{
  "day": "2026-06-18",
  "boundary": "UTC calendar day",
  "published_count": 151,
  "by_severity": {
    "CRITICAL": 27,
    "HIGH": 58,
    "MEDIUM": 62,
    "LOW": 4
  },
  "kev_count": 1,
  "exploit_reference_count": 5,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-20253",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.96939,
      "epss_percentile": 0.99886,
      "kev": true,
      "kev_due_at": "2026-06-21",
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-306",
      "title": "Unauthenticated Arbitrary File Creation and Truncation in a PostgreSQL Sidecar Service Endpoint in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20253"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-38714",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02307,
      "epss_percentile": 0.81986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python configuration function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38714"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-38715",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02307,
      "epss_percentile": 0.81987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the log viewing function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38715"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-38716",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02307,
      "epss_percentile": 0.81987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the Python application export function. This vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38716"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-38717",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02307,
      "epss_percentile": 0.81986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a command injection vulnerability in the file upload function. The vulnerability allows remote attackers to execute arbitrary commands as root via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38717"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-8461",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01572,
      "epss_percentile": 0.73418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-787",
      "title": "Heap out-of-bounds write via odd slice_height in FFmpeg MagicYUV decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8461"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2025-27511",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.01074,
      "epss_percentile": 0.62289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "geoserver",
      "product": "org.geoserver.extension:gs-db2",
      "cwe": "CWE-74",
      "title": "GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-27511"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2025-15661",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0103,
      "epss_percentile": 0.60986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libssh2",
      "product": "libssh2",
      "cwe": "CWE-125",
      "title": "libssh2 - Heap Buffer Over-read via sftp_symlink() in sftp.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15661"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-40456",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00947,
      "epss_percentile": 0.584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LMS",
      "product": "LMS",
      "cwe": "CWE-78",
      "title": "OS Command Injection in LMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40456"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-49257",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0093,
      "epss_percentile": 0.5782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "startreedata",
      "product": "mcp-pinot",
      "cwe": "CWE-306",
      "title": "mcp-pinot: Unauthenticated tool invocation via default oauth_enabled=False + host 0.0.0.0 bind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49257"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-12046",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0092,
      "epss_percentile": 0.57483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgadmin.org",
      "product": "pgAdmin 4",
      "cwe": "CWE-306",
      "title": "pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection routes enables remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12046"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-56078",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00915,
      "epss_percentile": 0.57354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PraisonAI",
      "product": "PraisonAI",
      "cwe": "CWE-22",
      "title": "PraisonAI - Arbitrary File Read and Write via Path Traversal in MultiAgentMonitor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56078"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-40624",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00835,
      "epss_percentile": 0.54864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AVer",
      "product": "PTC500S",
      "cwe": "CWE-552",
      "title": "AVer PTC cameras Files or Directories Accessible to External Parties",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40624"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-47647",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00778,
      "epss_percentile": 0.5304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Dynamics 365",
      "cwe": "CWE-284",
      "title": "Dynamics 365 Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47647"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-54103",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00772,
      "epss_percentile": 0.52863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Government Accountability Office",
      "product": "Electronic Protest Docketing System (EPDS)",
      "cwe": "CWE-306",
      "title": "U.S. GAO EPDS and CBCA EDS unauthenticated password change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54103"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-56076",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00743,
      "epss_percentile": 0.51898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PraisonAI",
      "product": "PraisonAI",
      "cwe": "CWE-942",
      "title": "PraisonAI - Cross-Origin Agent Execution via Hardcoded Wildcard CORS and Missing Authentication on AGUI Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56076"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-54104",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00724,
      "epss_percentile": 0.51213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Government Accountability Office",
      "product": "Electronic Protest Docketing System (EPDS)",
      "cwe": "CWE-602",
      "title": "U.S. GAO EPDS and CBCA EDS client-based privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54104"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-12044",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00709,
      "epss_percentile": 0.50685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgadmin.org",
      "product": "pgAdmin 4",
      "cwe": "CWE-89",
      "title": "pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog templates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12044"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-56075",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00707,
      "epss_percentile": 0.50596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PraisonAI",
      "product": "PraisonAI",
      "cwe": "CWE-863",
      "title": "PraisonAI - Arbitrary Shell Command Execution via Hardcoded Approval Mode Override",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56075"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2025-53114",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00684,
      "epss_percentile": 0.49763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cometd",
      "product": "cometd",
      "cwe": "CWE-400",
