{
  "day": "2026-06-17",
  "boundary": "UTC calendar day",
  "published_count": 396,
  "by_severity": {
    "CRITICAL": 90,
    "HIGH": 196,
    "MEDIUM": 101,
    "LOW": 9
  },
  "kev_count": 0,
  "exploit_reference_count": 7,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-42055",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.04022,
      "epss_percentile": 0.89749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "NGINX Open Source",
      "cwe": "CWE-787",
      "title": "NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42055"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-42530",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.03677,
      "epss_percentile": 0.8877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "NGINX Open Source",
      "cwe": "CWE-416",
      "title": "NGINX Open-Source ngx_http_v3_module vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42530"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-55200",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02027,
      "epss_percentile": 0.79455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libssh2",
      "product": "libssh2",
      "cwe": "CWE-680",
      "title": "libssh2 - Out-of-Bounds Write via Unchecked packet_length in transport.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55200"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-53876",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01786,
      "epss_percentile": 0.7654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Micro-Star International Co., Ltd.",
      "product": "RadiX AX6600 WiFi 6 Tri-Band Gaming Router",
      "cwe": "CWE-78",
      "title": "RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary command execution with the root privilege by a user who logs in to the web console as an administrator.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53876"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-47103",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01173,
      "epss_percentile": 0.64982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fgmacedo",
      "product": "python-statemachine",
      "cwe": "CWE-94",
      "title": "Python StateMachine 3.0.0 < 3.2.0 RCE via SCXML eval() Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47103"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-47774",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00967,
      "epss_percentile": 0.58984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-405",
      "title": "Envoy vulnerable to HTTP/2 memory exhaustion via cookie header size bypass and HPACK amplification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47774"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-55199",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00918,
      "epss_percentile": 0.57455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libssh2",
      "product": "libssh2",
      "cwe": "CWE-835",
      "title": "libssh2 - Pre-Authentication DoS via SSH_MSG_EXT_INFO Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55199"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-53805",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00872,
      "epss_percentile": 0.56071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nv-tlabs",
      "product": "GEN3C",
      "cwe": "CWE-502",
      "title": "NVIDIA SIL GEN3C Unauthenticated RCE via Pickle Deserialization in Inference API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53805"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-12151",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00789,
      "epss_percentile": 0.534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-400",
      "title": "undici WebSocket client vulnerable to denial of service via fragment count bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12151"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2025-71323",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00758,
      "epss_percentile": 0.5239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-184",
      "title": "picklescan - Remote Code Execution via Unblocked ctypes Module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71323"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-20181",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00748,
      "epss_percentile": 0.52056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-22",
      "title": "Cisco Identity Services Engine Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20181"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-48997",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00747,
      "epss_percentile": 0.52043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e107inc",
      "product": "e107",
      "cwe": "CWE-78",
      "title": "e107: Command Injection via shell expansion in ImageMagick resize destination path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48997"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-54806",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00699,
      "epss_percentile": 0.50319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Melapress",
      "product": "WP Activity Log",
      "cwe": "CWE-502",
      "title": "WordPress WP Activity Log plugin <= 5.6.3.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54806"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-48142",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00684,
      "epss_percentile": 0.49766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "NGINX Open Source",
      "cwe": "CWE-125",
      "title": "NGINX ngx_http_charset_module vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48142"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-20266",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00632,
      "epss_percentile": 0.476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk AI Toolkit",
      "cwe": "CWE-78",
      "title": "OS Command Injection in the btool Configuration Helper in Splunk AI Toolkit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20266"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-50203",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00626,
      "epss_percentile": 0.47314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow SFTP provider",
      "cwe": "CWE-22",
      "title": "Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory allows local file write outside the destination directory via malicious server-supplied directory-entry names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50203"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2025-71321",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00624,
      "epss_percentile": 0.4724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-502",
      "title": "picklescan - Arbitrary File Writing via distutils Module Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71321"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-3490",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00623,
      "epss_percentile": 0.47198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-183",
      "title": "picklescan - Universal Blocklist Bypass via pkgutil.resolve_name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3490"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2025-71320",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00623,
      "epss_percentile": 0.47198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-184",
      "title": "picklescan - Remote Code Execution via Incomplete Disallowed Inputs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71320"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-11407",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00623,
      "epss_percentile": 0.47169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pimcore GmbH",
      "product": "Pimcore CMS/DXP",
      "cwe": "CWE-1336",
      "title": "Pimcore CMS 12.3.8 Twig Sandbox Bypass via SecurityPolicy checkMethodAllowed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11407"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-12443",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00613,
      "epss_percentile": 0.46699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12443"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-53676",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00603,
      "epss_percentile": 0.46213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThingsBoard",
      "product": "ThingsBoard",
      "cwe": "CWE-1321",
      "title": "ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed context by a user who can log in to the affected product with the tenant administrator privilege (TENANT_ADMIN).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53676"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-53869",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00592,
      "epss_percentile": 0.4572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-306",
      "title": "Hermes Agent < 0.16.0 - DNS Rebinding Bypass via WebSocket Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53869"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-55196",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00579,
      "epss_percentile": 0.4509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hermes-webui",
      "product": "hermes-webui",
      "cwe": "CWE-306",
      "title": "Hermes WebUI < 0.51.409 - Unauthenticated Passkey Registration via Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55196"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-11311",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00567,
      "epss_percentile": 0.44547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "NGINX Gateway Fabric",
      "cwe": "CWE-74",
      "title": "NGINX Gateway Fabric vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11311"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-8383",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00563,
      "epss_percentile": 0.44349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "LearnPress",
      "cwe": "CWE-862",
      "title": "LearnPress < 4.3.7 - Unauthenticated Sensitive User Information Disclosure via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8383"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-49767",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00548,
      "epss_percentile": 0.43548,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tomdever",
      "product": "wpForo Forum",
      "cwe": "CWE-288",
      "title": "WordPress wpForo Forum plugin <= 3.1.0 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49767"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-40783",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00541,
      "epss_percentile": 0.43167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Creative Themes",
      "product": "Blocksy Companion Pro",
      "cwe": "CWE-94",
      "title": "WordPress Blocksy Companion Pro plugin <= 2.1.37 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40783"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-27400",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0054,
      "epss_percentile": 0.4314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ovatheme",
      "product": "BookPro",
      "cwe": "CWE-22",
      "title": "WordPress BookPro plugin <= 1.1.0 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27400"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2025-60205",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00525,
      "epss_percentile": 0.42324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "ThemeREX Addons",
      "cwe": "CWE-502",
      "title": "WordPress ThemeREX Addons plugin <= 2.36.1.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60205"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-53874",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00519,
      "epss_percentile": 0.41945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-502",
      "title": "picklescan - Arbitrary Code Execution via Obfuscated eval Call",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53874"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-12115",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00519,
      "epss_percentile": 0.41969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpcalc",
      "product": "Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress",
      "cwe": "CWE-502",
      "title": "Counter Box <= 2.0.13 - Authenticated (Administrator+) PHP Object Injection via Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12115"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-42380",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0051,
      "epss_percentile": 0.41385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jwsthemes",
      "product": "AI Lab",
      "cwe": "CWE-502",
      "title": "WordPress AI Lab theme < 5.4.2 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42380"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-53872",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00509,
      "epss_percentile": 0.41286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-22",
      "title": "picklescan - Arbitrary File Read via Unsafe Pickle Deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53872"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-20190",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00504,
      "epss_percentile": 0.40978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-285",
      "title": "Cisco Identity Services Engine Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20190"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-49268",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00494,
      "epss_percentile": 0.40436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Shiro",
      "cwe": "CWE-90",
      "title": "Apache Shiro: LDAP DN Injection in DefaultLdapRealm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49268"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-52707",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00494,
      "epss_percentile": 0.404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mikado-Themes",
      "product": "Kastell",
      "cwe": "CWE-35",
      "title": "WordPress Kastell theme <= 2.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52707"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-50107",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00492,
      "epss_percentile": 0.40315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "NGINX Gateway Fabric",
      "cwe": "CWE-74",
      "title": "NGINX Gateway Fabric vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50107"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2025-69130",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00482,
      "epss_percentile": 0.39686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themovation",
      "product": "Entrepreneur - Booking for Small Businesses WordPress Theme",
      "cwe": "CWE-502",
      "title": "WordPress Entrepreneur - Booking for Small Businesses WordPress Theme theme <= 3.1.3 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69130"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2025-71325",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00475,
      "epss_percentile": 0.39258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-391",
      "title": "picklescan - Detection Bypass via STACK_GLOBAL Opcode Parsing Logic Flaw",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71325"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2024-52488",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00471,
      "epss_percentile": 0.38906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zidithemes",
      "product": "Grip",
      "cwe": "CWE-434",
      "title": "WordPress Grip theme <= 1.0.9 - Arbitrary Plugin Activation/Deactivation to RCE vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-52488"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-36418",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00471,
      "epss_percentile": 0.38901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressions. The /jmreport/executeSelectApi endpoint passes user-supplied input directly to the Aviator expression engine without adequate validation allowing attackers to execute arbitrary code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36418"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-9690",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00467,
