{
  "day": "2026-06-19",
  "boundary": "UTC calendar day",
  "published_count": 194,
  "by_severity": {
    "CRITICAL": 20,
    "HIGH": 115,
    "MEDIUM": 51,
    "LOW": 8
  },
  "kev_count": 0,
  "exploit_reference_count": 16,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-8713",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02669,
      "epss_percentile": 0.84549,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themefusion",
      "product": "Avada (Fusion) Builder",
      "cwe": "CWE-22",
      "title": "Avada (Fusion) Builder <= 3.15.3 - Unauthenticated Arbitrary File Deletion via Form Entry Value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8713"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-12104",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01316,
      "epss_percentile": 0.68485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SIMA GmbH",
      "product": "Bondix Server",
      "cwe": "CWE-78",
      "title": "Authenticated OS Command Injection in Bondix",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12104"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-44939",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01279,
      "epss_percentile": 0.67687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-95",
      "title": "Command injection through unsanitized YAML parameter in Rancher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44939"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-49336",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01178,
      "epss_percentile": 0.65148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "kiota-typescript",
      "cwe": "CWE-178",
      "title": "@microsoft/kiota-http-fetchlibrary: Bearer token and Cookie leak across origin on redirect due to case-mismatched scrub in fetchRequestAdapter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49336"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2025-62821",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01052,
      "epss_percentile": 0.61658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-125",
      "title": "Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the reported data size as 0. This causes a caller to make a 1-byte allocation. Later, CopyPixels computes copy_size = stride * abs(roi_height) but does not check the source buffer length before a memmove call.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62821"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-49286",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0095,
      "epss_percentile": 0.58483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pontedilana",
      "product": "php-weasyprint",
      "cwe": "CWE-502",
      "title": "PhpWeasyPrint vulnerable to PHAR deserialization via output filename (CVE-2023-28115 case-insensitive bypass)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49286"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-7515",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00942,
      "epss_percentile": 0.58221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "betterdocs",
      "product": "BetterDocs Pro",
      "cwe": "CWE-98",
      "title": "BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7515"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2019-25758",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00892,
      "epss_percentile": 0.56639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wdmtech",
      "product": "vBizz",
      "cwe": "CWE-434",
      "title": "Joomla! Component vBizz 1.0.7 Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25758"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-49290",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00833,
      "epss_percentile": 0.54821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "byrongamatos",
      "product": "slopsmith",
      "cwe": "CWE-22",
      "title": "Slopsmith has path traversal in archive extractors that allows arbitrary file write → potential RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49290"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-47645",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00758,
      "epss_percentile": 0.52368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Copilot",
      "cwe": "CWE-601",
      "title": "Microsoft 365 Copilot's Business Chat Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47645"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-51846",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00693,
      "epss_percentile": 0.5011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to remote arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51846"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-48787",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0069,
      "epss_percentile": 0.49977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flipped-aurora",
      "product": "gin-vue-admin",
      "cwe": "CWE-78",
      "title": "gin-vue-admin vulnerable to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48787"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-48582",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00689,
      "epss_percentile": 0.4995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Online",
      "cwe": "CWE-862",
      "title": "Microsoft Exchange Online Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48582"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-54414",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00664,
      "epss_percentile": 0.48989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "error311",
      "product": "FileRise",
      "cwe": "CWE-22",
      "title": "FileRise shared-folder upload path traversal allows arbitrary file write and admin takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54414"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-3640",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00644,
      "epss_percentile": 0.48112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strablengineering",
      "product": "STRABL – A checkout solution",
      "cwe": "CWE-862",
      "title": "STRABL <= 4.5 - Unauthenticated Arbitrary Webhook Creation via REST API Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3640"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-8805",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00637,
      "epss_percentile": 0.47803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mitsubishi Electric Corporation",
      "product": "Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP Module FX5-EIP",
      "cwe": "CWE-190",
      "title": "Denial-of-service (DoS) vulnerability in MELSEC iQ-F Series EtherNet/IP module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8805"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-8806",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00637,
      "epss_percentile": 0.47803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mitsubishi Electric Corporation",
      "product": "Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP",
      "cwe": "CWE-440",
      "title": "Denial-of-service (DoS) vulnerability in MELSEC iQ-F Series FX5-ENET/IP Ethernet module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8806"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-49345",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00634,
      "epss_percentile": 0.47677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sourcentis",
      "product": "mercator",
      "cwe": "CWE-918",
      "title": "Mercator CVE Configuration Vulnerable to Server-Side Request Forgery (SSRF)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49345"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-11551",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00625,