      "title": "CometD has acknowledgement extension out of memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53114"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-54223",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00628,
      "epss_percentile": 0.47397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UBB Systems",
      "product": "UBB.threads",
      "cwe": "CWE-22",
      "title": "Remote Code Execution via arbitrary file read and write in UBB.threads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54223"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2025-52465",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00616,
      "epss_percentile": 0.46859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "geoserver",
      "product": "org.geoserver.web:gs-web-app",
      "cwe": "CWE-73",
      "title": "GeoServer has an arbitrary file write vulnerability in its Master Password Dump Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-52465"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-54390",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00604,
      "epss_percentile": 0.46264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JTL Software",
      "product": "JTL Shop",
      "cwe": "CWE-1336",
      "title": "JTL Shop < 5.7.2 Server-Side Template Injection via Smarty Renderer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54390"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-54130",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00578,
      "epss_percentile": 0.45069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Copilot",
      "cwe": "CWE-306",
      "title": "M365 Copilot Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54130"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-48937",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00573,
      "epss_percentile": 0.44833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodejs",
      "product": "node",
      "cwe": "CWE-400",
      "title": "A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported release lines: **Node.js 22** and **Node.js 24**.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48937"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-49248",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0057,
      "epss_percentile": 0.44689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "theonedev",
      "product": "onedev",
      "cwe": "CWE-61",
      "title": "OneDev: RCE through absolute-path symlink following allows low-privileged users to overwrite arbitrary server via TarUtils.untar",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49248"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-47633",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0057,
      "epss_percentile": 0.44663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Cost Management",
      "cwe": "CWE-200",
      "title": "Microsoft Cost Management Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47633"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-9860",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0056,
      "epss_percentile": 0.44162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vanyukov",
      "product": "Offload, AI & Optimize with Cloudflare Images",
      "cwe": "CWE-434",
      "title": "Offload, AI & Optimize with Cloudflare Images <= 1.10.2 - Authenticated (Author+) Remote Code Execution via 'api-key' / 'account-id' Parameters in cf_images_do_setup AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9860"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-56022",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00555,
      "epss_percentile": 0.43917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webmin",
      "product": "Webmin",
      "cwe": "CWE-308",
      "title": "Webmin MFA bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56022"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-8024",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00553,
      "epss_percentile": 0.43821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iba",
      "product": "ibaPDA",
      "cwe": "CWE-502",
      "title": "Deserialization vulnerability in ibaPDA and ibaDatCoordinator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8024"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-8100",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00549,
      "epss_percentile": 0.43583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Chef",
      "product": "Chef360",
      "cwe": "CWE-23",
      "title": "Impact A security issue has been identified in Chef 360 that could allow unauthorized access to protected API endpoints under specific conditions. This issue is due to improper handling of URL-encoded paths during request processing. In certain scenarios, an authenticated request may bypass standard access controls gaining additional privileges, potentially allowing access to API endpoints that are intended to be restricted to higher-permissioned roles. The impact is limited to environments where the affected request patterns can be triggered and depends on specific deployment configuration and access controls in place. Resolution The issue has been addressed through product updates that improve request validation and enforce strict path normalization before authorization checks. Customers are advised to update to the latest available version containing the fix, version 1.7.1 or later.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8100"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2025-32392",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00531,
      "epss_percentile": 0.42649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Significant-Gravitas",
      "product": "AutoGPT",
      "cwe": "CWE-400",
      "title": "AutoGPT has a DoS vulnerability in LoopVideoBlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32392"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-55205",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00524,
      "epss_percentile": 0.42228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nesquena",
      "product": "hermes-webui",
      "cwe": "CWE-770",
      "title": "Hermes WebUI < 0.51.468 - Resource Exhaustion via Unauthenticated OAuth Flow Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55205"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-54017",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00522,
      "epss_percentile": 0.42117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-22",
      "title": "Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54017"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-44688",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00507,
      "epss_percentile": 0.41184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Theia",
      "cwe": "CWE-829",
      "title": "In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its prompt context without distinguishing them from system instructions. An attacker could craft a malicious repository with adversarial directory or file names that, when analyzed by the AI agent, would cause the agent to follow attacker-controlled instructions (indirect prompt injection). Combined with other AI chat features available in untrusted workspaces, this enabled attack chains leading to data exfiltration via Markdown image rendering or arbitrary command execution via task definitions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44688"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-46580",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00507,
      "epss_percentile": 0.41184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Theia",
      "cwe": "CWE-829",
