update + Unauthenticated Customer-Cabinet Password Reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8176"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-46863",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00471,
      "epss_percentile": 0.38898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Server",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Connection Handling). Supported versions that are affected are MySQL Server: 8.4.0-8.4.9, 9.0.0-9.7.0; MySQL Cluster: 8.0.11-8.0.46, 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46863"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-12256",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00468,
      "epss_percentile": 0.38765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeFusion",
      "product": "Avada",
      "cwe": "CWE-502",
      "title": "WordPress Avada theme <= 3.15.3 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12256"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2025-69131",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00467,
      "epss_percentile": 0.38705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "extendons",
      "product": "WordPress & WooCommerce Scraper Plugin, Import Data from Any Site",
      "cwe": "CWE-22",
      "title": "WordPress WordPress & WooCommerce Scraper Plugin, Import Data from Any Site plugin <= 1.0.7 - Arbitrary File Download vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69131"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-35298",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00463,
      "epss_percentile": 0.38415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebLogic Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise WebLogic Server. While the vulnerability is in WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35298"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-46862",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00463,
      "epss_percentile": 0.38444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Router",
      "cwe": "CWE-400",
      "title": "Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise MySQL Router. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Router. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46862"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-46875",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00462,
      "epss_percentile": 0.38379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Deployment Library). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46875"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-46896",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00462,
      "epss_percentile": 0.38379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Command Center Framework",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46896"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-46945",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00462,
      "epss_percentile": 0.3838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iSupport",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport. While the vulnerability is in Oracle iSupport, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46945"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-46946",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00462,
      "epss_percentile": 0.38379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iSupport",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport. While the vulnerability is in Oracle iSupport, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46946"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-46851",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00459,
      "epss_percentile": 0.38156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Campus Community",
      "cwe": "CWE-94",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise CS Campus Community. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46851"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-46944",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00453,
      "epss_percentile": 0.37754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iSupport",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle iSupport. While the vulnerability is in Oracle iSupport, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle iSupport. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46944"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-35326",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35326"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-46769",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Development Framework (ADF)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Shared Components). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Application Development Framework (ADF). Successful attacks of this vulnerability can result in takeover of Oracle Application Development Framework (ADF). CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46769"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-46867",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Extensibility Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46867"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-46868",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Extensibility Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46868"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-46922",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HR Intelligence",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HR Intelligence. Successful attacks of this vulnerability can result in takeover of Oracle HR Intelligence. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46922"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-46938",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Cost Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46938"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-46956",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Property Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Property Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Property Manager. Successful attacks of this vulnerability can result in takeover of Oracle Property Manager. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46956"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-46960",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Portfolio Analysis",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in takeover of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46960"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-46969",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Financials for EMEA",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Financials for EMEA product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Financials for EMEA. Successful attacks of this vulnerability can result in takeover of Oracle Financials for EMEA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46969"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-46970",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HR Intelligence",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HR Intelligence. Successful attacks of this vulnerability can result in takeover of Oracle HR Intelligence. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46970"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2024-24909",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00448,
      "epss_percentile": 0.37433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "OpenManage",
      "cwe": "CWE-77",
      "title": "Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in the gateway plugin. A remote authenticated user could potentially exploit this vulnerability to escalate privileges. The malicious user may gain the ability to run arbitrary code remotely. This is a high severity vulnerability so Dell recommends customers to upgrade at the earliest opportunity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-24909"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-46858",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00447,
      "epss_percentile": 0.37345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "APM - Application Performance Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JADM, JVM Diagnostics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise APM - Application Performance Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all APM - Application Performance Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of APM - Application Performance Management. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46858"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-48777",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00446,
      "epss_percentile": 0.373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gtsteffaniak",
      "product": "filebrowser",
      "cwe": "CWE-22",
      "title": "FileBrowser Quantum: Path Traversal in public share PATCH allows file ops outside shared directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48777"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-46855",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00441,
      "epss_percentile": 0.36882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46855"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-35265",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Identity Manager",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Security). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35265"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-35267",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Identity Manager",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in takeover of Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35267"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-0647",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "FLEX I/O EtherNet/IP Adapters",
      "cwe": "CWE-306",
      "title": "Rockwell Automation FLEX I/O Dual-port EtherNet/IP Adapters – Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0647"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2025-58924",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX Group",
      "product": "Geya",
      "cwe": "CWE-98",
      "title": "WordPress Geya theme <= 1.15 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58924"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2025-69105",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Modernee",
      "cwe": "CWE-98",
      "title": "WordPress Modernee theme <= 1.6.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69105"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2025-69107",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Rosaleen",
      "cwe": "CWE-98",
      "title": "WordPress Rosaleen theme <= 2.8 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69107"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2025-69109",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Raider Spirit",
      "cwe": "CWE-98",
      "title": "WordPress Raider Spirit theme <= 1.1.2 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69109"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2025-69112",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Planty",
      "cwe": "CWE-98",
      "title": "WordPress Planty theme <= 1.14.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69112"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2025-69113",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Nexio",
      "cwe": "CWE-98",
      "title": "WordPress Nexio theme <= 1.10.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69113"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2025-69114",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "MaxiNet",
      "cwe": "CWE-98",
      "title": "WordPress MaxiNet theme <= 1.2.10 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69114"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2025-69116",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Iona",
      "cwe": "CWE-98",
      "title": "WordPress Iona theme <= 1.0.8 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69116"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2025-69119",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.3644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Corbesier",
      "cwe": "CWE-98",
      "title": "WordPress Corbesier theme <= 1.15.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69119"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2025-69121",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Deliciosa",
      "cwe": "CWE-98",
      "title": "WordPress Deliciosa theme <= 1.10.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69121"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2025-69124",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Especio",
      "cwe": "CWE-98",
      "title": "WordPress Especio theme <= 1.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69124"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2025-69136",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "THEMELOGI",
      "product": "Wanium",
      "cwe": "CWE-98",
      "title": "WordPress Wanium theme <= 1.9.8 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69136"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2025-69142",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Abelle",
      "cwe": "CWE-98",
      "title": "WordPress Abelle theme <= 1.22 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69142"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2025-69143",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.3644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Mission",
      "cwe": "CWE-98",
      "title": "WordPress Mission theme <= 1.22 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69143"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2025-69147",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Putter",
      "cwe": "CWE-98",
      "title": "WordPress Putter theme <= 1.17 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69147"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2025-69149",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Top Dog",
      "cwe": "CWE-98",
      "title": "WordPress Top Dog theme <= 1.0.5 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69149"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2025-69150",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Medeus",
      "cwe": "CWE-98",
      "title": "WordPress Medeus theme <= 1.14 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69150"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2025-69159",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Printo",
      "cwe": "CWE-98",
      "title": "WordPress Printo theme <= 1.11 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69159"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2025-69160",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Gita",
      "cwe": "CWE-98",
      "title": "WordPress Gita theme <= 1.11 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69160"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2025-69162",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Grecko",
      "cwe": "CWE-98",
      "title": "WordPress Grecko theme <= 5.17 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69162"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2025-69163",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "WineShop",
      "cwe": "CWE-98",
      "title": "WordPress WineShop theme <= 3.17 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69163"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2025-69165",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Choreo",
      "cwe": "CWE-98",
      "title": "WordPress Choreo theme <= 1.6 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69165"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2025-69167",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.3644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Eros",
      "cwe": "CWE-98",
      "title": "WordPress Eros theme <= 1.3 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69167"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2025-69168",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Spike",
      "cwe": "CWE-98",
      "title": "WordPress Spike theme <= 1.2 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69168"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2025-69178",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CactusThemes",
      "product": "Truemag",
      "cwe": "CWE-98",
      "title": "WordPress Truemag theme <= 4.3.14.2 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69178"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-46777",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00434,
      "epss_percentile": 0.36358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46777"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-46794",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00432,
      "epss_percentile": 0.36157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Identity Manager Connector",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Connector). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via SSH to compromise Identity Manager Connector. While the vulnerability is in Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Identity Manager Connector. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46794"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-46864",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via SSH to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46864"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-25470",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00428,
      "epss_percentile": 0.35871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ACPT",
      "product": "ACPT (Pro) - Custom Post Types Plugin for WordPress",
      "cwe": "CWE-94",
      "title": "WordPress ACPT (Pro) - Custom Post Types plugin for WordPress plugin <= 2.0.47 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25470"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-46784",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00425,
      "epss_percentile": 0.35671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebCenter Content: Imaging",
      "cwe": "CWE-284",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all WebCenter Content: Imaging accessible data as well as unauthorized access to critical data or complete access to all WebCenter Content: Imaging accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46784"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2025-60085",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX Group",
      "product": "Learnify",
      "cwe": "CWE-98",
      "title": "WordPress Learnify theme <= 1.15.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60085"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-34894",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebGeniusLab",
      "product": "Integrio Core",
      "cwe": "CWE-98",
      "title": "WordPress Integrio Core plugin < 1.2.8 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34894"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-39522",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "Solene",
      "cwe": "CWE-98",