      "epss_percentile": 0.38704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomunited",
      "product": "WP Media folder Addon",
      "cwe": "CWE-22",
      "title": "WordPress WP Media folder Addon plugin <= 4.0.1 - Arbitrary File Download vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9690"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-22334",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00467,
      "epss_percentile": 0.38705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPos",
      "product": "Woocommerce Book Price",
      "cwe": "CWE-22",
      "title": "WordPress Woocommerce Book Price plugin <= 1.3 - Arbitrary File Download vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22334"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-52706",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00466,
      "epss_percentile": 0.38635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jetimpex Inc.",
      "product": "JetEngine",
      "cwe": "CWE-502",
      "title": "WordPress JetEngine plugin <= 3.8.10 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52706"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-22327",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00465,
      "epss_percentile": 0.38566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zozothemes",
      "product": "Restaurt",
      "cwe": "CWE-434",
      "title": "WordPress Restaurt theme <= 1.0.4 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22327"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-53873",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0046,
      "epss_percentile": 0.38234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-184",
      "title": "picklescan - Arbitrary Code Execution via profile.run() Blocklist Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53873"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2025-69128",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0046,
      "epss_percentile": 0.38237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EMV",
      "product": "JobCareer",
      "cwe": "CWE-22",
      "title": "WordPress JobCareer theme <= 7.3 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69128"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-9697",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00459,
      "epss_percentile": 0.38165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-295",
      "title": "undici vulnerable to TLS certificate validation bypass via dropped requestTls in SOCKS5 ProxyAgent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9697"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2025-59872",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00454,
      "epss_percentile": 0.37835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "ZIE",
      "cwe": "CWE-434",
      "title": "HCL ZIE for Web is affetced by an Unrestricted File Upload vulnerability,",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59872"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2025-69179",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0045,
      "epss_percentile": 0.3757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Theme passion",
      "product": "Support Ticket Management System",
      "cwe": "CWE-266",
      "title": "WordPress Support Ticket Management System plugin <= 1.9 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69179"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-54803",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0045,
      "epss_percentile": 0.37571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cozy Vision Technologies Pvt. Ltd.",
      "product": "SMS Alert Order Notifications",
      "cwe": "CWE-863",
      "title": "WordPress SMS Alert Order Notifications plugin <= 3.9.4 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54803"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2025-60223",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0045,
      "epss_percentile": 0.37551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuantumCloud",
      "product": "WPBot Pro Wordpress Chatbot",
      "cwe": "CWE-22",
      "title": "WordPress WPBot Pro Wordpress Chatbot plugin <= 13.6.5 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60223"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-39589",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00448,
      "epss_percentile": 0.37457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "A WP Life",
      "product": "Webenvo",
      "cwe": "CWE-434",
      "title": "WordPress Webenvo theme <= 0.0.6 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39589"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2025-60218",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00447,
      "epss_percentile": 0.37326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPLocker",
      "product": "PT Luxa Addons",
      "cwe": "CWE-434",
      "title": "WordPress PT Luxa Addons Plugin <= 1.2.2 - Arbitrary File Upload Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60218"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-54387",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00439,
      "epss_percentile": 0.36697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinyproxy",
      "product": "tinyproxy",
      "cwe": "CWE-444",
      "title": "Tinyproxy - HTTP Request Smuggling via CL/TE Desynchronization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54387"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-54388",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00439,
      "epss_percentile": 0.36697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinyproxy",
      "product": "tinyproxy",
      "cwe": "CWE-444",
      "title": "Tinyproxy - HTTP Request Smuggling via Duplicate Content-Length Headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54388"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-54807",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00437,
      "epss_percentile": 0.36583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeGrill",
      "product": "Registration Form for WooCommerce",
      "cwe": "CWE-266",
      "title": "WordPress Registration Form for WooCommerce plugin <= 1.0.9 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54807"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-24611",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00437,
      "epss_percentile": 0.36583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPMet",
      "product": "MetForm Pro",
      "cwe": "CWE-862",
      "title": "WordPress MetForm Pro plugin <= 3.9.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24611"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-41280",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00437,
      "epss_percentile": 0.36601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache DolphinScheduler",
      "cwe": "CWE-863",
      "title": "Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41280"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2025-69106",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Imba",
      "cwe": "CWE-98",
      "title": "WordPress Imba theme <= 1.5.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69106"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2025-69110",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "AirSupply",
      "cwe": "CWE-98",
      "title": "WordPress AirSupply theme <= 2.0.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69110"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2025-69117",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Ingenioso",
      "cwe": "CWE-98",
      "title": "WordPress Ingenioso theme <= 1.14.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69117"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2025-69120",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Dazzle",
      "cwe": "CWE-98",
      "title": "WordPress Dazzle theme <= 1.0.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69120"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2025-69148",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Quirky",
      "cwe": "CWE-98",
      "title": "WordPress Quirky theme <= 1.23 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69148"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2025-69157",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Gamic",
      "cwe": "CWE-98",
      "title": "WordPress Gamic theme <= 1.15 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69157"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2025-69166",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.3644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Gunslinger",
      "cwe": "CWE-98",
      "title": "WordPress Gunslinger theme <= 1.7 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69166"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2025-69172",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Resurs",
      "cwe": "CWE-98",
      "title": "WordPress Resurs theme <= 1.3 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69172"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2025-69173",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Tipsy",
      "cwe": "CWE-98",
      "title": "WordPress Tipsy theme <= 1.1 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69173"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-25446",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00434,
      "epss_percentile": 0.36315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WishList Products, LLC.",
      "product": "WishList Member X",
      "cwe": "CWE-434",
      "title": "WordPress WishList Member X plugin <= 3.29.0 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25446"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-40746",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00434,
      "epss_percentile": 0.36315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themagnifico52",
      "product": "Restaurant Zone",
      "cwe": "CWE-434",
      "title": "WordPress Restaurant Zone theme <= 0.7.8 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40746"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-40747",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00434,
      "epss_percentile": 0.36313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themagnifico52",
      "product": "Ecommerce Zone",
      "cwe": "CWE-434",
      "title": "WordPress Ecommerce Zone theme <= 0.9.7 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40747"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-40748",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00434,
      "epss_percentile": 0.36314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themagnifico52",
      "product": "Kids Gift Shop",
      "cwe": "CWE-434",
      "title": "WordPress Kids Gift Shop theme <= 0.5.4 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40748"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-40749",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00434,
      "epss_percentile": 0.36315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themagnifico52",
      "product": "Charity Zone",
      "cwe": "CWE-434",
      "title": "WordPress Charity Zone theme <= 1.1.1 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40749"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-53875",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00434,
      "epss_percentile": 0.36361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-95",
      "title": "picklescan - Scanning Bypass via Dynamic Eval in scan_pytorch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53875"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-47340",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00434,
      "epss_percentile": 0.36297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache DolphinScheduler",
      "cwe": "CWE-200",
      "title": "Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47340"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2025-69129",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00432,
      "epss_percentile": 0.36155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Extendons",
      "product": "WordPress & WooCommerce Scraper Plugin, Import Data from Any Site",
      "cwe": "CWE-434",
      "title": "WordPress WordPress & WooCommerce Scraper Plugin, Import Data from Any Site plugin <= 1.0.7 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69129"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2024-32729",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0043,
      "epss_percentile": 0.36029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuantumCloud",
      "product": "Conversational Forms for ChatBot",
      "cwe": "CWE-22",
      "title": "WordPress ChatBot Conversational Forms plugin <= 1.1.8 - Arbitrary File Download vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-32729"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2025-60229",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00426,
      "epss_percentile": 0.35727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeton",
      "product": "Lagom",
      "cwe": "CWE-502",
      "title": "WordPress Lagom theme <= 2.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60229"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2025-60230",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00426,
      "epss_percentile": 0.35727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeton",
      "product": "The Barber Shop",
      "cwe": "CWE-502",
      "title": "WordPress The Barber Shop theme <= 1.9 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60230"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-12447",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00426,
      "epss_percentile": 0.35697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12447"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-12466",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00426,
      "epss_percentile": 0.35697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12466"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-9675",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00426,
      "epss_percentile": 0.35727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-400",
      "title": "undici WebSocket client vulnerable to denial of service via cumulative fragment bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9675"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2025-58953",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Joly",
      "cwe": "CWE-98",
      "title": "WordPress Joly theme <= 1.22.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58953"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2025-58954",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "HomeRoofer",
      "cwe": "CWE-98",
      "title": "WordPress HomeRoofer theme <= 2.11.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58954"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-39537",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mikado-Themes",
      "product": "Mikado Core",
      "cwe": "CWE-98",
      "title": "WordPress Mikado Core plugin <= 1.6 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39537"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-40731",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mikado-Themes",
      "product": "ChapterOne",
      "cwe": "CWE-98",
      "title": "WordPress ChapterOne theme <= 1.7 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40731"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-10839",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0042,
      "epss_percentile": 0.35202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Password Manager",
      "product": "Password Manager",
      "cwe": "CWE-601",
      "title": "Open redirection vulnerability in Password Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10839"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-54417",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00417,
      "epss_percentile": 0.34995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rxi",
      "product": "microtar",
      "cwe": "CWE-190",
      "title": "Integer Overflow in rxi/microtar mtar_next() Causes Infinite Loop DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54417"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-40724",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00412,