      "epss_percentile": 0.47264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmudev",
      "product": "Branda – White Label & Branding, Free Login Page Customizer",
      "cwe": "CWE-640",
      "title": "Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11551"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-50242",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.006,
      "epss_percentile": 0.46091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "Hub",
      "cwe": "CWE-306",
      "title": "In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authentication bypass via direct database access leading to administrative access was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50242"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-7547",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00589,
      "epss_percentile": 0.45591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "teamwsa",
      "product": "Woosa – Marktplaats for WooCommerce",
      "cwe": "CWE-22",
      "title": "Woosa <= 2.0.5 - Authenticated (Administrator+) Arbitrary File Read via 'log_file' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7547"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-10034",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00579,
      "epss_percentile": 0.45096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "legalweb",
      "product": "WP DSGVO Tools (GDPR)",
      "cwe": "CWE-862",
      "title": "WP DSGVO Tools (GDPR) <= 3.1.39 - Missing Authorization to Unauthenticated Sensitive Personal Data Disclosure via subject-access-request AJAX Endpoint (process_now/is_ajax Parameters)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10034"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-56081",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00574,
      "epss_percentile": 0.44892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo",
      "cwe": "CWE-640",
      "title": "Cap-go - Account Lockout via 2FA Misconfiguration on Unverified Email",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56081"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-56142",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00573,
      "epss_percentile": 0.44821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "Hub",
      "cwe": "CWE-915",
      "title": "In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privilege escalation by attaching authentication details to accounts was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56142"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-49357",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00564,
      "epss_percentile": 0.44413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dtwang",
      "product": "line-desktop-mcp",
      "cwe": "CWE-306",
      "title": "Streamable HTTP mode exposes LINE Desktop read/send tools without MCP authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49357"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-45480",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00562,
      "epss_percentile": 0.44259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Active Directory",
      "cwe": "CWE-287",
      "title": "Azure Active Directory Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45480"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-48137",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00561,
      "epss_percentile": 0.44197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NI",
      "product": "grpc-device",
      "cwe": "CWE-822",
      "title": "Untrusted pointer dereference in NI grpc-device sideband streaming API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48137"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2019-25760",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00542,
      "epss_percentile": 0.4321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomtech",
      "product": "Easy Shop",
      "cwe": "CWE-98",
      "title": "Joomla! Component Easy Shop 1.2.3 Local File Inclusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25760"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-56080",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00542,
      "epss_percentile": 0.43212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo",
      "cwe": "CWE-287",
      "title": "Cap-go - Authentication Logic Flaw in Enforce Password Policy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56080"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2019-25762",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0054,
      "epss_percentile": 0.43131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomboost",
      "product": "JoomProject",
      "cwe": "CWE-359",
      "title": "Joomla! Component JoomProject 1.1.3.2 Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25762"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2023-54357",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0054,
      "epss_percentile": 0.43131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Artio",
      "product": "Joomla! com_booking component",
      "cwe": "CWE-203",
      "title": "Joomla com_booking 2.4.9 Information Disclosure via Account Enumeration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-54357"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-32208",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00523,
      "epss_percentile": 0.42211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-79",
      "title": "Microsoft Entra ID Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32208"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-56141",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00522,
      "epss_percentile": 0.42109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "Hub",
      "cwe": "CWE-338",
      "title": "In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account takeover via predictable restore codes was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56141"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-50519",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00514,
      "epss_percentile": 0.41576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "GitHub Copilot Chat",
      "cwe": "CWE-1188",
      "title": "Microsoft Visual Studio Code CoPilot Chat Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50519"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-56138",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0051,
      "epss_percentile": 0.41358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ail-project",
      "product": "ail-framework",
      "cwe": "CWE-22",
      "title": "Authenticated Path Traversal in AIL framework /objects/item/diff Allows Reading Gzip-Compressed Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56138"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-12644",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00507,
      "epss_percentile": 0.41157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "ts-deepmerge",
      "cwe": "CWE-248",
      "title": "Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of built-in Object.prototype methods (such as toString, valueOf). When user-controlled input contains these keys with non-function values, the resulting merged object becomes broken — any string context operation throws a TypeError, crashing the application.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12644"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-48584",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.005,
      "epss_percentile": 0.4079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Synapse",
      "cwe": "CWE-250",