      "title": "In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were automatically loaded and could override or extend the AI agent's system prompts. An attacker could craft a malicious repository containing prompt template files that, when the workspace was opened in Theia, replaced the AI's system instructions with attacker-controlled content (indirect prompt injection). Combined with other AI chat features available in untrusted workspaces, this enabled attack chains leading to data exfiltration via Markdown image rendering or arbitrary command execution via task definitions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46580"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-54105",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00505,
      "epss_percentile": 0.41047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Government Accountability Office",
      "product": "Electronic Protest Docketing System (EPDS)",
      "cwe": "CWE-639",
      "title": "U.S. GAO EPDS and CBCA EDS user information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54105"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-56020",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00495,
      "epss_percentile": 0.4046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webmin",
      "product": "Webmin",
      "cwe": "CWE-290",
      "title": "Webmin HTTP header authentication bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56020"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-54106",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00491,
      "epss_percentile": 0.40252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Government Accountability Office",
      "product": "Electronic Protest Docketing System (EPDS)",
      "cwe": "CWE-940",
      "title": "U.S. GAO EPDS and CBCA EDS network access control bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54106"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-10736",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00489,
      "epss_percentile": 0.40145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Tutor LMS – eLearning and online course solution",
      "cwe": "CWE-89",
      "title": "Tutor LMS <= 3.9.11 - Authenticated (Administrator+) SQL Injection via 'data' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10736"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-55204",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00484,
      "epss_percentile": 0.39765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haproxy",
      "product": "haproxy",
      "cwe": "CWE-476",
      "title": "HAProxy - NULL Pointer Dereference in hpack_dht_insert Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55204"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-47846",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00483,
      "epss_percentile": 0.39705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bitnami",
      "product": "bitnami/cassandra",
      "cwe": "CWE-798",
      "title": "Bitnami Cassandra container images are affected by a retained default superuser vulnerability. When a custom administrator account is configured via the CASSANDRA_USER environment variable, the container initialization script creates the new superuser account but fails to drop the built-in cassandra account in certain scenarios. This leaves the default cassandra:cassandra superuser active as an unintended access path. Affected versions — Container image: 4.0.x prior to 4.0.20-photon-5-r7; 4.1.x prior to 4.1.11-photon-5-r7; 5.0.x prior to 5.0.8-photon-5-r4 / 5.0.8-debian-12-r3.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47846"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-12045",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00482,
      "epss_percentile": 0.39674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgadmin.org",
      "product": "pgAdmin 4",
      "cwe": "CWE-77",
      "title": "pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12045"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-56021",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00476,
      "epss_percentile": 0.3932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webmin",
      "product": "Webmin",
      "cwe": "CWE-185",
      "title": "Webmin information disclosure via regex pattern",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56021"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-11982",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00475,
      "epss_percentile": 0.39242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grav",
      "product": "grav-plugin-api",
      "cwe": "CWE-79",
      "title": "Stored XSS via missing XSS safety check in Admin2 Pages API partial validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11982"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-11360",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00474,
      "epss_percentile": 0.3917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "algolplus",
      "product": "Advanced Order Export For WooCommerce",
      "cwe": "CWE-89",
      "title": "Advanced Order Export For WooCommerce <= 4.0.10 - Authenticated (Shop Manager+) SQL Injection via 'sort_direction' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11360"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-49252",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0047,
      "epss_percentile": 0.38861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deepstreamIO",
      "product": "deepstream.io",
      "cwe": "CWE-1321",
      "title": "deepstream is vulnerable to prototype pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49252"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-38718",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00458,
      "epss_percentile": 0.38092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a buffer overflow vulnerability in the device registration function. This vulnerability could allow an attacker to cause a denial of service attack on the remote target device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38718"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-43994",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0045,
      "epss_percentile": 0.37581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coturn",
      "product": "coturn",
      "cwe": "CWE-120",
      "title": "Coturn: Stack buffer overflow in decode_oauth_token_gcm()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43994"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-56077",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.37228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PraisonAI",
      "product": "PraisonAI",
      "cwe": "CWE-668",
      "title": "PraisonAI - Information Disclosure via Shared MultiAgentLedger State",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56077"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-54419",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00443,
      "epss_percentile": 0.37015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "claudiopizzillo",
      "product": "PIAF-HMS",
      "cwe": "CWE-89",
      "title": "PIAF-HMS multiple unauthenticated SQL injection vulnerabilities via mysql_query",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54419"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2025-32422",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00428,
      "epss_percentile": 0.35865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Significant-Gravitas",
      "product": "AutoGPT",
      "cwe": "CWE-400",
      "title": "AutoGPT has a DoS vulnerability in FileStoreBlock with StepThroughItemsBlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32422"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2025-32424",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00428,
      "epss_percentile": 0.35865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Significant-Gravitas",
      "product": "AutoGPT",
      "cwe": "CWE-400",
      "title": "AutoGPT has a DoS vulnerability in ScreenshotWebPageBlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32424"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2025-32437",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00428,