      "epss_percentile": 0.34501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Client Portal Ltd.",
      "product": "Client Portal (Pro)",
      "cwe": "CWE-22",
      "title": "WordPress Client Portal (Pro) plugin <= 5.6.2 - Arbitrary File Download vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40724"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-40721",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.004,
      "epss_percentile": 0.33359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BdThemes",
      "product": "Element Pack Pro",
      "cwe": "CWE-98",
      "title": "WordPress Element Pack Pro plugin <= 9.0.6 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40721"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-55738",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rxi",
      "product": "microtar",
      "cwe": "CWE-121",
      "title": "Stack Buffer Overflow in rxi/microtar raw_to_header() via non-null-terminated TAR name field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55738"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-48989",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.33018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CursorTouch",
      "product": "Windows-MCP",
      "cwe": "CWE-306",
      "title": "Windows-MCP: HTTP transports expose unauthenticated PowerShell control with wildcard CORS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48989"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2025-59554",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.32967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Advanced Ads GmbH",
      "product": "Advanced Ads – Tracking",
      "cwe": "CWE-89",
      "title": "WordPress Advanced Ads – Tracking plugin < 3.0.7 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59554"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-12165",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.32985,
      "kev": false,
      "kev_due_at": null,
      "vendor": "contest-gallery",
      "product": "Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe",
      "cwe": "CWE-269",
      "title": "Contest Gallery <= 30.0.2 - Authenticated (Author+) Privilege Escalation via 'RegistryUserRole' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12165"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-12442",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00395,
      "epss_percentile": 0.32875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Passwords in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12442"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-39445",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00395,
      "epss_percentile": 0.32822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PressLayouts",
      "product": "Alukas",
      "cwe": "CWE-502",
      "title": "WordPress Alukas theme < 3.0.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39445"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-39545",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00395,
      "epss_percentile": 0.32823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Select-Themes",
      "product": "Zermatt",
      "cwe": "CWE-502",
      "title": "WordPress Zermatt theme <= 1.6.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39545"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-39573",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00395,
      "epss_percentile": 0.32822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Select-Themes",
      "product": "Mildhill",
      "cwe": "CWE-502",
      "title": "WordPress Mildhill theme <= 1.5 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39573"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-39576",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00395,
      "epss_percentile": 0.32823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "SingleMalt",
      "cwe": "CWE-502",
      "title": "WordPress SingleMalt theme <= 1.5 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39576"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-40735",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00395,
      "epss_percentile": 0.32823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edge-Themes",
      "product": "Reina",
      "cwe": "CWE-502",
      "title": "WordPress Reina theme <= 2.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40735"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-27868",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00394,
      "epss_percentile": 0.32694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Teldat",
      "product": "Regesta Smart HD-PLC - TLDPH16D2",
      "cwe": "CWE-201",
      "title": "PUBLICATION OF SENSITIVE INFORMATION ON REGESTA SMART HD-PLC OF TELDAT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27868"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-27869",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00394,
      "epss_percentile": 0.32694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Teldat",
      "product": "Regesta Smart HD-PLC - TLDPH16D2",
      "cwe": "CWE-770",
      "title": "WEB SERVICE (HTTP) DENIAL OF SERVICE VIA SLOW HEADERS ON REGESTA SMART HD-PLC OF TELDAT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27869"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2025-26240",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-26240"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-32966",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0039,
      "epss_percentile": 0.32361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache DolphinScheduler",
      "cwe": "CWE-863",
      "title": "Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32966"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2025-69138",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00389,
      "epss_percentile": 0.32229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jthemes",
      "product": "Genemy",
      "cwe": "CWE-266",
      "title": "WordPress Genemy theme <= 1.6.6 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69138"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-55743",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00388,
      "epss_percentile": 0.32167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinyhumansai",
      "product": "OpenHuman",
      "cwe": "CWE-78",
      "title": "OpenHuman desktop agent shell tool sandbox bypass leads to arbitrary command execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55743"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2025-69111",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00386,
      "epss_percentile": 0.31967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Reisen",
      "cwe": "CWE-502",
      "title": "WordPress Reisen theme <= 1.4.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69111"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2025-69127",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00386,
      "epss_percentile": 0.31967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Plumbing",
      "cwe": "CWE-502",
      "title": "WordPress Plumbing theme <= 1.6 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69127"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-45357",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00385,
      "epss_percentile": 0.31859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "harttle",
      "product": "liquidjs",
      "cwe": "CWE-400",
      "title": "LiquidJS: Memory and render limit bypass via unbounded width padding in `date` filter (strftime)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45357"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-45617",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00385,
      "epss_percentile": 0.31859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "harttle",
      "product": "liquidjs",
      "cwe": "CWE-1333",
      "title": "LiquidJS: ReDoS via Quadratic Backtracking in `strip_html` Filter Regex",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45617"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2025-71322",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.3169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PickleScan",
      "product": "PickleScan",
      "cwe": "CWE-693",
      "title": "PickleScan - Unsafe Globals Check Bypass via pty.spawn Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71322"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2025-66391",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00383,
      "epss_percentile": 0.3164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system will send a one-time password to an attacker-controlled email address when the attacker attempts to reset the password of a user account.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66391"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-55202",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00381,
      "epss_percentile": 0.31442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinyproxy",
      "product": "tinyproxy",
      "cwe": "CWE-290",
      "title": "Tinyproxy - Stathost Detection Bypass via Host Header Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55202"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-10094",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0038,
      "epss_percentile": 0.31348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dassault Systèmes",
      "product": "SOLIDWORKS Visualize",
      "cwe": "CWE-22",
      "title": "Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS Desktop Release 2026",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10094"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-48988",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00379,
      "epss_percentile": 0.31154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "markdown-it",
      "product": "markdown-it",
      "cwe": "CWE-400",
      "title": "markdown-it: Quadratic complexity DoS in smartquotes rule via replaceAt string operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48988"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2025-59563",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00378,
      "epss_percentile": 0.31046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SONAAR MUSIC",
      "product": "Sonaar",
      "cwe": "CWE-266",
      "title": "WordPress Sonaar theme <= 4.27.4 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59563"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-54805",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00378,
      "epss_percentile": 0.31046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sbouey",
      "product": "Falang multilanguage",
      "cwe": "CWE-266",
      "title": "WordPress Falang multilanguage plugin <= 1.4.2 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54805"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-40725",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00375,
      "epss_percentile": 0.30798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Barn2 Media Ltd",
      "product": "WooCommerce Product Filters",
      "cwe": "CWE-502",
      "title": "WordPress WooCommerce Product Filters plugin < 2.0.6 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40725"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-49075",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00375,
      "epss_percentile": 0.30805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jetimpex Inc.",
      "product": "JetEngine",
      "cwe": "CWE-502",
      "title": "WordPress JetEngine plugin <= 3.8.9.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49075"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-49107",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00375,
      "epss_percentile": 0.30796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thrive Themes",
      "product": "Thrive Apprentice",
      "cwe": "CWE-502",
      "title": "WordPress Thrive Apprentice plugin < 10.8.10.2 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49107"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-22340",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.30491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jobster Marketplace",
      "product": "WPJobster",
      "cwe": "CWE-89",
      "title": "WordPress WPJobster theme <= 6.3.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22340"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-39596",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.3049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Creative Themes",
      "product": "Blocksy Companion Pro",
      "cwe": "CWE-89",
      "title": "WordPress Blocksy Companion Pro plugin < 2.1.29 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39596"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-48875",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.30492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jetimpex Inc.",
      "product": "JetSmartFilters",
      "cwe": "CWE-89",
      "title": "WordPress JetSmartFilters plugin <= 3.8.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48875"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-49076",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.3049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jetimpex Inc.",
      "product": "JetEngine",
      "cwe": "CWE-89",
      "title": "WordPress JetEngine plugin <= 3.8.9.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49076"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-54802",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cozy Vision Technologies Pvt. Ltd.",
      "product": "SMS Alert Order Notifications",
      "cwe": "CWE-862",
      "title": "WordPress SMS Alert Order Notifications plugin <= 3.9.3 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54802"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-48818",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00368,
      "epss_percentile": 0.30007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kludex",
      "product": "starlette",
      "cwe": "CWE-918",
      "title": "Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48818"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-53871",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nesquena",
      "product": "hermes-webui",
      "cwe": "CWE-565",
      "title": "Hermes WebUI < 0.51.368 - Profile-Scoped Authorization Bypass via Forged hermes_profile Cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53871"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-8050",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SignalRGB",
      "product": "SignalRGB kernel driver",
      "cwe": null,
      "title": "CVE-2026-8050",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8050"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-22325",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.29521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AxiomThemes",
      "product": "Promo",
      "cwe": "CWE-98",
      "title": "WordPress Promo theme <= 1.3.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22325"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-22330",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.2952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeum",
      "product": "Right Way",
      "cwe": "CWE-98",
      "title": "WordPress Right Way theme <= 4.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22330"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-22331",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.2952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "AutoParts",
      "cwe": "CWE-98",
      "title": "WordPress AutoParts theme <= 1.5.8 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22331"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-9678",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0036,
      "epss_percentile": 0.29269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-524",
      "title": "undici vulnerable to cross-user information disclosure via shared cache whitespace bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9678"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-55706",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenBSD",
      "cwe": "CWE-1284",
      "title": "sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values for lengths.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55706"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-35065",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex",