      "title": "WordPress Solene theme <= 3.4 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39522"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-39549",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "Aperitif",
      "cwe": "CWE-98",
      "title": "WordPress Aperitif theme <= 1.5 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39549"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-39568",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "Mr. SEO",
      "cwe": "CWE-98",
      "title": "WordPress Mr. SEO theme <= 2.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39568"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-46789",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00416,
      "epss_percentile": 0.34838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46789"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-35276",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PT PeopleTools",
      "cwe": "CWE-306",
      "title": "Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Application Server). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35276"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-46791",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.34705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46791"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-35283",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35283"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-35284",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35284"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-35285",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35285"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-35294",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Identity Manager Connector",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: Mainframe Connectors). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager Connector. While the vulnerability is in Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Identity Manager Connector. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35294"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-35313",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35313"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-35316",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35316"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-35321",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35321"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-35323",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35323"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-46832",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Discovery Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46832"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-46838",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46838"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-46847",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46847"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-46854",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Target Management). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46854"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-46895",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Command Center Framework",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46895"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-46907",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Order Promising",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Order Promising product of Oracle JD Edwards (component: Order Promising Integration). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Order Promising. While the vulnerability is in JD Edwards EnterpriseOne Order Promising, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Order Promising. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46907"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-46908",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.3441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Accounts Payable",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Oracle JD Edwards (component: Accounts Payable). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Accounts Payable. While the vulnerability is in JD Edwards EnterpriseOne Accounts Payable, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Accounts Payable. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46908"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-46918",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.3441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Product Development",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Product Development. While the vulnerability is in Oracle Process Manufacturing Product Development, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Product Development. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46918"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-46933",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Applications Manager",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Manager. While the vulnerability is in Oracle Applications Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Applications Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46933"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-35299",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebLogic Server. Successful attacks of this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35299"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-35303",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebLogic Server",
      "cwe": "CWE-306",
      "title": "Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebLogic Server. Successful attacks of this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35303"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-35315",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35315"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-35317",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35317"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-35322",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35322"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-35325",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35325"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-46886",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel Apps - Marketing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46886"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-46929",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Cost Management",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46929"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-46931",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.3441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Asset Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset Management. Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Asset Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46931"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-46937",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iSetup",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSetup. Successful attacks of this vulnerability can result in takeover of Oracle iSetup. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46937"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-46940",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Cost Management",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in takeover of Oracle Cost Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46940"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-46942",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Process Planning",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Process Manufacturing Process Planning product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Process Planning. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Process Planning. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46942"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-46947",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.3441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Outbound Telephony",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Outbound Telephony. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46947"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-46950",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Outbound Telephony",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks of this vulnerability can result in takeover of Oracle Advanced Outbound Telephony. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46950"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-46951",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Quality",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality. Successful attacks of this vulnerability can result in takeover of Oracle Quality. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46951"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-46961",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Portfolio Analysis",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in takeover of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46961"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-46965",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Universal Work Queue",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46965"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-46973",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Outsourced Mfg for Discrete Industries",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Outsourced Mfg for Discrete Industries. Successful attacks of this vulnerability can result in takeover of Oracle Outsourced Mfg for Discrete Industries. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46973"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-12327",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00407,
      "epss_percentile": 0.34061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12327"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-35289",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00407,
      "epss_percentile": 0.34116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PT PeopleTools",
      "cwe": "CWE-306",
      "title": "Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35289"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2025-69103",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00407,
      "epss_percentile": 0.3413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Utillz",
      "product": "Brikk",
      "cwe": "CWE-862",
      "title": "WordPress Brikk theme <= 3.0.0 - Arbitrary Content Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69103"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-46809",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00405,
      "epss_percentile": 0.33915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Sites accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46809"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-46930",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00405,
      "epss_percentile": 0.3388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle In-Memory Cost Management for Discrete Industries",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle In-Memory Cost Management for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.12-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle In-Memory Cost Management for Discrete Industries. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle In-Memory Cost Management for Discrete Industries accessible data as well as unauthorized access to critical data or complete access to all Oracle In-Memory Cost Management for Discrete Industries accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46930"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-46949",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00405,
      "epss_percentile": 0.3388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Advanced Outbound Telephony",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Advanced Outbound Telephony accessible data as well as unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46949"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-46852",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00403,
      "epss_percentile": 0.33684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Metadata Plugin). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46852"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-35311",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.3368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebLogic Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebLogic Server. Successful attacks of this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35311"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-46885",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Integration",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration. Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46885"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-46921",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46921"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-9507",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00403,
      "epss_percentile": 0.33767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Enhancesoft",
      "product": "osTicket",
      "cwe": "CWE-38",
      "title": "Session fixation vulnerability in Enhancesoft's osTicket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9507"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-35282",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35282"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-46765",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46765"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-46767",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46767"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-46779",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3 to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46779"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-46782",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Enterprise Capture",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture. While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46782"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-46792",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Identity Manager Connector",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: Generic Unix Connector). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager Connector. While the vulnerability is in Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Identity Manager Connector. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46792"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-46793",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Identity Manager Connector",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: Database User). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Identity Manager Connector. While the vulnerability is in Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Identity Manager Connector. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46793"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-46802",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46802"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-46814",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46814"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-46844",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46844"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-46900",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Command Center Framework",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Enterprise Command Center Framework. While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46900"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-46963",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Universal Work Queue",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. While the vulnerability is in Oracle Universal Work Queue, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46963"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-46964",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Universal Work Queue",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. While the vulnerability is in Oracle Universal Work Queue, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46964"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-35318",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35318"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-35324",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35324"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-46780",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebCenter Content: Imaging",
      "cwe": "CWE-306",
      "title": "Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebCenter Content: Imaging. Successful attacks of this vulnerability can result in takeover of WebCenter Content: Imaging. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46780"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-46903",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": "CWE-269",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Business Logic Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46903"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-46952",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.3362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Quality",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality. Successful attacks of this vulnerability can result in takeover of Oracle Quality. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46952"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-46962",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.3362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Project Portfolio Analysis",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio Analysis. Successful attacks of this vulnerability can result in takeover of Oracle Project Portfolio Analysis. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46962"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-46967",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Financials (International)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Public Sector Financials (International) product of Oracle E-Business Suite (component: Authorization). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Public Sector Financials (International). Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Financials (International). CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46967"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-47277",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00399,
      "epss_percentile": 0.33222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "runtipi",
      "product": "runtipi",
      "cwe": "CWE-22",