      "epss_percentile": 0.35864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Significant-Gravitas",
      "product": "AutoGPT",
      "cwe": "CWE-400",
      "title": "AutoGPT has a DoS vulnerability in MediaDurationBlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32437"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-50141",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00427,
      "epss_percentile": 0.35832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "woodpecker-ci",
      "product": "woodpecker",
      "cwe": "CWE-290",
      "title": "Woodpecker gRPC agent_id metadata can be spoofed- cross-tenant agent impersonation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50141"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-56099",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00423,
      "epss_percentile": 0.35502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openbsd",
      "product": "src",
      "cwe": "CWE-125",
      "title": "OpenBSD mpls_do_error Kernel Stack Memory Disclosure via MPLS Input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56099"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-48716",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00422,
      "epss_percentile": 0.35383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "nanobot",
      "cwe": "CWE-22",
      "title": "nanobot: Path traversal via unsanitized WhatsApp document fileName enables arbitrary file write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48716"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-9692",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00419,
      "epss_percentile": 0.35139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HAYAJO",
      "product": "Mojolicious::Sessions::Storable",
      "cwe": "CWE-338",
      "title": "Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9692"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-44942",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00417,
      "epss_percentile": 0.34942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "libzypp",
      "cwe": "CWE-24",
      "title": "libzypp .repo files can have an optional path which can lead to path traversal attacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44942"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-32174",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure AI Bot Service",
      "cwe": "CWE-287",
      "title": "Azure Bot Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32174"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-44691",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00408,
      "epss_percentile": 0.34193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Theia",
      "cwe": "CWE-829",
      "title": "In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/tasks.json) could be executed without requiring workspace trust. An attacker could craft a malicious repository that, when cloned and opened in Theia, leads to execution of arbitrary commands with the user's privileges. In combination with AI chat features and a workspace .theia/settings.json that disabled tool confirmation, this could be triggered automatically by sending a message in the AI chat.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44691"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2025-10560",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00388,
      "epss_percentile": 0.32141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silver Leaf Technologies, Inc.",
      "product": "Worksnaps.net Worksnaps",
      "cwe": "CWE-798",
      "title": "Hardcoded cloud credentials in Worksnaps client application binaries expose production cloud resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-10560"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-49205",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00385,
      "epss_percentile": 0.31797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-862",
      "title": "phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49205"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2025-32436",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.31511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Significant-Gravitas",
      "product": "AutoGPT",
      "cwe": "CWE-400",
      "title": "AutoGPT has a DoS vulnerability in AddAudioToVideoBlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32436"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-12407",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.3089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oleksandrz",
      "product": "E2Pdf – Export Pdf Tool for WordPress",
      "cwe": "CWE-862",
      "title": "E2Pdf <= 1.32.26 - Missing Authorization to Authenticated (Custom+) Arbitrary Option Update / Privilege Escalation via 'screen_action' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12407"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-56012",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00357,
      "epss_percentile": 0.28981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "David Lingren",
      "product": "Media LIbrary Assistant",
      "cwe": "CWE-89",
      "title": "WordPress Media LIbrary Assistant plugin <= 3.35 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56012"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-42488",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-119",
      "title": "x86: mismatched mapcache metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42488"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-12093",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00352,
      "epss_percentile": 0.28353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpinsider-1",
      "product": "Simple Membership",
      "cwe": "CWE-862",
      "title": "Simple Membership <= 4.7.5 - Missing Authorization to Unauthenticated Arbitrary Member Account Deactivation via Forged Stripe 'charge.refunded' Webhook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12093"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-52866",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apollo Pharmacy",
      "product": "Blood Glucose Monitoring System (Model No. APG-01 BT)",
      "cwe": "CWE-862",
      "title": "Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52866"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-55203",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00347,
      "epss_percentile": 0.27898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haproxy",
      "product": "haproxy",
      "cwe": "CWE-190",
      "title": "HAProxy - Integer Overflow in FCGI Demux Record Length Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55203"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-11776",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10web",
      "product": "Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder",
      "cwe": "CWE-89",
      "title": "Form Maker by 10Web <= 1.15.43 - Authenticated (Adminsitrator+) SQL Injection via 'groupids' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11776"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-11777",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "10web",
      "product": "Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder",
      "cwe": "CWE-89",
      "title": "Form Maker by 10Web <= 1.15.43 - Authenticated (Administrator+) SQL Injection via 'name' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11777"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-12120",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.26156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fireplugins",
      "product": "FireBox Popups – Increase Sales and Grow Your Email List",
      "cwe": "CWE-200",
      "title": "FireBox Popups <= 3.1.7 - Unauthenticated Sensitive Information Exposure in 'form_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12120"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-46699",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.26018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "conda-forge",