      "cwe": "CWE-306",
      "title": "Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Code execution, Denial of service, Information disclosure, Information tampering, Remote execution, Script injection, and Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35065"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-54415",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Azuriom",
      "product": "Azuriom CMS",
      "cwe": "CWE-269",
      "title": "Broken Access Control in Azuriom CMS Server Routes Allows Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54415"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2025-69115",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "LuxMed | Medicine & Healthcare Doctor WordPress Theme",
      "cwe": "CWE-98",
      "title": "WordPress LuxMed | Medicine & Healthcare Doctor WordPress Theme theme <= 1.2.2 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69115"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2025-69123",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Snow Club",
      "cwe": "CWE-98",
      "title": "WordPress Snow Club theme <= 1.1 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69123"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2025-69126",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Fortius",
      "cwe": "CWE-98",
      "title": "WordPress Fortius theme <= 2.3.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69126"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2025-69144",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.28001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Preservation",
      "cwe": "CWE-98",
      "title": "WordPress Preservation theme <= 1.10 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69144"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2025-69145",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.28,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Gat",
      "cwe": "CWE-98",
      "title": "WordPress Gat theme <= 1.16 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69145"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2025-69158",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.28,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Granola",
      "cwe": "CWE-98",
      "title": "WordPress Granola theme <= 1.13 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69158"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2025-69161",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Snowy",
      "cwe": "CWE-98",
      "title": "WordPress Snowy theme <= 1.13 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69161"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2025-69164",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Skyward",
      "cwe": "CWE-98",
      "title": "WordPress Skyward theme <= 1.10 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69164"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2025-69170",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Eventicity",
      "cwe": "CWE-98",
      "title": "WordPress Eventicity theme <= 1.5 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69170"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2025-69171",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Orpheus",
      "cwe": "CWE-98",
      "title": "WordPress Orpheus theme <= 1.3 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69171"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2025-69174",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Etude",
      "cwe": "CWE-98",
      "title": "WordPress Etude theme <= 1.6 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69174"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2025-69175",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Line Agency",
      "cwe": "CWE-98",
      "title": "WordPress Line Agency theme <= 1.3.1 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69175"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-22335",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WC Lovers.",
      "product": "WooCommerce Frontend Manager – Ultimate",
      "cwe": "CWE-89",
      "title": "WordPress WooCommerce Frontend Manager – Ultimate plugin < 6.7.7 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22335"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-49079",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00346,
      "epss_percentile": 0.27812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jetimpex Inc.",
      "product": "JetSearch",
      "cwe": "CWE-89",
      "title": "WordPress JetSearch plugin <= 3.5.17 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49079"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-6734",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-346",
      "title": "undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6734"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-49133",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "typemill",
      "product": "typemill",
      "cwe": "CWE-22",
      "title": "Typemill < 2.24.0 Path Traversal via ControllerApiImage::getPagemedia()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49133"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2025-69135",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CurlyThemes",
      "product": "Events Schedule - WordPress Events Calendar Plugin",
      "cwe": "CWE-89",
      "title": "WordPress Events Schedule - WordPress Events Calendar Plugin plugin <= 2.7.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69135"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-52716",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0034,
      "epss_percentile": 0.27171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "purethemes",
      "product": "WorkScout-Core",
      "cwe": "CWE-22",
      "title": "WordPress WorkScout-Core plugin <= 1.7.11 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52716"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-50196",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SteeltoeOSS",
      "product": "Steeltoe.Discovery.Eureka",
      "cwe": "CWE-20",
      "title": "Steeltoe.Discovery.Eureka: Unrecognized DataCenterInfo.Name poisons entire registry fetch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50196"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2025-58952",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Neuronet",
      "cwe": "CWE-98",
      "title": "WordPress Neuronet theme < 1.14.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58952"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-22326",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AxiomThemes",
      "product": "Reprizo",
      "cwe": "CWE-98",
      "title": "WordPress Reprizo theme <= 1.0.8 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22326"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-22338",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26855,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "EcoBlue",
      "cwe": "CWE-98",
      "title": "WordPress EcoBlue theme <= 1.15 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22338"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-39523",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "Solene Core",
      "cwe": "CWE-98",
      "title": "WordPress Solene Core plugin <= 2.3.2 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39523"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-39558",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "Malmö",
      "cwe": "CWE-98",
      "title": "WordPress Malmö theme <= 2.2 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39558"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-39559",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26855,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codesupplyco",
      "product": "Uppercase",
      "cwe": "CWE-98",
      "title": "WordPress Uppercase theme < 1.2.2 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39559"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-39582",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xtemos",
      "product": "Hitek",
      "cwe": "CWE-98",
      "title": "WordPress Hitek theme < 1.8.3 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39582"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-39590",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26855,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeMove",
      "product": "Atomlab",
      "cwe": "CWE-98",
      "title": "WordPress Atomlab theme <= 2.4.5 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39590"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-32967",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00337,
      "epss_percentile": 0.26788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache DolphinScheduler",
      "cwe": "CWE-863",
      "title": "Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32967"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-48967",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dylan Kuhn",
      "product": "Geo Mashup",
      "cwe": "CWE-89",
      "title": "WordPress Geo Mashup plugin <= 1.13.19 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48967"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-54185",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "THEMECO",
      "product": "Cornerstone",
      "cwe": "CWE-89",
      "title": "WordPress Cornerstone plugin < 7.8.8 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54185"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-12439",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.25979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Digital Credentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12439"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-54814",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StylemixThemes",
      "product": "Motors",
      "cwe": "CWE-98",
      "title": "WordPress Motors plugin <= 1.4.109 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54814"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-54193",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeFusion",
      "product": "Fusion Builder",
      "cwe": "CWE-22",
      "title": "WordPress Fusion Builder plugin <= 3.15.4 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54193"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-54816",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Monetizemore",
      "product": "Advanced Ads",
      "cwe": "CWE-94",
      "title": "WordPress Advanced Ads plugin <= 2.0.21 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54816"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-12199",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25464,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nltk",
      "product": "nltk/nltk",
      "cwe": "CWE-306",
      "title": "Unauthenticated Denial of Service in nltk.app.wordnet_app",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12199"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-25439",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fs-code",
      "product": "Booknetic",
      "cwe": "CWE-288",
      "title": "WordPress Booknetic plugin <= 4.8.5 - Account Takeover vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25439"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-12360",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock",
      "product": "JetEngine",
      "cwe": "CWE-89",
      "title": "JetEngine <= 3.8.10.1 - Unauthenticated SQL Injection via Listing Grid Load More AJAX Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12360"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-49058",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00321,
      "epss_percentile": 0.25017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LoginPress",
      "product": "LoginPress Pro",
      "cwe": "CWE-266",
      "title": "WordPress LoginPress Pro plugin <= 6.2.2 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49058"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-27041",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00319,
      "epss_percentile": 0.2476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Studio Keren Aga LTD.",
      "product": "Unlimited Elements for Elementor (Premium)",
      "cwe": "CWE-434",
      "title": "WordPress Unlimited Elements for Elementor (Premium) plugin <= 2.0.6 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27041"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-44645",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00317,
      "epss_percentile": 0.24591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "harttle",
      "product": "liquidjs",
      "cwe": "CWE-400",
      "title": "LiquidJS has a renderLimit DoS guard bypass via empty `{% for %}` body",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44645"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-42629",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Powerpackelements",
      "product": "PowerPack Pro for Elementor",
      "cwe": "CWE-288",
      "title": "WordPress PowerPack Pro for Elementor plugin < v2.13.0 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42629"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-10837",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00315,
      "epss_percentile": 0.24316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Password Manager",
      "product": "Password Manager",
      "cwe": "CWE-601",
      "title": "Open redirection vulnerability in Password Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10837"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2025-60231",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EMV",
      "product": "The Hospital",
      "cwe": "CWE-502",
      "title": "WordPress The Hospital theme <= 1.8.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60231"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2025-60236",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EMV",
      "product": "Creatify",
      "cwe": "CWE-502",
      "title": "WordPress Creatify theme <= 1.5 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60236"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-42357",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.2399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache DolphinScheduler",
      "cwe": "CWE-863",
      "title": "Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42357"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-49072",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00309,
      "epss_percentile": 0.23626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OPMC",
      "product": "WooCommerce Anti-Fraud",
      "cwe": "CWE-862",
      "title": "WordPress WooCommerce Anti-Fraud plugin <= 7.2.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49072"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-54808",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00308,
      "epss_percentile": 0.23522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Travel",
      "product": "WP Travel Gutenberg Blocks",
      "cwe": "CWE-89",
      "title": "WordPress WP Travel Gutenberg Blocks plugin <= 3.9.4 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54808"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-39442",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PressLayouts",
      "product": "PressMart",
      "cwe": "CWE-502",
      "title": "WordPress PressMart theme <= 1.2.26 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39442"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-39556",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "Konsept",
      "cwe": "CWE-502",
      "title": "WordPress Konsept theme <= 1.9 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39556"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-39560",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Select-Themes",
      "product": "Hiroshi",
      "cwe": "CWE-502",
      "title": "WordPress Hiroshi theme <= 1.5.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39560"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-40733",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mikado-Themes",
      "product": "ShiftUp",
      "cwe": "CWE-502",