      "title": "Runtipi: Unauthenticated arbitrary file read through app-store logo symlinks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47277"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-46788",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.3312,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46788"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-12290",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.33074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Memory safety bug fixed in Firefox 152",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12290"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-46892",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.33005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Human Resources Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Human Resources Management product of Oracle JD Edwards (component: Human Resources). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Human Resources Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Human Resources Management accessible data as well as unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Human Resources Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46892"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-2381",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00396,
      "epss_percentile": 0.32985,
      "kev": false,
      "kev_due_at": null,
      "vendor": "woocommerce",
      "product": "WooCommerce Stripe Payment Gateway",
      "cwe": "CWE-862",
      "title": "WooCommerce Stripe Payment Gateway <= 10.7.0 - Missing Authorization to Unauthenticated Order Status Manipulation via 'order' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2381"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-12289",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00395,
      "epss_percentile": 0.32881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Privilege escalation in the Graphics: WebRender component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12289"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-39557",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00395,
      "epss_percentile": 0.32823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "NeoBeat",
      "cwe": "CWE-502",
      "title": "WordPress NeoBeat theme <= 1.7 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39557"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-12295",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00393,
      "epss_percentile": 0.32608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "title": "Sandbox escape in the DOM: Navigation component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12295"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-12296",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00393,
      "epss_percentile": 0.32609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "title": "Sandbox escape in the Security: Process Sandboxing component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12296"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-12297",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00393,
      "epss_percentile": 0.32608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Sandbox escape due to incorrect boundary conditions in the Networking component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12297"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-46866",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-400",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Manager Base Platform as well as unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46866"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-46795",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00391,
      "epss_percentile": 0.32385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46795"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-46805",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00391,
      "epss_percentile": 0.32385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46805"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-35259",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00389,
      "epss_percentile": 0.32251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebLogic Server",
      "cwe": "CWE-601",
      "title": "Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35259"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-35262",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00387,
      "epss_percentile": 0.32001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Data Integrator",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Market Place). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Data Integrator. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Data Integrator accessible data as well as unauthorized access to critical data or complete access to all Oracle Data Integrator accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Data Integrator. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35262"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-12291",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.31483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the Networking: HTTP component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12291"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-35274",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PT PeopleTools",
      "cwe": "CWE-306",
      "title": "Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all PeopleSoft Enterprise PT PeopleTools accessible data as well as unauthorized update, insert or delete access to some of PeopleSoft Enterprise PT PeopleTools accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35274"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-39529",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00375,
      "epss_percentile": 0.30802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX Group",
      "product": "Elementra",
      "cwe": "CWE-502",
      "title": "WordPress Elementra theme <= 1.0.9 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39529"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-54194",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00375,
      "epss_percentile": 0.30804,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeFusion",
      "product": "Fusion Builder",
      "cwe": "CWE-502",
      "title": "WordPress Fusion Builder plugin <= 3.15.4 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54194"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-46849",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.3079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Student Financials",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Student Financials product of Oracle PeopleSoft (component: Other). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Student Financials. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Student Financials accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Student Financials accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46849"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-35279",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00374,
      "epss_percentile": 0.30665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PT PeopleTools",
      "cwe": "CWE-306",
      "title": "Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Performance Monitor). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35279"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-46927",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00374,
      "epss_percentile": 0.30665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Receivables",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Receivables product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Receivables. Successful attacks of this vulnerability can result in takeover of Oracle Receivables. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46927"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-12305",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00374,
      "epss_percentile": 0.30662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Memory safety bug fixed in Firefox 152",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12305"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-35320",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00373,
      "epss_percentile": 0.30634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. While the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35320"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-39438",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.3049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Emraan Cheema",
      "product": "ListingPro",
      "cwe": "CWE-89",
      "title": "WordPress ListingPro plugin <= 2.9.10 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39438"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-46776",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Unified Directory",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Unified Directory. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Unified Directory accessible data as well as unauthorized read access to a subset of Oracle Unified Directory accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Unified Directory. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46776"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-49113",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "THEMECO",
      "product": "Cornerstone",
      "cwe": "CWE-94",
      "title": "WordPress Cornerstone plugin < 7.8.8 - Arbitrary Code Execution vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49113"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-10640",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-416",
      "title": "Use-after-free reading `net_pkt` `iface` after send in IPv6 Neighbor Discovery (`ipv6_nbr.c`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10640"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-46897",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00368,
      "epss_percentile": 0.30018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Command Center Framework",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Command Center Framework accessible data as well as unauthorized access to critical data or complete access to all Oracle Enterprise Command Center Framework accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46897"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-46901",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00368,
      "epss_percentile": 0.30018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Command Center Framework",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Command Center Framework accessible data as well as unauthorized access to critical data or complete access to all Oracle Enterprise Command Center Framework accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Command Center Framework. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46901"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-12294",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00363,
      "epss_percentile": 0.29533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "title": "Sandbox escape in the DOM: Workers component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12294"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-12326",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.29505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Memory safety bugs fixed in Firefox 152 and Thunderbird 152",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12326"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-35263",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00362,
      "epss_percentile": 0.29422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebLogic Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise WebLogic Server. While the vulnerability is in WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35263"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-46919",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00362,
      "epss_percentile": 0.29462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46919"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-46861",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00362,
      "epss_percentile": 0.29469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL NDB Cluster",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL NDB Cluster product of Oracle MySQL (component: Cluster: NDB Operator). Supported versions that are affected are 8.0.11-8.0.46, 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise MySQL NDB Cluster. While the vulnerability is in MySQL NDB Cluster, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL NDB Cluster accessible data as well as unauthorized access to critical data or complete access to all MySQL NDB Cluster accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46861"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-46932",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.29286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Asset Management",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Asset Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Asset Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Enterprise Asset Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Enterprise Asset Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46932"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-53776",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00357,
      "epss_percentile": 0.28989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PerryTS",
      "product": "perry",
      "cwe": "CWE-613",
      "title": "Perry < 0.5.1166 JWT Expiration Bypass via verify_decode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53776"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-46846",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00355,
      "epss_percentile": 0.28718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Portal",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46846"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-44932",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.28717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "wicked",
      "cwe": "CWE-78",
      "title": "indirect remote shell command injection via unsanitized DHCP options in wicked",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44932"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-49772",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Liquid Web / StellarWP",
      "product": "The Events Calendar",
      "cwe": "CWE-89",
      "title": "WordPress The Events Calendar plugin 6.15.12-6.16.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49772"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-46910",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": "CWE-20",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46910"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-35269",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Identity Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Identity Manager. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Identity Manager accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35269"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-35306",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00353,
      "epss_percentile": 0.28524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Coherence accessible data as well as unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35306"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-46796",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-601",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46796"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-10638",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-416",
      "title": "Use-after-free in Zephyr ICMPv6 RX path when updating statistics after sending an echo reply or error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10638"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-39433",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00352,
      "epss_percentile": 0.28421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mojoomla",
      "product": "WPAMS",
      "cwe": "CWE-862",
      "title": "WordPress WPAMS plugin < 49.5.3 - Arbitrary Content Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39433"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-46898",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Command Center Framework",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Enterprise Command Center Framework. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Command Center Framework accessible data as well as unauthorized access to critical data or complete access to all Oracle Enterprise Command Center Framework accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46898"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-35291",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0035,
      "epss_percentile": 0.28227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebLogic Server",
      "cwe": "CWE-269",
      "title": "Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise WebLogic Server. Successful attacks of this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35291"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2025-69118",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "CopyPress",
      "cwe": "CWE-98",
      "title": "WordPress CopyPress theme <= 1.4.5 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69118"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2025-69125",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Food Drop",
      "cwe": "CWE-98",
      "title": "WordPress Food Drop theme <= 1.3 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69125"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2025-69141",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Kelly Young",
      "cwe": "CWE-98",
      "title": "WordPress Kelly Young theme <= 1.1.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69141"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2025-69146",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.28001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Dom",
      "cwe": "CWE-98",
      "title": "WordPress Dom theme <= 1.24 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69146"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2025-69176",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "ITactics",
      "cwe": "CWE-98",
      "title": "WordPress ITactics theme <= 1.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69176"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-8444",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "https://wpreviewslider.com/",
      "product": "WP Review Slider Pro",
      "cwe": "CWE-89",
      "title": "WP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) SQL Injection via 'curselrevs' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8444"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-53853",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-693",
      "title": "OpenClaw < 2026.5.12 - Argument Pattern Bypass in Exec Allowlist via Linux and macOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53853"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-27395",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00345,
      "epss_percentile": 0.27616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Schiocco",
      "product": "Support Board",
      "cwe": "CWE-266",
      "title": "WordPress Support Board plugin < 3.8.9 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27395"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-46899",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00344,