      "product": "conda-smithy",
      "cwe": "CWE-284",
      "title": "conda-smithy vulnerable to misrouted repository invitation by conda-forge-webservices[bot] due to GitHub username takeover leading to unintended write access in conda-forge feedstock repository",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46699"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-12050",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.2507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgadmin.org",
      "product": "pgAdmin 4",
      "cwe": "CWE-89",
      "title": "pgAdmin 4: SQL injection in named restore point endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12050"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-11357",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.2512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stellarwp",
      "product": "Kadence Blocks — Page Builder Toolkit for Gutenberg Editor",
      "cwe": "CWE-200",
      "title": "Kadence Blocks <= 3.7.5 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor proData Localization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11357"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-55237",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Significant-Gravitas",
      "product": "AutoGPT",
      "cwe": "CWE-87",
      "title": "AutoGPT SignUp Page has DOM-Based XSS and Open Redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55237"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-8811",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SEPPmail AG",
      "product": "Secure Email Gateway",
      "cwe": "CWE-22",
      "title": "Path traversal in PDF generation module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8811"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-40457",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00318,
      "epss_percentile": 0.24692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LMS",
      "product": "LMS",
      "cwe": "CWE-79",
      "title": "Reflected XSS in LMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40457"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-47847",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bitnami",
      "product": "bitnami/mariadb-galera",
      "cwe": "CWE-798",
      "title": "Bitnami MariaDB Galera container images and Helm chart are affected by a hardcoded default credential vulnerability in the Galera replication health-check user. The MARIADB_REPLICATION_USER and MARIADB_REPLICATION_PASSWORD environment variables defaulted to monitor and monitor respectively. This user is granted REPLICATION CLIENT privileges from any host ('%'). The Bitnami Helm chart for MariaDB Galera did not expose parameters to configure this user's credentials, resulting in all chart deployments using this publicly known credential by default. Affected versions — Container image: 10.6.x prior to 10.6.27-photon-5-r0; 10.11.x prior to 10.11.17-photon-5-r1; 11.4.x prior to 11.4.12-photon-5-r0; 11.8.x prior to 11.8.7-photon-5-r1; 12.3.x prior to 12.3.2-photon-5-r0 / 12.3.2-debian-12-r0. Helm chart: prior to 18.3.0.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47847"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-22551",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.24022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Theia",
      "cwe": "CWE-201",
      "title": "In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP requests to arbitrary external URLs without restriction. Combined with prompt injection in a malicious workspace, an attacker could induce the AI agent to construct image URLs encoding sensitive information from the workspace or conversation context, exfiltrating it to attacker-controlled servers. The workspace trust enforcement introduced in v1.71.0 mitigates the documented attack chain by disabling AI features in untrusted workspaces.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22551"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-10029",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0031,
      "epss_percentile": 0.23807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eventkoi",
      "product": "Event Koi Lite – Events Calendar, Event Management, RSVP, and Tickets",
      "cwe": "CWE-862",
      "title": "Event Koi Lite <= 1.3.13.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via REST API Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10029"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-22674",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00309,
      "epss_percentile": 0.23652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hashgraph",
      "product": "guardian",
      "cwe": "CWE-79",
      "title": "Hashgraph Guardian Stored XSS via branding companyName field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22674"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-54222",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UBB Systems",
      "product": "UBB.threads",
      "cwe": "CWE-89",
      "title": "Blind SQL Injection in UBB.threads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54222"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-9158",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00304,
      "epss_percentile": 0.23091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse 4diac",
      "cwe": "CWE-416",
      "title": "In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subsequent commands to access freed memory (use-after-free).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9158"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-54219",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UBB Systems",
      "product": "UBB.threads",
      "cwe": "CWE-79",
      "title": "Stored XSS in UBB.threads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54219"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-54221",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UBB Systems",
      "product": "UBB.threads",
      "cwe": "CWE-79",
      "title": "Reflected XSS in UBB.threads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54221"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-45696",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcademySoftwareFoundation",
      "product": "openexr",
      "cwe": "CWE-122",
      "title": "OpenEXR HTJ2K decoder heap buffer over-read in ht_undo_impl() (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45696"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-11395",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mariovalney",
      "product": "CF7 to Webhook",
      "cwe": "CWE-918",
      "title": "CF7 to Webhook <= 5.0.0 - Unauthenticated Server-Side Request Forgery via CF7 Field Placeholder in Webhook URL Host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11395"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2025-58175",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "geoserver",
      "product": "org.geoserver.web:gs-web-app",
      "cwe": "CWE-20",
      "title": "GeoServer has a Server-Side Request Forgery (SSRF) Vulnerability in its XML Entity Resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58175"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-55740",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00282,
      "epss_percentile": 0.20724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nur-Alam39",
      "product": "bus-ticket",
      "cwe": "CWE-89",
      "title": "SQL Injection in Nur-Alam39 bus-ticket bus_info.php via busid parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55740"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-12111",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codepeople",
      "product": "Appointment Booking Calendar",
      "cwe": "CWE-200",