      "title": "WordPress ShiftUp theme <= 1.3 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40733"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-40738",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edge-Themes",
      "product": "Eldon",
      "cwe": "CWE-502",
      "title": "WordPress Eldon theme <= 1.4.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40738"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-40752",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Select-Themes",
      "product": "Manufaktur Solutions",
      "cwe": "CWE-502",
      "title": "WordPress Manufaktur Solutions theme <= 1.1.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40752"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-40753",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mikado-Themes",
      "product": "EasyMeals",
      "cwe": "CWE-502",
      "title": "WordPress EasyMeals theme <= 1.5.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40753"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-10836",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Password Manager",
      "product": "Password Manager",
      "cwe": "CWE-644",
      "title": "Improper neutralization of HTTP headers in Password Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10836"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-49071",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.23185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OPMC",
      "product": "WooCommerce Dropshipping",
      "cwe": "CWE-288",
      "title": "WordPress WooCommerce Dropshipping plugin <= 5.2.4 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49071"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-49108",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00304,
      "epss_percentile": 0.23127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "park_of_ideas",
      "product": "Moderno",
      "cwe": "CWE-502",
      "title": "WordPress Moderno theme < 1.43 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49108"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2025-49403",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AA-Team",
      "product": "Premium Age Verification / Restriction for WordPress",
      "cwe": "CWE-98",
      "title": "WordPress Premium Age Verification / Restriction for WordPress Plugin <= 3.0.2 - Arbitrary File Download Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-49403"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-55201",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hackplayers",
      "product": "evil-winrm",
      "cwe": "CWE-22",
      "title": "Evil-WinRM - Path Traversal in download_dir() Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55201"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-45436",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00304,
      "epss_percentile": 0.23128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rain-Task Ltd.",
      "product": "WPBakery Page Builder",
      "cwe": "CWE-862",
      "title": "WordPress WPBakery Page Builder plugin <= 8.7.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45436"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-34888",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.2293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bricksforge",
      "product": "Bricksforge",
      "cwe": "CWE-201",
      "title": "WordPress Bricksforge plugin <= 3.1.8.4 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34888"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-12530",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "bedrock-agentcore",
      "cwe": "CWE-88",
      "title": "Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12530"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-12441",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.2276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in File Input in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12441"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-12437",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00299,
      "epss_percentile": 0.22536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebShare in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12437"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-48814",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00297,
      "epss_percentile": 0.22356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jovancoding",
      "product": "Network-AI",
      "cwe": "CWE-306",
      "title": "Network-AI: Empty default secret still authorizes all requests (Incomplete fix for CVE-2026-46701)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48814"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-30803",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RTI",
      "product": "Connext Micro",
      "cwe": "CWE-191",
      "title": "Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30803"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2024-35690",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.21966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MarketingFire",
      "product": "Widget Options",
      "cwe": "CWE-201",
      "title": "WordPress Widget Options plugin <= 4.0.1 - Subscriber+ User Meta Data Exposure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-35690"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2024-32949",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.21904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Prince",
      "product": "Integrate Google Drive",
      "cwe": "CWE-862",
      "title": "WordPress Integrate Google Drive plugin <= 1.3.8 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-32949"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-27870",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Teldat",
      "product": "Regesta Smart HD-PLC - TLDPH16D2",
      "cwe": "CWE-79",
      "title": "CROSS-SITE SCRIPTING (XSS) VIA MALICIOUS FILE UPLOAD ON REGESTA SMART HD-PLC OF TELDAT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27870"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-32682",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "NGINX Gateway Fabric",
      "cwe": "CWE-129",
      "title": "NGINX Gateway Fabric vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32682"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-54445",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vantage6",
      "product": "vantage6",
      "cwe": "CWE-204",
      "title": "Vantage6: Set admin user and password from environment or configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54445"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-49081",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeGrill",
      "product": "User Registration Stripe",
      "cwe": "CWE-862",
      "title": "WordPress User Registration Stripe plugin <= 1.3.12 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49081"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-50202",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SteeltoeOSS",
      "product": "Steeltoe.Security.Authentication.CloudFoundryBase",
      "cwe": "CWE-668",
      "title": "Steeltoe's static JWKS cache shared across schemes and never invalidated",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50202"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-54186",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00289,
      "epss_percentile": 0.21467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eyecix",
      "product": "JobSearch",
      "cwe": "CWE-89",
      "title": "WordPress JobSearch plugin <= 3.2.9 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54186"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-39546",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21389,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Techspawn",
      "product": "MultiLoca",
      "cwe": "CWE-266",
      "title": "WordPress MultiLoca plugin <= 4.2.15 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39546"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-40768",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21389,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dimitri Grassi",
      "product": "Salon booking system",
      "cwe": "CWE-639",
      "title": "WordPress Salon booking system plugin <= 10.30.24 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40768"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-52705",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00285,
      "epss_percentile": 0.2109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BDthemes",
      "product": "SigmaForms Pro – AI Generated Forms",
      "cwe": "CWE-434",
      "title": "WordPress SigmaForms Pro – AI Generated Forms plugin <= 1.4.5 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52705"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-54533",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vantage6",
      "product": "vantage6",
      "cwe": "CWE-284",
      "title": "vantage6 node has an Improper Access Control issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54533"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-12529",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00284,
      "epss_percentile": 0.20972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "CET Automated Grading System with AI Predictive Analytics",
      "cwe": "CWE-266",
      "title": "SourceCodester CET Automated Grading System with AI Predictive Analytics Student Self-Registration Endpoint index.php access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12529"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-22332",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.2087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeum",
      "product": "Tutor LMS Pro",
      "cwe": "CWE-89",
      "title": "WordPress Tutor LMS Pro plugin <= 3.9.6 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22332"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-49084",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jetimpex Inc.",
      "product": "JetEngine",
      "cwe": "CWE-89",
      "title": "WordPress JetEngine plugin < 3.8.9.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49084"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-54187",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jetimpex Inc.",
      "product": "JetEngine",
      "cwe": "CWE-89",
      "title": "WordPress JetEngine plugin <= 3.8.10.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54187"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-54811",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tips and Tricks HQ",
      "product": "WP eMember",
      "cwe": "CWE-89",
      "title": "WordPress WP eMember plugin < v10.9.4 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54811"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-54812",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StylemixThemes",
      "product": "Motors",
      "cwe": "CWE-89",
      "title": "WordPress Motors plugin <= 1.4.109 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54812"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-10641",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in Bluetooth HFP Hands-Free CIND indicator parsing (cind_handle_values)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10641"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-54818",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.2038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VeronaLabs",
      "product": "Slimstat Analytics",
      "cwe": "CWE-89",
      "title": "WordPress Slimstat Analytics plugin <= 5.4.11 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54818"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2024-27928",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.2037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vantage6",
      "product": "vantage6",
      "cwe": "CWE-308",
      "title": "Vantage6: 2FA can be circumvented with hacked email access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-27928"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2024-24769",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00278,
      "epss_percentile": 0.20315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vantage6",
      "product": "vantage6",
      "cwe": "CWE-400",
      "title": "Vantage6: No limit on emails sent for password/MFA reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-24769"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-54804",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "melhorenvio",
      "product": "Melhor Envio",
      "cwe": "CWE-288",
      "title": "WordPress Melhor Envio plugin <= 2.16.3 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54804"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-27410",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.19899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VeronaLabs",
      "product": "Slimstat Analytics",
      "cwe": "CWE-502",
      "title": "WordPress Slimstat Analytics plugin < 5.4.0 - Deserialization of untrusted data vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27410"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-11857",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quanos Solutions GmbH",
      "product": "SCHEMA ST4",
      "cwe": "CWE-502",
      "title": "Insecure .NET Remoting deserialization in Quanos SCHEMA ST4 Client Update Service allows local privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11857"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-55197",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nesquena",
      "product": "hermes-webui",
      "cwe": "CWE-639",
      "title": "Hermes WebUI < 0.51.443 - Broken Access Control in /api/session Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55197"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-55198",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nesquena",
      "product": "hermes-webui",
      "cwe": "CWE-639",
      "title": "Hermes WebUI < 0.51.443 - Cross-Profile Session Data Exfiltration via Session Export Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55198"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-48764",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.19594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-918",
      "title": "TypeBot has SSRF in HTTP request and script fetch flows via DNS rebinding bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48764"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-12462",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.19393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12462"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-44646",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.19413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "harttle",
      "product": "liquidjs",
      "cwe": "CWE-693",
      "title": "LiquidJS: `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44646"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-10741",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sonatype",
      "product": "Nexus Repository Manager",
      "cwe": "CWE-863",
      "title": "Nexus Repository Manager - Incorrect Authorization allows credential disclosure via proxy repository configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10741"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-10696",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "UniGetUI",
      "cwe": "CWE-706",
      "title": "Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier allows a WinGet community catalog contributor to cause an installed application to be correlated to an unrelated, attacker-controlled catalog package and to execute an attacker-controlled installer via a crafted catalog package whose normalized name is contained as a substring within the installed application name when a user applies the proposed update.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10696"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2024-37210",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ali2woo",
      "product": "AliNext",
      "cwe": "CWE-862",
      "title": "WordPress AliExpress Dropshipping with AliNext Lite plugin <= 3.3.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-37210"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-48768",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00268,
      "epss_percentile": 0.19092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-22",