      "epss_percentile": 0.2756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Command Center Framework",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). Supported versions that are affected are V15 and V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Command Center Framework. While the vulnerability is in Oracle Enterprise Command Center Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Command Center Framework accessible data as well as unauthorized access to critical data or complete access to all Oracle Enterprise Command Center Framework accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46899"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-46939",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.2756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Configure to Order",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Configure to Order product of Oracle E-Business Suite (component: Supply to Order Workbench). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Configure to Order. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Configure to Order accessible data as well as unauthorized access to critical data or complete access to all Oracle Configure to Order accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46939"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-0646",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "FLEX I/O EtherNet/IP Adapters",
      "cwe": "CWE-401",
      "title": "Rockwell Automation FLEX I/O Dual-port EtherNet/IP Adapters – Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0646"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-46953",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HRMS (UK)",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle HRMS (UK) product of Oracle E-Business Suite (component: UK Payroll). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HRMS (UK). Successful attacks of this vulnerability can result in takeover of Oracle HRMS (UK). CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46953"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-46976",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Public Sector Payroll",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Public Sector Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Public Sector Payroll. Successful attacks of this vulnerability can result in takeover of Oracle Public Sector Payroll. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46976"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-35305",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00338,
      "epss_percentile": 0.26857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Coherence",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Centralized Third Party Jars). The supported version that is affected is 15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Coherence. While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Coherence accessible data as well as unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35305"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-34893",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebGeniusLab",
      "product": "Thegov Core",
      "cwe": "CWE-98",
      "title": "WordPress Thegov Core plugin < 2.0.23 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34893"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-34895",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebGeniusLab",
      "product": "Softlab Core",
      "cwe": "CWE-98",
      "title": "WordPress Softlab Core plugin < 1.2.11 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34895"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-39547",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Select-Themes",
      "product": "Getaway",
      "cwe": "CWE-98",
      "title": "WordPress Getaway theme < 1.8 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39547"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-46906",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00337,
      "epss_percentile": 0.26774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Tools accessible data as well as unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46906"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-46891",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Accounts Payable",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Accounts Payable product of Oracle JD Edwards (component: Accounts Payable). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Accounts Payable. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Accounts Payable accessible data as well as unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Accounts Payable accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46891"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-46790",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00337,
      "epss_percentile": 0.26752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46790"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-8443",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "https://wpreviewslider.com/",
      "product": "WP Review Slider Pro",
      "cwe": "CWE-89",
      "title": "WP Review Slider Pro <= 12.6.8 - Authenticated (Subscriber+) SQL Injection via 'stypes' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8443"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-48616",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00332,
      "epss_percentile": 0.26223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rocket.Chat",
      "product": "Rocket.Chat",
      "cwe": "CWE-284",
      "title": "Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads at /file-upload/:fileId/:name authorize livechat access using rc_room_type=l with rc_rid+rc_token, but the authorization path does not verify that rc_rid matches the requested file's rid. Furthermore, :fileId is predictable via sequential MongoDB IDs, and :name can be anything, allowing unauthenticated discovery of all uploaded files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48616"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-46808",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46808"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-5149",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.2573,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rometheme",
      "product": "RTMKit",
      "cwe": "CWE-863",
      "title": "RTMKit <= 2.0.7 - Authenticated (Contributor+) Missing Authorization to Arbitrary Form Submission Access via 'entries_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5149"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-46804",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.25529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46804"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-48797",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00324,
      "epss_percentile": 0.25373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcp-tool-shop-org",
      "product": "backpropagate",
      "cwe": "CWE-358",
      "title": "Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48797"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-35271",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PT PeopleTools",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Weblogic). Supported versions that are affected are 8.61 and 8.62. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PT PeopleTools. While the vulnerability is in PeopleSoft Enterprise PT PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PT PeopleTools accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise PT PeopleTools accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35271"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-46806",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-601",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46806"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-48745",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00323,
      "epss_percentile": 0.25168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traccar",
      "product": "traccar-client",
      "cwe": "CWE-940",
      "title": "Traccar Client: silent configuration hijack via unverified deep link redirects all GPS telemetry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48745"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-6964",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.25257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "j_3rk",
      "product": "Video Conferencing with Zoom",
      "cwe": "CWE-862",
      "title": "Video Conferencing with Zoom <= 4.6.7 - Missing Authorization to Unauthenticated Zoom SDK Credential Exposure via 'get_auth' AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6964"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-48782",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.25102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pydantic",
      "product": "pydantic-ai",
      "cwe": "CWE-918",
      "title": "pydantic-ai: SSRF blocklist bypass via IPv4-compatible, SIIT/IVI, and local NAT64 IPv6 addresses (incomplete fix of CVE-2026-46678)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48782"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-40739",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.2488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mikado-Themes",
      "product": "LuxeDrive",
      "cwe": "CWE-502",
      "title": "WordPress LuxeDrive theme <= 1.4 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40739"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-40751",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mikado-Themes",
      "product": "Ashtanga",
      "cwe": "CWE-502",
      "title": "WordPress Ashtanga theme <= 1.2 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40751"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-40758",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.2488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "Léonie",
      "cwe": "CWE-502",
      "title": "WordPress Léonie theme <= 1.2.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40758"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-40759",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mikado-Themes",
      "product": "Esmée",
      "cwe": "CWE-502",
      "title": "WordPress Esmée theme <= 1.4 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40759"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-46915",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Complex Maintenance, Repair and Overhaul",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Production). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. While the vulnerability is in Oracle Complex Maintenance, Repair and Overhaul, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46915"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-7273",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.2435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zyxel",
      "product": "GS1900-48HPv2 firmware",
      "cwe": "CWE-121",
      "title": "A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7273"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-12329",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Memory safety bug fixed in Thunderbird ESR 140.12",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12329"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-49080",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00312,
      "epss_percentile": 0.23972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TMS",
      "product": "wpDataTables",
      "cwe": "CWE-89",
      "title": "WordPress wpDataTables plugin <= 7.3.6 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49080"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-46870",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Shell",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.0+9.6.1. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Shell. While the vulnerability is in MySQL Shell, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of MySQL Shell. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46870"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-35295",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Sites",
      "cwe": "CWE-306",
      "title": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites. Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35295"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-46934",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Complex Maintenance, Repair and Overhaul",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. Successful attacks of this vulnerability can result in takeover of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46934"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-46935",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Complex Maintenance, Repair and Overhaul",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul. Successful attacks of this vulnerability can result in takeover of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46935"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-46957",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iSupplier Portal",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSupplier Portal. Successful attacks of this vulnerability can result in takeover of Oracle iSupplier Portal. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46957"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-46966",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Universal Work Queue",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level Administration). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue. Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46966"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-10828",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0031,
      "epss_percentile": 0.23789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Moxa",
      "product": "NPort W2150A-W4/W2250A-W4 Series",
      "cwe": "CWE-134",
      "title": "A format string vulnerability has been found in the \"alias\" parameter of the Serial Param configuration page in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior. This vulnerability stems from insufficient input validation and improper handling of externally supplied format strings. An attacker could exploit this vulnerability by sending crafted input to the web service, causing unintended memory disclosure. Successful exploitation may allow an attacker to leak sensitive memory contents and determine critical memory addresses, potentially bypassing Address Space Layout Randomization (ASLR) protections.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10828"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-46916",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Process Manufacturing Product Development",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process Manufacturing Product Development. Successful attacks of this vulnerability can result in takeover of Oracle Process Manufacturing Product Development. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46916"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-46928",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Spares Management",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Spares Management. Successful attacks of this vulnerability can result in takeover of Oracle Spares Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46928"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-39443",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PressLayouts",
      "product": "EmallShop",
      "cwe": "CWE-502",
      "title": "WordPress EmallShop theme <= 2.4.21 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39443"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-39446",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PressLayouts",
      "product": "Kapee",
      "cwe": "CWE-502",
      "title": "WordPress Kapee theme < 1.7.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39446"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-39539",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edge-Themes",
      "product": "Alloggio - Hotel Booking",
      "cwe": "CWE-502",
      "title": "WordPress Alloggio - Hotel Booking theme <= 2.1.2 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39539"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-39554",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "Fidalgo",
      "cwe": "CWE-502",
      "title": "WordPress Fidalgo theme <= 1.2.2 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39554"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-39567",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Select-Themes",
      "product": "Santé",
      "cwe": "CWE-502",
      "title": "WordPress Santé theme <= 1.5.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39567"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-10636",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00308,
      "epss_percentile": 0.23533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-416",
      "title": "Use-after-free in Zephyr IPv4 IGMP send path (`igmp_send`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10636"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-46978",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00307,
      "epss_percentile": 0.23444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Solaris",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). The supported version that is affected is 11.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Solaris accessible data as well as unauthorized access to critical data or complete access to all Oracle Solaris accessible data. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46978"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-35314",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Web Server Plugin). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Access Manager accessible data as well as unauthorized read access to a subset of Oracle Access Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Access Manager. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35314"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-12298",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00306,
      "epss_percentile": 0.23287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-125",
      "title": "Memory safety bug fixed in Firefox 152",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12298"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-12299",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00306,
      "epss_percentile": 0.23251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-843",
      "title": "JIT miscompilation in the DOM: Core & HTML component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12299"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-35258",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebLogic Server",
      "cwe": "CWE-601",
      "title": "Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all WebLogic Server accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35258"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-39490",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "artbees",
      "product": "JupiterX Core",
      "cwe": "CWE-862",