      "title": "Appointment Booking Calendar <= 1.4.01 - Authenticated (Contributor+) Sensitive Information Exposure via 'id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12111"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-54224",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.1967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UBB Systems",
      "product": "UBB.threads",
      "cwe": "CWE-405",
      "title": "Denial of Service in UBB.threads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54224"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-12102",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00272,
      "epss_percentile": 0.19627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stiofansisland",
      "product": "UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP",
      "cwe": "CWE-639",
      "title": "UsersWP <= 1.2.63 - Insecure Direct Object Reference to Authenticated (Editor+) Arbitrary User Avatar/Banner Reset via 'user_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12102"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-8668",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00271,
      "epss_percentile": 0.19409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Chef",
      "product": "Chef360",
      "cwe": "CWE-523",
      "title": "Hardcoded credentials in embedded content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8668"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-11358",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeisle",
      "product": "Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More",
      "cwe": "CWE-79",
      "title": "Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More <= 3.0.6 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'menu-item-icon' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11358"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-10623",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pressprimer",
      "product": "PressPrimer Quiz – AI Quiz Maker, Exam Builder & LMS Assessment Plugin",
      "cwe": "CWE-639",
      "title": "PressPrimer Quiz <= 2.3.0 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Modification via 'quiz_id', 'item_id', and 'rule_id' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10623"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-12527",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shenzhen Liandian Communication Technology LTD",
      "product": "V380 IP Camera / AppFHE1_V1.0.6.0",
      "cwe": "CWE-306",
      "title": "A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V380 IP Camera firmware AppFHE1_V1.0.6.020230803 enables unauthenticated network actors to bypass the device’s credential-enforced live-view workflow and directly retrieve real-time video stream data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12527"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-10023",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dokaninc",
      "product": "Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy",
      "cwe": "CWE-639",
      "title": "Dokan: AI Powered WooCommerce Multivendor Marketplace Solution <= 5.0.3 - Insecure Direct Object Reference to Authenticated (Custom+) Arbitrary Order Modification via Multiple AJAX Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10023"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-43915",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coturn",
      "product": "coturn",
      "cwe": "CWE-79",
      "title": "Coturn: Stored Cross-Site Scripting (XSS) in web-admin interface via TURN username",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43915"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-48617",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": 0.0024,
      "epss_percentile": 0.15411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodejs",
      "product": "node",
      "cwe": "CWE-284",
      "title": "A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48617"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-9199",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "equalizedigital",
      "product": "Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance",
      "cwe": "CWE-862",
      "title": "Equalize Digital Accessibility Checker <= 1.42.1 - Missing Authorization to Authenticated (Author+) Arbitrary Accessibility Issue Modification via 'largeBatch' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9199"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-11784",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "optimole",
      "product": "Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization",
      "cwe": "CWE-352",
      "title": "Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization <= 4.2.6 - Cross-Site Request Forgery via 'optml_replace_file' AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11784"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-49454",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00226,
      "epss_percentile": 0.13552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "szTheory",
      "product": "relyra",
      "cwe": "CWE-287",
      "title": "Relyra SAML SignatureValue not cryptographically verified -> authentication bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49454"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-12049",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgadmin.org",
      "product": "pgAdmin 4",
      "cwe": "CWE-601",
      "title": "pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated 'next' parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12049"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-40455",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00216,
      "epss_percentile": 0.12298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LMS",
      "product": "LMS",
      "cwe": "CWE-89",
      "title": "SQL Injection in LMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40455"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-9815",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MagicForm",
      "cwe": null,
      "title": "MagicForm <= 0.1.3 - Unauthenticated Arbitrary File Upload to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9815"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-11791",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11",
      "cwe": "CWE-416",
      "title": "389-ds-base: 389-ds-base: use-after-free in schema reload via attr_syntax_swap_ht()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11791"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-12137",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phppoet",
      "product": "SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager",
      "cwe": "CWE-79",
      "title": "SysBasics Customize My Account for WooCommerce <= 4.3.6 - Reflected Cross-Site Scripting via 'tab' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12137"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-12048",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0021,
      "epss_percentile": 0.11529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgadmin.org",
      "product": "pgAdmin 4",
      "cwe": "CWE-79",
      "title": "pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12048"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-50034",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.11384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apollo Pharmacy",
      "product": "Blood Glucose Monitoring System (Model No. APG-01 BT)",
      "cwe": "CWE-319",
      "title": "Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT Cleartext Transmission of Sensitive Information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50034"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-11402",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.10941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bplugins",