      "title": "TypeBot: Unauthenticated arbitrary s3 object write in generate-upload-url via unsanitized fileName",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48768"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-48979",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.1895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "php-standard-library",
      "product": "php-standard-library",
      "cwe": "CWE-444",
      "title": "PHP Standard Library: HTTP/2 server-side missing content-length validation enables request smuggling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48979"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-22343",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.18035,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PremiumPress Limited.",
      "product": "WordPress Dating Theme",
      "cwe": "CWE-862",
      "title": "WordPress WordPress Dating Theme theme <= 11.2.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22343"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-8607",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "saadiqbal",
      "product": "Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred",
      "cwe": "CWE-79",
      "title": "myCred – Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wrap' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8607"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-24575",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WishList Member",
      "product": "WishList Member X",
      "cwe": "CWE-862",
      "title": "WordPress WishList Member X plugin <= 3.29.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24575"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-48820",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cakephp",
      "product": "cakephp",
      "cwe": "CWE-22",
      "title": "CakePHP: View::element() is missing a path containment check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48820"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-9679",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-93",
      "title": "undici vulnerable to HTTP header injection via Set-Cookie percent-decoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9679"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-12452",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17464,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Downloads in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12452"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-8494",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mbis",
      "product": "Permalink Manager Lite",
      "cwe": "CWE-79",
      "title": "Permalink Manager Lite <= 2.5.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8494"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-11975",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "simplcommerce",
      "product": "SimplCommerce",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) in SimplCommerce News Module Admin Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11975"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-12448",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12448"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-30799",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RTI",
      "product": "Connext Professional",
      "cwe": "CWE-306",
      "title": "Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identity Spoofing.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30799"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-54184",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.17105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Alberto Hornero",
      "product": "Clean Login",
      "cwe": "CWE-639",
      "title": "WordPress Clean Login plugin <= 1.15 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54184"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-54817",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FluxBuilder",
      "product": "MStore API",
      "cwe": "CWE-288",
      "title": "WordPress MStore API plugin <= 4.18.4 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54817"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-20220",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Crosswork Network Change Automation",
      "cwe": "CWE-74",
      "title": "Cisco Crosswork Network Controller Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20220"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-12440",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00251,
      "epss_percentile": 0.1682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12440"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-7300",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RTI",
      "product": "Connext Professional",
      "cwe": "CWE-120",
      "title": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web Integration Service) allows Filter Failure through Buffer Overflow.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7300"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-12568",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Black Lantern Security",
      "product": "BBOT",
      "cwe": "CWE-22",
      "title": "Arbitrary File Write in postman_download module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12568"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-40756",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mikado-Themes",
      "product": "Zoya",
      "cwe": "CWE-502",
      "title": "WordPress Zoya theme <= 1.4 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40756"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-40757",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mikado-Themes",
      "product": "Château",
      "cwe": "CWE-502",
      "title": "WordPress Château theme <= 1.2.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40757"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-30802",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RTI",
      "product": "Connext Micro",
      "cwe": "CWE-125",
      "title": "Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30802"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2024-33909",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Avirtum",
      "product": "iPages Flipbook",
      "cwe": "CWE-862",
      "title": "WordPress iPages Flipbook plugin <= 1.5.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-33909"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-40726",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.1591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeGrill",
      "product": "User Registration Stripe",
      "cwe": "CWE-862",
      "title": "WordPress User Registration Stripe plugin <= 1.3.14 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40726"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-22328",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.15895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VamTam",
      "product": "Auto Repair",
      "cwe": "CWE-79",
      "title": "WordPress Auto Repair theme <= 22.6 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22328"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-24610",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPMet",
      "product": "MetForm Pro",
      "cwe": "CWE-862",
      "title": "WordPress MetForm Pro plugin <= 3.9.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24610"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-40723",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bricks",
      "product": "Bricks Builder",
      "cwe": "CWE-862",
      "title": "WordPress Bricks Builder theme <= 2.1.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40723"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-12465",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Object lifecycle issue in Metrics in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12465"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-12461",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12461"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2024-49269",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mythemes",
      "product": "my flatonica",
      "cwe": "CWE-79",
      "title": "WordPress my flatonica theme <= 0.0.8 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-49269"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-54386",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "marimo-team",
      "product": "marimo",
      "cwe": "CWE-79",
      "title": "marimo < 0.23.9 XSS via file Query Parameter in assets.py",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54386"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-12491",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vLLM",
      "cwe": "CWE-115",
      "title": "Vllm: vllm: image exif rotation & png trns transparency not normalized, causing mismatch between model input and expectations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12491"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-50194",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.1509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SteeltoeOSS",
      "product": "Steeltoe.Management.Endpoint",
      "cwe": "CWE-288",
      "title": "Steeltoe vulnerable to management-port isolation bypass via spoofed Host header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50194"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-52696",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jetimpex Inc.",
      "product": "JetBlog",
      "cwe": "CWE-1258",
      "title": "WordPress JetBlog plugin <= 2.4.8 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52696"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-11525",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00238,
      "epss_percentile": 0.1516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-183",
      "title": "undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11525"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-54810",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14855,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexi Payments",
      "product": "Nexi XPay",
      "cwe": "CWE-862",
      "title": "WordPress Nexi XPay plugin <= 8.3.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54810"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-54196",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jetmonsters",
      "product": "JetFormBuilder",
      "cwe": "CWE-266",
      "title": "WordPress JetFormBuilder plugin <= 3.6.1 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54196"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-54809",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.14612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VillaTheme",
      "product": "GIFT4U",
      "cwe": "CWE-89",
      "title": "WordPress GIFT4U plugin <= 1.0.10 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54809"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-50201",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SteeltoeOSS",
      "product": "Steeltoe.Management.Endpoint",
      "cwe": "CWE-269",
      "title": "Steeltoe's sensitive actuators (heapdump/env) only require Restricted permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50201"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2025-59560",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SONAAR MUSIC",
      "product": "Sonaar",
      "cwe": "CWE-79",
      "title": "WordPress Sonaar theme <= 4.27.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59560"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2025-68524",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.1411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeGoods",
      "product": "Avante",
      "cwe": "CWE-79",
      "title": "WordPress Avante theme < 3.0.5 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68524"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-22339",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jobster Marketplace",
      "product": "WPJobster",
      "cwe": "CWE-79",
      "title": "WordPress WPJobster theme <= 6.3.5 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22339"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-40765",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "collectchat",
      "product": "collectchat",
      "cwe": "CWE-79",
      "title": "WordPress collectchat plugin <= 2.4.9 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40765"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-41557",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PressLayouts",
      "product": "Kapee",
      "cwe": "CWE-79",
      "title": "WordPress Kapee theme < 1.7.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41557"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-42385",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cozmoslabs",
      "product": "Profile Builder Pro",
      "cwe": "CWE-79",
      "title": "WordPress Profile Builder Pro plugin <= 3.15.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42385"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-54815",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00229,
      "epss_percentile": 0.14015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cargo RD",
      "product": "Cargo Shipping Location for WooCommerce",
      "cwe": "CWE-89",
      "title": "WordPress Cargo Shipping Location for WooCommerce plugin <= 5.6 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54815"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-54819",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00229,
      "epss_percentile": 0.14017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webilia Inc.",
      "product": "Listdom",
      "cwe": "CWE-89",
      "title": "WordPress Listdom plugin <= 5.4.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54819"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-35069",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.13987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex",
      "cwe": "CWE-89",
      "title": "Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Script injection.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35069"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-32804",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex",
      "cwe": "CWE-287",
      "title": "Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32804"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2025-15657",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mojoomla",
      "product": "School Management",
      "cwe": "CWE-639",
      "title": "WordPress School Management plugin <= 93.1.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15657"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-12455",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Tab Strip in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12455"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-12528",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11",
      "cwe": "CWE-787",
      "title": "389-ds-base: 389-ds-base: heap-buffer-overflows in __aclp__normalize_acltxt()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12528"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-12515",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6.16 for RHEL 8",
      "cwe": "CWE-862",
      "title": "Katello: missing repository authorization in content_uploads exposes cross-product content existence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12515"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-12464",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Browser in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12464"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-12467",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12467"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-54192",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.12861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ays Pro",
      "product": "Popup box",
      "cwe": "CWE-79",
      "title": "WordPress Popup box plugin <= 6.2.9 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54192"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-6733",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.0022,
      "epss_percentile": 0.12752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-367",