      "title": "WordPress JupiterX Core plugin <= 4.14.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39490"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-12293",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00302,
      "epss_percentile": 0.22902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-416",
      "title": "Use-after-free in the Graphics: WebGPU component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12293"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-11317",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "CompactLogix, ControlLogix",
      "cwe": "CWE-404",
      "title": "Rockwell Automation Logix 5370 and 5570 Controllers Vulnerable To Denial of Service Via CIP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11317"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-46893",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00301,
      "epss_percentile": 0.2279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne General Ledger",
      "cwe": "CWE-269",
      "title": "Vulnerability in the JD Edwards EnterpriseOne General Ledger product of Oracle JD Edwards (component: E1 Foundation). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via SMB to compromise JD Edwards EnterpriseOne General Ledger. While the vulnerability is in JD Edwards EnterpriseOne General Ledger, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne General Ledger. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46893"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-46972",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Outsourced Mfg for Discrete Industries",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Outsourced Mfg for Discrete Industries product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Outsourced Mfg for Discrete Industries. Successful attacks of this vulnerability can result in takeover of Oracle Outsourced Mfg for Discrete Industries. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46972"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-35302",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebLogic Server",
      "cwe": "CWE-601",
      "title": "Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of WebLogic Server. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35302"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-10637",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00299,
      "epss_percentile": 0.2257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-416",
      "title": "Use-after-free of `net_pkt` in IPv6 MLD send path triggerable by a link-local MLD Query",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10637"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2025-69137",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.22591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jthemes",
      "product": "Genemy",
      "cwe": "CWE-862",
      "title": "WordPress Genemy theme <= 1.6.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69137"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-12105",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00298,
      "epss_percentile": 0.2249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Devolutions Server",
      "cwe": "CWE-862",
      "title": "Improper access control in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to access attachments via folder duplication with inherited permissions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12105"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-9307",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00298,
      "epss_percentile": 0.22448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "CompactLogix 5370",
      "cwe": "CWE-497",
      "title": "Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9307"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-10748",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonatype",
      "product": "Nexus Repository",
      "cwe": "CWE-502",
      "title": "Nexus Repository 3 - Remote Code Execution via License Deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10748"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-49057",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EyeCix Technologies",
      "product": "JobSearch",
      "cwe": "CWE-862",
      "title": "WordPress JobSearch plugin <= 3.2.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49057"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-46979",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.21984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise CS Campus Community",
      "cwe": "CWE-284",
      "title": "Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and Interfaces). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Campus Community accessible data as well as unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46979"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-10831",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Moxa",
      "product": "NPort 6000 Series",
      "cwe": "CWE-862",
      "title": "Improper Authorization of Break Signal Commands in Devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10831"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-46920",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications. Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46920"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2025-13036",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0029,
      "epss_percentile": 0.21532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "FactoryTalk Historian SE",
      "cwe": "CWE-362",
      "title": "Rockwell Automation FactoryTalk Historian Site Edition - Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13036"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-12317",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Memory safety bug fixed in Firefox 152",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12317"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-0132",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.21106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-122",
      "title": "In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0132"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-0149",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.21105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-122",
      "title": "In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0149"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-12348",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Browser Company of New York`",
      "product": "Arc Search",
      "cwe": "CWE-1021",
      "title": "Address Bar Spoofing in Arc Search for Android (window.open race condition)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12348"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-46872",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00282,
      "epss_percentile": 0.20802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Install). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46872"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-49774",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0028,
      "epss_percentile": 0.20509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Filipe Nasc",
      "product": "RD Station",
      "cwe": "CWE-94",
      "title": "WordPress RD Station plugin <= 5.6.0 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49774"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-39581",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "activity-log.com",
      "product": "WP Sessions Time Monitoring Full Automatic",
      "cwe": "CWE-89",
      "title": "WordPress WP Sessions Time Monitoring Full Automatic plugin <= 1.1.4 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39581"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-0126",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00277,
      "epss_percentile": 0.20205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-787",
      "title": "In WC-Radio, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0126"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-0139",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.20206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-119",
      "title": "In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0139"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-0146",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.20205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-120",
      "title": "In mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0146"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-0147",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.20205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-120",
      "title": "In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0147"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-0148",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.20204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-190",
      "title": "In multiple functions of VideoRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0148"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-53843",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.19986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-613",
      "title": "OpenClaw < 2026.5.26 - Node Token Revocation Bypass via Pairing-Scoped Device Session",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53843"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-40750",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00273,
      "epss_percentile": 0.19803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themagnifico52",
      "product": "Kids Online Store",
      "cwe": "CWE-434",
      "title": "WordPress Kids Online Store theme <= 0.8.9 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40750"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-54197",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.19781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wpmet",
      "product": "GetGenie",
      "cwe": "CWE-201",
      "title": "WordPress GetGenie plugin <= 4.4.1 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54197"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-46448",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Nova",
      "cwe": "CWE-669",
      "title": "In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46448"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-35261",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-287",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Access Manager accessible data as well as unauthorized read access to a subset of Oracle Access Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35261"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-46810",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Identity Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: End User Self Service). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Identity Manager. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Identity Manager accessible data as well as unauthorized read access to a subset of Identity Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46810"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-53866",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.1937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-862",
      "title": "OpenClaw < 2026.5.12 - Allowlist Bypass in Shell Inline-Command Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53866"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-35327",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35327"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-39578",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "Valiance",
      "cwe": "CWE-502",
      "title": "WordPress Valiance theme <= 1.2 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39578"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-46911",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00267,
      "epss_percentile": 0.18923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Project Costing",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Project Costing product of Oracle JD Edwards (component: Job Costing). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via JDENET to compromise JD Edwards EnterpriseOne Project Costing. While the vulnerability is in JD Edwards EnterpriseOne Project Costing, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all JD Edwards EnterpriseOne Project Costing accessible data as well as unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Project Costing accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46911"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-46912",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00267,
      "epss_percentile": 0.18954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": "CWE-200",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Web Runtime Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all JD Edwards EnterpriseOne Tools accessible data as well as unauthorized update, insert or delete access to some of JD Edwards EnterpriseOne Tools accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46912"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-53849",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-290",
      "title": "OpenClaw < 2026.5.7 - Privilege Escalation via Mutable Discord Display Names in allowFrom",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53849"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-46925",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.1856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 17.0-26.5. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46925"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-12318",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Incorrect boundary conditions in the Libraries component in NSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12318"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-46871",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Shell",
      "cwe": "CWE-284",
      "title": "Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is affected is 2026.2.0+9.6.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Shell. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Shell accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46871"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-12306",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Memory safety bug fixed in Firefox 152",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12306"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-12307",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Memory safety bug fixed in Firefox 152",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12307"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-12308",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Memory safety bug fixed in Firefox 152",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12308"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-12117",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Devolutions Server",
      "cwe": "CWE-200",
      "title": "Improper access control in the social login connection endpoint in Devolutions Server 2026.2.5 allows an authenticated vault member to enumerate social login entry metadata to which they are not authorized via a crafted API request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12117"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-53855",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-184",
      "title": "OpenClaw < 2026.4.2 - Shell Positional Parameters Bypass in Inline-Eval Checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53855"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-54190",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Awesomemotive",
      "product": "Envira Photo Gallery",
      "cwe": "CWE-862",
      "title": "WordPress Envira Photo Gallery plugin <= 1.12.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54190"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-0127",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-125",
      "title": "In NrmmMsgCodec::DecodeUPUTransparentContext of cn_NrmmDecoder.cpp, there is a possible out-of-bounds read due to memory corruption. This could lead to remote denial of service causing a communication processor crash with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0127"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-0136",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-120",
      "title": "In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0136"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-0144",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-120",
      "title": "In writeAocCommand of AocAudioCodec.cpp, there is a possible memory safety issue due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0144"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-12310",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.1687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Memory safety bug fixed in Firefox 152",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12310"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-12312",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.1687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Memory safety bug fixed in Firefox 152",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12312"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-12314",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.1687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Memory safety bug fixed in Firefox 152",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12314"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-12300",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Memory safety bug fixed in Firefox 152",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12300"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-12301",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Memory safety bug fixed in Firefox 152",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12301"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-12315",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00251,
      "epss_percentile": 0.1679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "title": "Mitigation bypass in the DOM: Security component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12315"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-39580",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Select-Themes",
      "product": "Micdrop",
      "cwe": "CWE-502",
      "title": "WordPress Micdrop theme <= 1.3.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39580"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-40736",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edge-Themes",
      "product": "Laurits",
      "cwe": "CWE-502",
      "title": "WordPress Laurits theme <= 1.5.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40736"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-40754",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "Roisin",
      "cwe": "CWE-502",
      "title": "WordPress Roisin theme <= 1.4 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40754"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-40755",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mikado-Themes",
      "product": "TechLink",
      "cwe": "CWE-502",