      "product": "Services Section Block – Showcase Service Details in Grid or Columns",
      "cwe": "CWE-79",
      "title": "Services Section Block <= 1.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11402"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-42490",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-667",
      "title": "domctl lock open to abuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42490"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-44663",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcademySoftwareFoundation",
      "product": "openexr",
      "cwe": "CWE-190",
      "title": "OpenEXR: Integer overflow in the HTJ2K decoder leads to heap-buffer-overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44663"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-2021",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "contrid",
      "product": "Slideshow Gallery LITE",
      "cwe": "CWE-79",
      "title": "Slideshow Gallery LITE <= 1.8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'alwaysauto' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2021"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-25865",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yandex",
      "product": "Punto Switcher",
      "cwe": "CWE-428",
      "title": "Punto Switcher 4.5.0.583 Unquoted Search Path via WinExec",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25865"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-12098",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "blubrry",
      "product": "PowerPress Podcasting plugin by Blubrry",
      "cwe": "CWE-79",
      "title": "PowerPress Podcasting plugin by Blubrry <= 11.16.8 - Authenticated (Author+) Stored Cross-Site Scripting via 'embed' Episode Meta Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12098"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-12136",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phppoet",
      "product": "SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager",
      "cwe": "CWE-79",
      "title": "SysBasics Customize My Account for WooCommerce <= 4.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12136"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-54220",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00187,
      "epss_percentile": 0.08684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UBB Systems",
      "product": "UBB.threads",
      "cwe": "CWE-352",
      "title": "Cross-Site Request Forgery in UBB.threads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54220"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-11718",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00185,
      "epss_percentile": 0.08385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "MCP Toolbox for Databases (googleapis/mcp-toolbox)",
      "cwe": "CWE-287",
      "title": "An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When the toolbox validates an opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), it decodes the response into an introspectResp struct. However, the subsequent claim-checking logic (validateClaims) evaluates the issuer condition as if a.issuer != \"\" && iss != \"\". If the external OAuth provider's introspection response omits the optional iss (issuer) field completely, the variable iss defaults to an empty string. This causes the conditional block to evaluate to false and be skipped silently. Consequently, the application accepts tokens issued by unauthorized or unintended third-party identity providers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11718"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-8039",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.08046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dijitul",
      "product": "Fancy Testimonials",
      "cwe": "CWE-79",
      "title": "Fancy Testimonials <= 1.0 - Authenticated (Author+) Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8039"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-11717",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00176,
      "epss_percentile": 0.07485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "MCP Toolbox for Databases (googleapis/mcp-toolbox)",
      "cwe": "CWE-287",
      "title": "An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googleapis/mcp-toolbox. When verifying an unparsed opaque token via an OAuth 2.0 introspection endpoint (RFC 7662), the toolbox decodes the response into an introspectResp struct where the Active field is declared as a pointer to a boolean (*bool). The code only explicitly rejects a token if the response contains a populated active field set to false (if introspectResp.Active != nil && !*introspectResp.Active). If an introspection endpoint responds with a payload that completely omits the mandatory active key, the internal variable remains nil, causing the conditional check to short-circuit. As a result, Toolbox accepts authorization tokens missing the \"active\" field, granting access to protected tools and underlying data sources.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11717"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-56024",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saad Iqbal",
      "product": "WP EasyPay",
      "cwe": "CWE-352",
      "title": "WordPress WP EasyPay plugin <= 4.5.0 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56024"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-48980",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-454",
      "title": "pam_usb: getenv() used in PAM context allows environment variable injection into local-check logic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48980"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-55746",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cotonti",
      "product": "Cotonti",
      "cwe": "CWE-79",
      "title": "Cotonti stored XSS via PFS folder title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55746"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-47833",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloud Foundry Foundation",
      "product": "bpm-release",
      "cwe": "CWE-59",
      "title": "setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A compromised process inside a bpm container can cause root to chown an arbitrary host file to vcap and append bpm JSON log lines to it. The chown alone lets the attacker take ownership of /etc/shadow and read every password hash on the host via the read-only /etc bind mount. This is a container-to-host confidentiality break affecting every bpm-managed job. Affected versions: bpm-release, all versions prior to v1.4.30.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47833"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-56074",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PraisonAI",
      "product": "PraisonAI",
      "cwe": "CWE-863",
      "title": "PraisonAI - Tool Approval Cache Bypass via Coarse-Grained Caching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56074"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-48985",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-476",
      "title": "pam_usb: NULL Dereference Crash in pusb_is_loginctl_local when loginctl Returns Empty Remote Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48985"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-12505",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.05365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-250",
      "title": "Cifs-utils: local privilege escalation via forged cifs.spnego key description in cifs.upcall",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12505"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-48981",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-611",
      "title": "pam_usb: xmlReadFile flags=0 permits XXE network entity fetching in conf.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48981"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-55742",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00151,