      "title": "undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6733"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-0092",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00218,
      "epss_percentile": 0.12539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-862",
      "title": "In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0092"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-55748",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12545,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Horizon",
      "cwe": "CWE-78",
      "title": "OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55748"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-20265",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.1241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk AI Toolkit",
      "cwe": "CWE-1188",
      "title": "Insecure Default Domain Allowlist in Splunk AI Toolkit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20265"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-8089",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce",
      "cwe": "CWE-79",
      "title": "weMail < 2.1.3 - Reflected Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8089"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-52698",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Syed Balkhi",
      "product": "PushEngage – Web Push Notifications, eCommerce Automation &amp; Chat Widget",
      "cwe": "CWE-201",
      "title": "WordPress PushEngage – Web Push Notifications, eCommerce Automation & Chat Widget plugin <= 4.2.3 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52698"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-22283",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.11927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex",
      "cwe": "CWE-829",
      "title": "Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion of Functionality from Untrusted Control Sphere vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22283"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-48817",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kludex",
      "product": "starlette",
      "cwe": "CWE-470",
      "title": "Starlette: Arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48817"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-2675",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RTI",
      "product": "Connext Professional",
      "cwe": "CWE-306",
      "title": "Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake the Source of Data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2675"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-49502",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex",
      "cwe": "CWE-287",
      "title": "Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure, Information tampering, and Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49502"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-35162",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex",
      "cwe": "CWE-284",
      "title": "Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35162"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-39595",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BoldGrid",
      "product": "W3 Total Cache",
      "cwe": "CWE-862",
      "title": "WordPress W3 Total Cache plugin <= 2.9.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39595"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-12565",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Black Lantern Security",
      "product": "BBOT",
      "cwe": "CWE-22",
      "title": "Path Traversal (Zip-Slip) in unarchive module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12565"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2024-31435",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Inisev",
      "product": "Social Media & Share Icons",
      "cwe": "CWE-862",
      "title": "WordPress Social Media Share Buttons & Social Sharing Icons plugin <= 2.8.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-31435"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2024-37496",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.1127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rara Themes",
      "product": "Metro Magazine",
      "cwe": "CWE-862",
      "title": "WordPress Metro Magazine theme <= 1.3.7 - Broken Access Control on Notice Dismissal vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-37496"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-12438",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.11178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12438"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-54813",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brainstorm Force",
      "product": "SureDash",
      "cwe": "CWE-89",
      "title": "WordPress SureDash plugin <= 1.8.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54813"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2025-62340",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "iControl",
      "cwe": "CWE-613",
      "title": "HCL iControl was affected by Inadequate Session Timeout vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62340"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-44644",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "harttle",
      "product": "liquidjs",
      "cwe": "CWE-79",
      "title": "LiquidJS's strip_html filter bypass via newline characters in HTML tags enables XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44644"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-48759",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-639",
      "title": "TypeBot: Cross-Workspace Theme Template IDOR (Modification and Deletion)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48759"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-20178",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Webex App",
      "cwe": "CWE-601",
      "title": "A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco has addressed this vulnerability in the Cisco Webex App, and no customer action is needed. This vulnerability existed due to improper input validation of URL parameters in an HTTP request. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by persuading a user to click a crafted URL. A successful exploit could have allowed the attacker to redirect a user to a malicious website.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20178"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-3894",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.002,
      "epss_percentile": 0.10157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RTI",
      "product": "Connext Professional",
      "cwe": "CWE-125",
      "title": "Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3894"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-54195",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.0991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jetmonsters",
      "product": "JetFormBuilder",
      "cwe": "CWE-79",
      "title": "WordPress JetFormBuilder plugin <= 3.6.0.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54195"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-9591",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09804,
      "kev": false,
      "kev_due_at": null,
      "vendor": "simplcommerce",
      "product": "SimplCommerce",
      "cwe": "CWE-352",
      "title": "Cross-Site Request Forgery (CSRF) in SimplCommerce News Module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9591"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-12446",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12446"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-35068",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex",
      "cwe": "CWE-89",
      "title": "Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35068"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2024-24709",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shareaholic",
      "product": "Shareaholic",
      "cwe": "CWE-862",
      "title": "WordPress Shareaholic plugin <= 9.7.11 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-24709"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2025-48571",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-693",
      "title": "In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48571"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-12458",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0019,
      "epss_percentile": 0.09007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12458"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-2467",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00189,
      "epss_percentile": 0.08859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RTI",
      "product": "Connext Professional",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2467"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-40722",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yoast BV",
      "product": "Yoast SEO Premium",
      "cwe": "CWE-862",
      "title": "WordPress Yoast SEO Premium plugin <= 26.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40722"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-22329",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeum",
      "product": "Skillate",
      "cwe": "CWE-79",
      "title": "WordPress Skillate theme <= 1.2.10 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22329"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-49778",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPFunnels",
      "product": "WPFunnels Pro",
      "cwe": "CWE-79",
      "title": "WordPress WPFunnels Pro plugin <= 2.9.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49778"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-12469",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12469"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-50200",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SteeltoeOSS",
      "product": "Steeltoe.Management.Endpoint",
      "cwe": "CWE-200",
      "title": "Steeltoe's env sanitizer misses connection strings — leaks embedded DB passwords",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50200"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-22342",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.08305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PremiumPress Limited.",
      "product": "WordPress Dating Theme",
      "cwe": "CWE-352",
      "title": "WordPress WordPress Dating Theme theme <= 11.2.0 - Cross Site Request Forgery (CSRF) to Account Takeover vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22342"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-48117",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fduflyer",
      "product": "DroneAware-Node-Releases",
      "cwe": "CWE-287",
      "title": "DroneAware's Improper Account Activation in Registration and SSO Flows Leads to Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48117"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-12450",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12450"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-35066",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00183,
      "epss_percentile": 0.08227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex",
      "cwe": "CWE-284",
      "title": "Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35066"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-12459",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.0795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in Serial in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12459"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2025-69140",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SeventhQueen",
      "product": "SweetDate Core",
      "cwe": "CWE-79",
      "title": "WordPress SweetDate Core plugin < 1.1.5 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69140"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-2674",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RTI",
      "product": "Connext Professional",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Service,Core Libraries,Persistence Service) allows Overflow Buffers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2674"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-12453",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12453"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2025-69189",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00178,
      "epss_percentile": 0.07619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EMV",
      "product": "JobBank",
      "cwe": "CWE-862",
      "title": "WordPress JobBank plugin <= 1.2.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69189"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-12451",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.07497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12451"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-39597",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPZOOM",
      "product": "WPZOOM Addons for Elementor",
      "cwe": "CWE-79",
      "title": "WordPress WPZOOM Addons for Elementor plugin <= 1.3.4 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39597"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-40720",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Royal Elementor Addons",
      "product": "Royal Elementor Addons Pro",
      "cwe": "CWE-79",
      "title": "WordPress Royal Elementor Addons Pro plugin < 1.7.1041 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40720"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-49074",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jetimpex Inc.",
      "product": "JetEngine",
      "cwe": "CWE-79",
      "title": "WordPress JetEngine plugin <= 3.8.9.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49074"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-12566",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00167,
      "epss_percentile": 0.06423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Black Lantern Security",
      "product": "BBOT",
      "cwe": "CWE-918",
      "title": "SSRF via unvalidated WWW-Authenticate realm in docker_pull module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12566"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-0082",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00165,
      "epss_percentile": 0.06195,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-453",
      "title": "In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0082"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-10850",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Plane",
      "product": "Plane",
      "cwe": "CWE-79",
      "title": "Plane 1.3.1 - Stored XSS in intake issue description_html",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10850"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2025-15641",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netskope",
      "product": "Netskope Client",
      "cwe": "CWE-782",
      "title": "Netskope Client Exposed IOCTL with Insufficient Access Controls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15641"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-48990",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "authlib",
      "product": "joserfc",
      "cwe": "CWE-400",
      "title": "joserfc: b64=false RFC7797 JWS payloads bypass JWSRegistry payload-size limits during deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48990"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-12445",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.05515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12445"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-0063",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00155,
      "epss_percentile": 0.05198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-269",
      "title": "In setAllowedCarriers of PhoneInterfaceManager.java, there is a possible way to disable carrier restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0063"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-0071",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00155,
      "epss_percentile": 0.05198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-862",