      "title": "WordPress TechLink theme <= 1.3 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40755"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-40760",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edge-Themes",
      "product": "Behold",
      "cwe": "CWE-502",
      "title": "WordPress Behold theme <= 1.5 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40760"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-40761",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edge-Themes",
      "product": "Valeska",
      "cwe": "CWE-502",
      "title": "WordPress Valeska theme <= 1.2.2 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40761"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-53861",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-184",
      "title": "OpenClaw < 2026.5.6 - Allowlist Bypass via Combined POSIX Inline Flags on macOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53861"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-12302",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.16391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "title": "Mitigation bypass in the DOM: Security component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12302"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-48788",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "umputun",
      "product": "remark42",
      "cwe": "CWE-79",
      "title": "Remark42: Cross-Site Scripting (XSS) on /api/v1/img via content-type spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48788"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-46958",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Subledger Accounting",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Subledger Accounting. Successful attacks of this vulnerability can result in takeover of Oracle Subledger Accounting. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46958"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-46959",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Subledger Accounting",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Subledger Accounting product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Subledger Accounting. Successful attacks of this vulnerability can result in takeover of Oracle Subledger Accounting. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46959"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-46971",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle HR Intelligence",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HR Intelligence. Successful attacks of this vulnerability can result in takeover of Oracle HR Intelligence. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46971"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-1767",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-805",
      "title": "Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer overflow leading to denial of service or information disclosure via malformed mp3 id3 tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1767"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-53864",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.1615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-184",
      "title": "OpenClaw < 2026.5.26 - Insufficient Environment Variable Sanitization in Node.js Control Variables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53864"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-12316",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00245,
      "epss_percentile": 0.1609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-693",
      "title": "Mitigation bypass in the DOM: Security component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12316"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-46812",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.16021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Access Manager",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Access Manager accessible data as well as unauthorized read access to a subset of Oracle Access Manager accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46812"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-53854",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.16065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw < 2026.4.25 - Privilege Escalation via ownerAllowFrom Wildcard Inheritance in Internal/Webchat Commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53854"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-52715",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00243,
      "epss_percentile": 0.15715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eyal Fitoussi",
      "product": "GEO my WordPress",
      "cwe": "CWE-89",
      "title": "WordPress GEO my WordPress plugin <= 4.5.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52715"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-10825",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Moxa",
      "product": "NPort 6000-G2 Series",
      "cwe": "CWE-1287",
      "title": "Improper JSON Input Validation in WebSocket API Leads to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10825"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2025-69104",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jkdevstudio",
      "product": "Qreatix",
      "cwe": "CWE-79",
      "title": "WordPress Qreatix theme <= 1.9.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69104"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2025-14272",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "FactoryTalk Analytics PavilionX",
      "cwe": "CWE-862",
      "title": "Rockwell Automation FactoryTalk Analytics PavilionX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14272"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-12309",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14693,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Memory safety bug fixed in Firefox 152",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12309"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-39574",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.14612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RealMag777",
      "product": "InPost Gallery",
      "cwe": "CWE-89",
      "title": "WordPress InPost Gallery plugin <= 2.1.4.6 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39574"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-11890",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Devolutions Server",
      "cwe": "CWE-882",
      "title": "Improper access control in PAM account discovery results in Devolutions Server 2026.2.5, 2026.1.21 allows an authenticated user to retrieve account discovery scan results.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11890"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-22312",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Radiflow",
      "product": "iSAP Smart Collector",
      "cwe": "CWE-798",
      "title": "Use of Hard-coded Credentials Vulnerability in Radiflow iSAP Smart Collector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22312"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-48775",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langchain-ai",
      "product": "langgraph",
      "cwe": "CWE-502",
      "title": "LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48775"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-10639",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-416",
      "title": "Use-after-free reading `net_pkt_iface()` of a sent ICMPv4 echo-reply packet in `icmpv4_handle_echo_request()`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10639"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-0151",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-190",
      "title": "In IntfGraphCreate of intfgraph.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0151"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-0154",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-120",
      "title": "In Modem, there is a possible way to trigger a modem crash during a SIP REFER request due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0154"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-0160",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-120",
      "title": "In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0160"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-0161",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-190",
      "title": "In numberOfReportBlocks of RtpSession.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0161"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-0162",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-843",
      "title": "In ParsePayloads of AudioSdpParser.cpp, there is a possible memory corruption due to type confusion. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0162"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-0164",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-120",
      "title": "In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0164"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-46770",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Development Framework (ADF)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Development Framework (ADF). Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Development Framework (ADF), attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Development Framework (ADF) accessible data as well as unauthorized read access to a subset of Oracle Application Development Framework (ADF) accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46770"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-52712",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tnomi",
      "product": "Attendance Manager",
      "cwe": "CWE-89",
      "title": "WordPress Attendance Manager plugin <= 0.6.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52712"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-10093",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deepakkite",
      "product": "Secure Client Portal and Private File Sharing Plugin – User Private Files",
      "cwe": "CWE-79",
      "title": "File Sharing & Download Manager <= 2.1.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'fldr_ttl' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10093"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-9187",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zealopensource",
      "product": "Abandoned Contact Form 7",
      "cwe": "CWE-862",
      "title": "Abandoned Contact Form 7 <= 2.2 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'recover_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9187"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-12325",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-400",
      "title": "Denial-of-service in the Graphics: ImageLib component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12325"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-53857",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-290",
      "title": "OpenClaw < 2026.5.3 - Mutable Display Name Binding in Zalo allowFrom Policy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53857"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2025-68045",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arraytics",
      "product": "WP Event SOlution",
      "cwe": "CWE-862",
      "title": "WordPress WP Event SOlution plugin <= 4.1.12 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68045"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-52711",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kilbot",
      "product": "WooCommerce POS",
      "cwe": "CWE-862",
      "title": "WordPress WooCommerce POS plugin <= 1.8.14 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52711"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-44587",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "carrierwaveuploader",
      "product": "carrierwave",
      "cwe": "CWE-79",
      "title": "CarrierWave has a denylisted_content_type bypass via Unescaped Regex Metacharacters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44587"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-53840",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.1321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-522",
      "title": "OpenClaw < 2026.5.12 - Custom Header Leakage via MCP Streamable HTTP Cross-Origin Redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53840"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-47684",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.12991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sync-in",
      "product": "server",
      "cwe": "CWE-918",
      "title": "Sync-in Server: SSRF protection bypass via IPv4-mapped IPv6 addresses in regExpPrivateIP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47684"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-12303",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-125",
      "title": "Information disclosure due to incorrect boundary conditions in the Graphics: WebGPU component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12303"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-39598",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kodezen LLC",
      "product": "Academy LMS Pro",
      "cwe": "CWE-434",
      "title": "WordPress Academy LMS Pro plugin < 3.5.2 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39598"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-48780",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.12563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "forem",
      "product": "forem",
      "cwe": "CWE-287",
      "title": "Forem vulnerable to bypass of email address domain restrictions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48780"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-48776",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00216,
      "epss_percentile": 0.12367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langchain-ai",
      "product": "langchain-ai",
      "cwe": "CWE-22",
      "title": "LangGraph SDK has unsafe URL path construction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48776"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-46786",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00212,
      "epss_percentile": 0.11779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-352",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46786"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-0156",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-476",
      "title": "In checkSsrcCollisionOnRcv of RtpSession.cpp, there is a possible memory safety issue due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0156"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-12319",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-400",
      "title": "Denial-of-service in the Audio/Video: Playback component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12319"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-53844",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-862",
      "title": "OpenClaw < 2026.4.29 - Session Visibility Check Bypass in Shared Memory Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53844"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-53859",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-918",
      "title": "OpenClaw < 2026.5.26 - Hostname Validation Bypass via Trailing-Dot Inconsistency",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53859"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-48781",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00209,
      "epss_percentile": 0.11394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitroomhq",
      "product": "postiz-app",
      "cwe": "CWE-302",
      "title": "Postiz has cross-tenant SUPERADMIN takeover via Skool-provider JWT forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48781"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-12324",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.11348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-703",
      "title": "Incorrect boundary conditions in the Graphics: CanvasWebGL component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12324"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-1764",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Localsearch: tracker-miners: gnome localsearch mp3 extractor: heap buffer overflow leads to denial of service or information disclosure when parsing mp3 files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1764"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2025-71261",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00208,
      "epss_percentile": 0.11265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Harvester",
      "cwe": "CWE-295",
      "title": "Harvester's SUSE Virtualization Registration Client Vulnerable to MITM and DOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71261"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-12322",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-1021",
      "title": "Clickjacking issue in the Widget: Gtk component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12322"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-47964",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.10995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "DNG SDK",
      "cwe": "CWE-122",
      "title": "DNG SDK | Heap-based Buffer Overflow (CWE-122)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47964"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-53852",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00206,
      "epss_percentile": 0.11017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-636",
      "title": "OpenClaw < 2026.4.25 - Scope Bypass via Empty-Scope Device Re-pairing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53852"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-49073",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpWax",
      "product": "Directorist Booking",
      "cwe": "CWE-89",
      "title": "WordPress Directorist Booking plugin <= 3.0.3 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49073"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-39577",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "Playroom",
      "cwe": "CWE-502",
      "title": "WordPress Playroom theme <= 1.4.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39577"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-10780",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mohammadtanzilurrahman",
      "product": "Static Block",
      "cwe": "CWE-639",
      "title": "Static Block <= 2.2 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Disclosure via Shortcode 'id' Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10780"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-47749",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "leejet",
      "product": "stable-diffusion.cpp",
      "cwe": "CWE-122",
      "title": "stable-diffusion.cpp: Heap buffer overflow in SHORT_BINUNICODE parsing for PyTorch checkpoint files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47749"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-35272",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.002,
      "epss_percentile": 0.10254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PT PeopleTools",
      "cwe": "CWE-269",