      "epss_percentile": 0.04781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cotonti",
      "product": "Cotonti",
      "cwe": "CWE-352",
      "title": "Cotonti CSRF in admin.rights.php allows privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55742"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-55392",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.04773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nilfs-dev",
      "product": "nilfs-utils",
      "cwe": "CWE-1284",
      "title": "NILFS utilities - Undefined Behavior and Out-of-Memory via Unvalidated s_log_block_size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55392"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-55741",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cotonti",
      "product": "Cotonti",
      "cwe": "CWE-352",
      "title": "Cotonti CSRF in admin.config.php allows unauthorized configuration changes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55741"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-55744",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cotonti",
      "product": "Cotonti",
      "cwe": "CWE-352",
      "title": "Cotonti CSRF in PFS allows forced arbitrary file upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55744"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-12039",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Docker",
      "product": "Docker Sandboxes",
      "cwe": "CWE-923",
      "title": "Docker Sandboxes network egress allowlist bypass via unfiltered DNS resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12039"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-48984",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-14",
      "title": "pam_usb: xfree() does not call explicit_bzero — sensitive cryptographic material may linger in freed heap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48984"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-11719",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "MCP Toolbox for Databases (googleapis/mcp-toolbox)",
      "cwe": "CWE-862",
      "title": "An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement across older protocol handlers. While the 2025-11-25 protocol version handler correctly enforces per-tool restrictions defined by scopesRequired, older supported protocol versions (2025-06-18, 2025-03-26, and 2024-11-05) omit this check. An authenticated client with low-privilege tokens (e.g., read) can bypass the intended per-tool scope restrictions and execute high-privilege tools (e.g., admin) simply by specifying an older protocol version in the MCP-Protocol-Version header, or by omitting the header entirely (which causes the server to default to the vulnerable 2024-11-05 handler).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11719"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-48986",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-835",
      "title": "pam_usb: Infinite loop DoS in process-tree walk when parent process exits during authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48986"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-12539",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Docker",
      "product": "Docker Sandboxes",
      "cwe": "CWE-665",
      "title": "Docker Sandboxes ICMP egress restriction bypass after daemon restart",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12539"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-28573",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00138,
      "epss_percentile": 0.03683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Android",
      "cwe": "CWE-862",
      "title": "In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28573"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-56007",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OceanWP",
      "product": "Ocean Product Sharing",
      "cwe": "CWE-79",
      "title": "WordPress Ocean Product Sharing plugin <= 2.2.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56007"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-50643",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rui314",
      "product": "8cc",
      "cwe": "CWE-125",
      "title": "Out‑of‑Bounds Read in 8cc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50643"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-12047",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgadmin.org",
      "product": "pgAdmin 4",
      "cwe": "CWE-79",
      "title": "pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via unsanitised SDK exception text",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12047"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-56009",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bricksable",
      "product": "Bricksable for Bricks Builder",
      "cwe": "CWE-79",
      "title": "WordPress Bricksable for Bricks Builder plugin <= 1.6.83 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56009"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-12390",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AzeoTech",
      "product": "DAQFactory",
      "cwe": "CWE-843",
      "title": "Access of resource using incompatible type ('type confusion') in AzeoTech DAQFactory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12390"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-48982",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.01989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-362",
      "title": "pam_usb: Missing O_EXCL on pad temp file creation allows concurrent update race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48982"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-48983",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mcdope",
      "product": "pam_usb",
      "cwe": "CWE-367",
      "title": "pam_usb: TOCTOU race condition in pad directory creation allows symlink substitution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48983"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-11958",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00102,
      "epss_percentile": 0.0105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ANSSI",
      "product": "DFIR-ORC",
      "cwe": "CWE-427",
      "title": "Local privilege escalation in ANSSI’s DFIR-ORC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11958"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-55745",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00097,
      "epss_percentile": 0.0085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cotonti",
      "product": "Cotonti",
      "cwe": "CWE-352",
      "title": "Cotonti CSRF in PFS folder edit allows unauthorized folder modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55745"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-42487",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00095,
      "epss_percentile": 0.00766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-362",
      "title": "x86 HVM I/O port list traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42487"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-42489",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00078,
      "epss_percentile": 0.00159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-667",
      "title": "domctl lock open to abuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42489"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43994",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43994 (coturn). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44663",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44663 (AcademySoftwareFoundation openexr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45696",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45696 (AcademySoftwareFoundation openexr). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