      "title": "In SettingsLib, there is a possible missing permission check due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0071"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2024-33685",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jegstudio",
      "product": "Startupzy",
      "cwe": "CWE-862",
      "title": "WordPress Startupzy theme <= 1.1.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-33685"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-12460",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.04995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in File System Access in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12460"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-5667",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mitsubishi Electric Corporation",
      "product": "Room Air Conditioners (for Japan) MSZ-BKR2223-W",
      "cwe": "CWE-798",
      "title": "Information Disclosure, Information Tampering, or Denial-of-Service (DoS) Vulnerability in Multiple Home Appliances",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5667"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-35067",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex",
      "cwe": "CWE-284",
      "title": "Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileged attacker with adjacent network access could potentially exploit this vulnerability, leading to Elevation of privileges and Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35067"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-0081",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00148,
      "epss_percentile": 0.04546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-862",
      "title": "In NFC, there is a possible way to spoof an NFC event due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0081"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-28576",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00148,
      "epss_percentile": 0.04531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Android",
      "product": "Android",
      "cwe": "CWE-89",
      "title": "In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28576"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-12454",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12454"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2025-31013",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themify",
      "product": "Themify Folo",
      "cwe": "CWE-79",
      "title": "WordPress Themify Folo theme <= 1.9.6 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-31013"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-9570",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.0439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Taskbuilder",
      "cwe": "CWE-79",
      "title": "Taskbuilder < 5.0.8 - Reflected XSS via Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9570"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2025-32748",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex rack",
      "cwe": "CWE-601",
      "title": "Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Host Header Injection vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to trigger redirections.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32748"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-12468",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00143,
      "epss_percentile": 0.04056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in Updater in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12468"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2025-15642",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netskope",
      "product": "Netskope Client",
      "cwe": "CWE-276",
      "title": "Netskope Client Service Insufficient Access Controls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15642"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-12444",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12444"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-54188",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jetimpex Inc.",
      "product": "JetEngine",
      "cwe": "CWE-79",
      "title": "WordPress JetEngine plugin <= 3.8.10 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54188"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-54189",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jetimpex Inc.",
      "product": "JetEngine",
      "cwe": "CWE-79",
      "title": "WordPress JetEngine plugin <= 3.8.10 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54189"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-7850",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Magnific Popup",
      "cwe": null,
      "title": "WP Magnific Popup <= 1.0 - Author+ Stored XSS via href Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7850"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-12456",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12456"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-12457",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.0348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12457"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-48591",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pragdave",
      "product": "earmark",
      "cwe": "CWE-83",
      "title": "Stored XSS via unescaped HTML attribute values in earmark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48591"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-12463",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12463"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-48821",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shaarli",
      "product": "Shaarli",
      "cwe": "CWE-79",
      "title": "Shaarli: DOM-based Cross-Site Scripting (XSS) in Thumbnail Synchronizer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48821"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-48991",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XianYuLauncher",
      "product": "XianYuLauncher",
      "cwe": "CWE-287",
      "title": "XianYuLauncher: Legacy Microsoft account OAuth sign-in flow lacks PKCE and state validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48991"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2024-35648",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Andy Moyle",
      "product": "Emergency Password Reset",
      "cwe": "CWE-352",
      "title": "WordPress Emergency Password Reset plugin <= 8.0 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-35648"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-11858",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quanos Solutions GmbH",
      "product": "SCHEMA ST4",
      "cwe": "CWE-862",
      "title": "Missing authorization in Quanos SCHEMA ST4 Client Update Service allows arbitrary file overwrite as SYSTEM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11858"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-28575",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00125,
      "epss_percentile": 0.02602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-400",
      "title": "In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible memory exhaustion attack due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28575"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-39199",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00125,
      "epss_percentile": 0.02595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Snes9X team",
      "product": "Snes9X",
      "cwe": "CWE-787",
      "title": "snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39199"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2024-47477",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02548,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex Manager",
      "cwe": "CWE-295",
      "title": "Dell PowerFlex Manager, versions prior to 4.5.1.1, contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leading to man-in-the-middle attack in tandem with DNS cache poisoning.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-47477"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-0068",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00123,
      "epss_percentile": 0.02513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-362",
      "title": "In createSessionInternal of PackageInstallerService.java, there is a possible method to remove a DPC app from a managed device without DO consent due to desync from persistence. This could lead to local escalation of privilege if a user can install a malicious app with no additional execution privileges needed. User interaction is needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0068"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-28615",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00123,
      "epss_percentile": 0.02511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-862",
      "title": "In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28615"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-0064",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00122,
      "epss_percentile": 0.02385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-400",
      "title": "In multiple places, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0064"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-0083",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00121,
      "epss_percentile": 0.02232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-362",
      "title": "In Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0083"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-48822",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shaarli",
      "product": "Shaarli",
      "cwe": "CWE-79",
      "title": "Shaarli has Stored Cross-Site Scripting (XSS) via Markdown Reference Links",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48822"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2024-34810",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Extend Themes",
      "product": "Skyline WP",
      "cwe": "CWE-352",
      "title": "WordPress Skyline WP theme <= 1.0.10 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-34810"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-1288",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "Revit",
      "cwe": "CWE-476",
      "title": "RFA File Parsing Vulnerability in Autodesk Revit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1288"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-28587",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00115,
      "epss_percentile": 0.01793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-862",
      "title": "In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28587"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-48823",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shaarli",
      "product": "Shaarli",
      "cwe": "CWE-79",
      "title": "Shaarli has Stored Cross-Site Scripting (XSS) via Tags Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48823"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-8049",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SignalRGB",
      "product": "SignalRGB kernel driver",
      "cwe": null,
      "title": "CVE-2026-8049",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8049"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-12449",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00109,
      "epss_percentile": 0.01403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12449"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-53870",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-276",
      "title": "Hermes Agent < 0.16.0 - Sensitive File Permission Vulnerability in Store Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53870"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-20246",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.01171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Umbrella Insights Virtual Appliance",
      "cwe": "CWE-269",
      "title": "Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20246"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-40641",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.01012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex",
      "cwe": "CWE-327",
      "title": "Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40641"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-32652",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00098,
      "epss_percentile": 0.00886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "AIOps",
      "cwe": "CWE-1392",
      "title": "Dell AIOps Collector versions prior to 1.18.3 contain a \"Use of Default Credentials\" vulnerability. A low privileged attacker with console access could potentially exploit this vulnerability to gain Filesystem access. This vulnerability only affects fresh installations of Collector versions earlier than 1.18.3. Systems that have been upgraded (either manually or automatically) to version 1.18.3 or later are not impacted, even if they were originally installed on an earlier version.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32652"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2025-48640",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00094,
      "epss_percentile": 0.00678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-862",
      "title": "In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48640"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-12567",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00091,
      "epss_percentile": 0.00554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Black Lantern Security",
      "product": "BBOT",
      "cwe": "CWE-59",
      "title": "Symlink-following arbitrary write via github_workflows module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12567"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2025-48643",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00084,
      "epss_percentile": 0.00325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-20",
      "title": "In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48643"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-0019",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0008,
      "epss_percentile": 0.00213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-269",
      "title": "In SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0019"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2025-48617",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00077,
      "epss_percentile": 0.00135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-862",
      "title": "In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-48617"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-50267",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00065,
      "epss_percentile": 0.0002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SteeltoeOSS",
      "product": "Steeltoe.Configuration.Abstractions",
      "cwe": "CWE-312",
      "title": "Steeltoe: TLS private keys written to /tmp with default permissions, never deleted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50267"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-0057",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00065,
      "epss_percentile": 0.0002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-862",
      "title": "In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0057"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-50268",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00047,
      "epss_percentile": 0,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SteeltoeOSS",
      "product": "Steeltoe.Configuration.Encryption",
      "cwe": "CWE-256",
      "title": "Steeltoe: OAEP setting silently selects PKCS#1 v1.5 padding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50268"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10641",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10641 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10850",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10850 (Plane). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47103",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47103 (fgmacedo python-statemachine). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47774",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47774 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48988",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48988 (markdown-it). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