      "title": "Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise PT PeopleTools executes to compromise PeopleSoft Enterprise PT PeopleTools. Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Score 8.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35272"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-0141",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-120",
      "title": "In decodeAppPacket of RtcpAppPacket.cpp, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0141"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2024-30476",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerStore",
      "cwe": "CWE-79",
      "title": "PowerStore contains a Stored Cross-Site Scripting Vulnerability in the PowerStore Manager. A remote authenticated low-privileged malicious actor could potentially exploit this vulnerability, it could lead to script execution in the client browser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-30476"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-54191",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pods Framework",
      "product": "Pods",
      "cwe": "CWE-79",
      "title": "WordPress Pods plugin <= 3.3.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54191"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-54198",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "David Lingren",
      "product": "Media LIbrary Assistant",
      "cwe": "CWE-79",
      "title": "WordPress Media LIbrary Assistant plugin <= 3.35 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54198"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-46785",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00196,
      "epss_percentile": 0.09755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-352",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46785"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-40809",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rara Themes",
      "product": "Metro Magazine",
      "cwe": "CWE-862",
      "title": "WordPress Metro Magazine theme <= 1.4.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40809"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-24155",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00193,
      "epss_percentile": 0.09398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "NeMo Framework",
      "cwe": "CWE-94",
      "title": "NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24155"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-53851",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-862",
      "title": "OpenClaw < 2026.5.12 - Slack Reaction Event Notification Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53851"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-12304",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00189,
      "epss_percentile": 0.08925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-346",
      "title": "Same-origin policy bypass in the Networking: Cookies component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12304"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-2604",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "Evolution Data Server",
      "cwe": "CWE-73",
      "title": "Evolution-data-server: evolution data server: arbitrary file deletion via inconsistent uri handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2604"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-35288",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.0872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "PeopleSoft Enterprise PT PeopleTools",
      "cwe": "CWE-269",
      "title": "Vulnerability in the PeopleSoft Enterprise PT PeopleTools product of Oracle PeopleSoft (component: Deployment Package). Supported versions that are affected are 8.61 and 8.62. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PT PeopleTools executes to compromise PeopleSoft Enterprise PT PeopleTools. While the vulnerability is in PeopleSoft Enterprise PT PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PT PeopleTools. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35288"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-53841",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00188,
      "epss_percentile": 0.08777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-83",
      "title": "OpenClaw < 2026.5.12 - Cross-Site Scripting via Unsafe Markdown Links in Exported Session HTML",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53841"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-48869",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kriesi",
      "product": "Enfold",
      "cwe": "CWE-79",
      "title": "WordPress Enfold theme <= 7.1.4 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48869"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-12311",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-200",
      "title": "Information disclosure, sandbox escape in the Security: Process Sandboxing component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12311"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-53845",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00185,
      "epss_percentile": 0.08371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-693",
      "title": "OpenClaw < 2026.5.6 - Skill-Command Dispatch Hook Bypass via Before-Tool-Call Hook Skipping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53845"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-53848",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00185,
      "epss_percentile": 0.08387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-184",
      "title": "OpenClaw < 2026.5.26 - Exec Allowlist Bypass via Transparent Command Wrappers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53848"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-0128",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-190",
      "title": "In RtcpFbPacket::decodeRtcpFbPacket, there is a possible out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0128"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-47747",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "leejet",
      "product": "stable-diffusion.cpp",
      "cwe": "CWE-122",
      "title": "stable-diffusion.cpp has a Heap-based Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47747"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-47750",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "leejet",
      "product": "stable-diffusion.cpp",
      "cwe": "CWE-787",
      "title": "stable-diffusion.cpp: Heap buffer overflow in GLOBAL opcode parsing for PyTorch checkpoint files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47750"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2025-69151",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeGoods",
      "product": "Grand Car Rental",
      "cwe": "CWE-79",
      "title": "WordPress Grand Car Rental theme <= 3.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69151"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-46869",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "MySQL Shell",
      "cwe": "CWE-352",
      "title": "Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Dump and Load). Supported versions that are affected are 8.4.0-8.4.9 and 9.0.0-9.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Shell. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Shell accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46869"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-12320",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-200",
      "title": "Information disclosure in the Password Manager component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12320"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-0140",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-125",
      "title": "In RtpPacket::decodePacket, there is a possible out-of-bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0140"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-53847",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-266",
      "title": "OpenClaw < 2026.5.6 - Privilege Escalation via Active Memory Write Scope",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53847"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-39548",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sneeit",
      "product": "MagOne",
      "cwe": "CWE-79",
      "title": "WordPress MagOne theme <= 9.0 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39548"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-12313",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-269",
      "title": "Information disclosure, sandbox escape in the Security: Process Sandboxing component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12313"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-0130",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00173,
      "epss_percentile": 0.07109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-122",
      "title": "In RtcpChunk::decodeRtcpChunk, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0130"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-42089",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.07002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yeoman",
      "product": "environment",
      "cwe": "CWE-829",
      "title": "yeoman-environment Vulnerable to Arbitrary Package Installation without User Confirmation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42089"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-52714",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SEO Squirrly",
      "product": "SEO Plugin by Squirrly SEO",
      "cwe": "CWE-862",
      "title": "WordPress SEO Plugin by Squirrly SEO plugin <= 12.4.16 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52714"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-0165",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-120",
      "title": "In several functions of the RTCP packet decoder, there is a possible out-of-bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0165"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-53860",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00171,
      "epss_percentile": 0.06875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-807",
      "title": "OpenClaw < 2026.5.7 - Sender Policy Bypass via Mutable Conversation Identifiers in BlueBubbles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53860"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2025-11694",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rockwell Automation",
      "product": "CompactLogix 5370",
      "cwe": "CWE-354",
      "title": "Rockwell Automation CompactLogix 5370 Controllers – Multiple Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-11694"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-48783",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitroomhq",
      "product": "postiz-app",
      "cwe": "CWE-345",
      "title": "Postiz has an unauthenticated billing-enforcement bypass via /public/modify-subscription",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48783"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-53863",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-639",
      "title": "OpenClaw < 2026.4.25 - Unvalidated Group ID Acceptance in Tool Group Policy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53863"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-0155",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-120",
      "title": "In ImsMediaBitReader::ReadByteBuffer, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0155"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-0157",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-120",
      "title": "In RtcpHeader::decodeRtcpHeader, there is a possible OOB read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0157"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-46865",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00168,
      "epss_percentile": 0.06629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Enterprise Manager Base Platform",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Extensibility Framework). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Enterprise Manager Base Platform executes to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46865"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-46894",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00168,
      "epss_percentile": 0.06558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle iSupplier Portal",
      "cwe": "CWE-352",
      "title": "Vulnerability in the Oracle iSupplier Portal product of Oracle E-Business Suite (component: Home Page). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle iSupplier Portal. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle iSupplier Portal. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46894"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-12323",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.0658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-1021",
      "title": "Spoofing issue in the DOM: Core & HTML component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12323"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-0129",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00168,
      "epss_percentile": 0.06611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-120",
      "title": "In RtcpByePacket::decodeByePacket, there is a possible due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0129"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-46877",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46877"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-47927",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "DNG SDK",
      "cwe": "CWE-125",
      "title": "DNG SDK | Out-of-bounds Read (CWE-125)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47927"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-47934",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.0625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "DNG SDK",
      "cwe": "CWE-125",
      "title": "DNG SDK | Out-of-bounds Read (CWE-125)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47934"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-47963",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.0625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "DNG SDK",
      "cwe": "CWE-125",
      "title": "DNG SDK | Out-of-bounds Read (CWE-125)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47963"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-10635",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-416",
      "title": "Dangling memory-domain pointer (use-after-free) in Xtensa MMU page-table code on memory-domain de-init",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10635"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-12330",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-119",
      "title": "Incorrect boundary conditions in the Internationalization component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12330"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-47748",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.06036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "leejet",
      "product": "stable-diffusion.cpp",
      "cwe": "CWE-125",
      "title": "stable-diffusion.cpp: Out-of-bounds reads in PyTorch checkpoint pickle opcode parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47748"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-46815",
      "cvss_base": 3.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00162,
      "epss_percentile": 0.05892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46815"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-46816",
      "cvss_base": 3.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00162,
      "epss_percentile": 0.05892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46816"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-46977",
      "cvss_base": 3.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00162,
      "epss_percentile": 0.05892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46977"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-24228",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00161,
      "epss_percentile": 0.0583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "NeMo Framework",
      "cwe": "CWE-502",
      "title": "NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24228"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-46787",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle WebCenter Content",
      "cwe": "CWE-352",
      "title": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). The supported version that is affected is 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Content accessible data as well as unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data. CVSS 3.1 Base Score 8.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46787"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-46825",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46825"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-12321",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-670",
      "title": "JIT miscompilation in the JavaScript: WebAssembly component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12321"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-1766",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-805",
      "title": "Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of service and information disclosure via malformed mp3 files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1766"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-46955",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.05319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Human Resources",
      "cwe": "CWE-79",
      "title": "Vulnerability in the Oracle Human Resources product of Oracle E-Business Suite (component: Person). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Human Resources. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Human Resources. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46955"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-46914",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.05095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Solaris",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Solaris accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46914"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-42014",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.04728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-825",
      "title": "Gnutls: gnutls: use-after-free in gnutls_pkcs11_token_set_pin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42014"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-46768",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.04745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46768"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-12425",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerSchool",
      "product": "Employee Access Center",
      "cwe": "CWE-79",
      "title": "Reflected / DOM cross-site scripting (XSS) in PowerSchool ERP / Employee Access Center 23.10",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12425"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-35275",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00147,
      "epss_percentile": 0.04483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Shared Folders). The supported version that is affected is 7.2.8. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data as well as unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35275"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-12003",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Software Foundation",
      "product": "CPython",
      "cwe": "CWE-427",
      "title": "CPython >3.11 Insecure Input Validation resulting in privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12003"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-39437",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.0399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPFactory",
      "product": "Min Max Step Quantity Limits Manager for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Min Max Step Quantity Limits Manager for WooCommerce plugin <= 5.2.2 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39437"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-46848",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00141,
      "epss_percentile": 0.03961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "WebLogic Server",
      "cwe": "CWE-284",
      "title": "Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected are 14.1.2.0.0 and 15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where WebLogic Server executes to compromise WebLogic Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in WebLogic Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all WebLogic Server accessible data as well as unauthorized access to critical data or complete access to all WebLogic Server accessible data. CVSS 3.1 Base Score 7.9 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46848"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-46913",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0014,
      "epss_percentile": 0.03878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "JD Edwards EnterpriseOne Tools",
      "cwe": "CWE-284",
      "title": "Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). Supported versions that are affected are 9.2.0.0-9.2.26.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where JD Edwards EnterpriseOne Tools executes to compromise JD Edwards EnterpriseOne Tools. While the vulnerability is in JD Edwards EnterpriseOne Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of JD Edwards EnterpriseOne Tools. CVSS 3.1 Base Score 9.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46913"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-46974",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.0387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.8. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46974"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-8484",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FuseSource",
      "product": "jansi",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in Jansi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8484"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-1765",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Localsearch: tracker-miners: gnome localsearch mp3 extractor: denial of service and potential information disclosure via crafted mp3 files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1765"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-46771",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.0341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Development Framework (ADF)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: Java Business Objects). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Application Development Framework (ADF) executes to compromise Oracle Application Development Framework (ADF). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Development Framework (ADF) accessible data. CVSS 3.1 Base Score 4.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46771"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-53842",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.03287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-426",
      "title": "OpenClaw < 2026.5.2 - Arbitrary Python Runtime Execution via CLOUDSDK_PYTHON Environment Variable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53842"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-46772",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Application Development Framework (ADF)",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Application Development Framework (ADF) executes to compromise Oracle Application Development Framework (ADF). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Application Development Framework (ADF) accessible data as well as unauthorized update, insert or delete access to some of Oracle Application Development Framework (ADF) accessible data. CVSS 3.1 Base Score 4.7 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46772"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-4367",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.0296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-125",
      "title": "Libxpm: libxpm: denial of service via out-of-bounds read in xpm file parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4367"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-46874",
      "cvss_base": 3.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00129,
      "epss_percentile": 0.02983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46874"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-53858",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-426",
      "title": "OpenClaw < 2026.5.2 - Arbitrary Runtime Dependency Loading via STATE_DIRECTORY Environment Variable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53858"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-53865",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00123,
      "epss_percentile": 0.02503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-426",
      "title": "OpenClaw < 2026.5.2 - Arbitrary Command Execution via Workspace-Derived Service PATH",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53865"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-46926",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Cloud Applications",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications. While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46926"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-46888",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Siebel CRM Deployment",
      "cwe": "CWE-284",
      "title": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Database Upgrade). Supported versions that are affected are 17.0-26.5. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM Deployment. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46888"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-53846",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.02008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-426",
      "title": "OpenClaw < 2026.4.29 - Arbitrary Package Manager Execution via Workspace .env npm_execpath",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53846"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2025-10262",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nokia",
      "product": "SR Linux",
      "cwe": "CWE-134",
      "title": "An unsanitized format validation vulnerability in Nokia SR Linux",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-10262"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-46873",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00114,
      "epss_percentile": 0.01726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle VM VirtualBox",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported version that is affected is 7.2.8. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46873"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2025-9912",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0011,
      "epss_percentile": 0.01476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nokia",
      "product": "Nokia SR Linux",
      "cwe": "CWE-269",
      "title": "A local privilege escalation vulnerability in Nokia SR Linux",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-9912"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-0135",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00103,
      "epss_percentile": 0.01132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-125",
      "title": "In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0135"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-53900",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.0096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox for iOS",
      "cwe": "CWE-345",
      "title": "Cookie injection was possible when opening a PDF link",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53900"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2024-22451",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00099,
      "epss_percentile": 0.0093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Peripheral Manager",
      "cwe": "CWE-427",
      "title": "Dell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious executable, leading to arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-22451"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2024-22447",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00098,
      "epss_percentile": 0.00866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Peripheral Manager",
      "cwe": "CWE-427",
      "title": "Dell Peripheral Manager, versions prior to 1.7.3, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious dll., leading to arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-22447"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2024-39575",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00096,
      "epss_percentile": 0.00793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Dell EMC VxRail Appliance",
      "cwe": "CWE-256",
      "title": "update_disk_psu_baseline.sh requires password in plain text",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-39575"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-53899",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00096,
      "epss_percentile": 0.00814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox for iOS",
      "cwe": "CWE-345",
      "title": "Cross-origin cookies could be leaked when opening a PDF link",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53899"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-53856",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.00702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-732",
      "title": "OpenClaw 2026.4.23 < 2026.4.24 - Insecure File Permissions in Config Recovery via OpenClaw.json",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53856"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-53850",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-862",
      "title": "OpenClaw < 2026.4.25 - Control Scope Enforcement Bypass in Focus Command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53850"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-50255",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00089,
      "epss_percentile": 0.00488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sony Corporation",
      "product": "Optical Disc Archive Software for Windows",
      "cwe": "CWE-276",
      "title": "Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulnerability is exploited, arbitrary code may be executed with SYSTEM privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50255"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-53862",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00088,
      "epss_percentile": 0.00452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-266",
      "title": "OpenClaw < 2026.5.12 - Bootstrap Token Replay via Pending Pairing Scope Widening",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53862"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2024-38487",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00081,
      "epss_percentile": 0.00221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "EMC VxRail Appliance",
      "cwe": "CWE-269",
      "title": "api-gateway container running with root privilege would allow an attacker to escape the container and access host system to perform unintended actions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-38487"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-0137",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00073,
      "epss_percentile": 0.00079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-416",
      "title": "In edgetpu_sync_fence_group_shutdown() of edgetpu-dmabuf.c, there is a possible elevation of privilege due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0137"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-0138",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00073,
      "epss_percentile": 0.00079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-120",
      "title": "In lwis_io_buffer_write of lwis_io_buffer.c, there is a possible out of bounds write due to memory corruption. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0138"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-0143",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00073,
      "epss_percentile": 0.00076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-416",
      "title": "In lwis_device_external_event_emit of lwis_event.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0143"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-0131",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00072,
      "epss_percentile": 0.00066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-125",
      "title": "In RtpPacket::decodePacket, there is a possible out of bounds access due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0131"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-0134",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00072,
      "epss_percentile": 0.00063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-1188",
      "title": "In PostWipeData of recovery_ui.cpp, there is a possible data persistence issue after a factory reset due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0134"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-0152",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00071,
      "epss_percentile": 0.00057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-119",
      "title": "In OSMMapPMRGeneric of pmr_os.c, there is a possible way to leverage a system call to system call to maliciously expand the VMA out of bounds due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0152"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-0142",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00069,
      "epss_percentile": 0.00038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-20",
      "title": "In iavb_parse_key_data of avb_rsa.c, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0142"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-0153",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00068,
      "epss_percentile": 0.00035,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-787",
      "title": "In Write of msg_to_host_buffer.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0153"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-0145",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00068,
      "epss_percentile": 0.00036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-862",
      "title": "In keymint, there is a possible Permission Bypass due to a logic error in the code. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0145"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-0133",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00067,
      "epss_percentile": 0.00031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-862",
      "title": "In smmu_attach_dev of arm-smmu-v3.c, there is a possible way to sign malicious Android Runtime bootclass artifacts due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0133"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-0150",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00067,
      "epss_percentile": 0.00029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-190",
      "title": "In ExecuteGraph command handler of EdgeTPU firmware, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with root privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0150"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-0125",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00067,
      "epss_percentile": 0.0003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-416",
      "title": "In multiple functions of vpu_ioctl.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0125"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-0158",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0006,
      "epss_percentile": 0.0001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-862",
      "title": "In Camera, there is a possible unauthorized way to access photos due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0158"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10635",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10635 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10636",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10636 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10637",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10637 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10639",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10639 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10640",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10640 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-1764",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-1764 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-1766",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-1766 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-1767",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-1767 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44587",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44587 (carrierwaveuploader carrierwave). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46448",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46448 (OpenStack Nova). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47747",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47747 (leejet stable-diffusion.cpp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47748",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47748 (leejet stable-diffusion.cpp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47749",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47749 (leejet stable-diffusion.cpp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47750",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47750 (leejet stable-diffusion.cpp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48779",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48779 (websockets ws). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-35273",
      "detail": "DUE DATE PASSED — CVE-2026-35273 (Oracle Corporation PeopleSoft Enterprise PeopleTools). CISA remediation deadline was June 15, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