      "title": "Microsoft Azure Synapse Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48584"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-11989",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00496,
      "epss_percentile": 0.40551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bitpressadmin",
      "product": "Bit integrations – Form Integration, Webhook, Spreadsheets, CRM, LMS & Email Automation",
      "cwe": "CWE-918",
      "title": "Bit integrations <= 2.8.7 - Unauthenticated Server-Side Request Forgery via Form Field Upload Mapping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11989"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-48138",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00488,
      "epss_percentile": 0.40049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NI",
      "product": "grpc-device",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read vulnerability in the NI grpc-device streaming API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48138"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-48139",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00488,
      "epss_percentile": 0.40049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NI",
      "product": "grpc-device",
      "cwe": "CWE-476",
      "title": "NULL pointer dereference vulnerability in NI grpc-device data moniker service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48139"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-49291",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00488,
      "epss_percentile": 0.40053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "doobidoo",
      "product": "mcp-memory-service",
      "cwe": "CWE-862",
      "title": "mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49291"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-48773",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00466,
      "epss_percentile": 0.38623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sysown",
      "product": "proxysql",
      "cwe": "CWE-787",
      "title": "ProxySQL pre-auth heap overflow in MySQL and PostgreSQL first-packet handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48773"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-50559",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00463,
      "epss_percentile": 0.3843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quarkusio",
      "product": "quarkus",
      "cwe": "CWE-287",
      "title": "Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50559"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2025-7737",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0046,
      "epss_percentile": 0.38241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi",
      "product": "Hitachi Virtual Storage Platform E990, E1090, E1090H",
      "cwe": "CWE-770",
      "title": "DoS Vulnerability in 10G iSCSI Interface of Hitachi Virtual Storage Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7737"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-11576",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0046,
      "epss_percentile": 0.38242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse ThreadX - NetX Duo",
      "cwe": "CWE-459",
      "title": "The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file was never successfully opened. Multiple error branches jump to the shared cleanup label before any file open operation has occurred, causing fx_file_close() to operate on an uninitialized file handle, leading to undefined behavior, double-close issues, or memory corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11576"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-49287",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00457,
      "epss_percentile": 0.3807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "statamic",
      "product": "cms",
      "cwe": "CWE-470",
      "title": "Statamic CMS vulnerable to unsafe method invocation via collection sorting allows data destruction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49287"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-6798",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00455,
      "epss_percentile": 0.37913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "2download",
      "product": "2Download Connector for 2DL Hosted Checkout",
      "cwe": "CWE-862",
      "title": "2Download Connector for 2DL Hosted Checkout <= 0.1.5 - Missing Authorization to Unauthenticated Sensitive Customer Subscription Data Exposure via 'ToDownload_email' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6798"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-47203",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00453,
      "epss_percentile": 0.37751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "authelia",
      "product": "authelia",
      "cwe": "CWE-178",
      "title": "Authelia Missing Username Canonicalization in Basic Auth (LDAP)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47203"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-56211",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00452,
      "epss_percentile": 0.37701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux AI 3.3 for RHEL 9",
      "cwe": "CWE-787",
      "title": "Libaom: libaom: remote code execution via svc layer context handling with attacker-controlled frames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56211"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2017-20253",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gegabyte",
      "product": "My Projects",
      "cwe": "CWE-89",
      "title": "Joomla! Component My Projects 2.0 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20253"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2017-20254",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gegabyte",
      "product": "User Bench",
      "cwe": "CWE-89",
      "title": "Joomla! Component User Bench 1.0 SQL Injection via userid",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20254"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2017-20255",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joombooking",
      "product": "JB Visa",
      "cwe": "CWE-89",
      "title": "Joomla! Component JB Visa 1.0 SQL Injection via visatype",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20255"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2017-20256",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomplace",
      "product": "Survey Force Deluxe",
      "cwe": "CWE-89",
      "title": "Joomla Survey Force Deluxe 3.2.4 SQL Injection via invite Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20256"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2017-20257",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomplace",
      "product": "Quiz Deluxe",
      "cwe": "CWE-89",
      "title": "Joomla! Component Quiz Deluxe 3.7.4 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20257"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2017-20258",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.3749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Extro",
      "product": "RPC",
      "cwe": "CWE-89",
      "title": "Joomla! Component RPC Responsive Portfolio 1.6.1 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20258"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2017-20259",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomlashack",
      "product": "OSDownloads",
      "cwe": "CWE-89",
      "title": "Joomla OSDownloads 1.7.4 SQL Injection via item view",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20259"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2017-20260",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Weborange",
      "product": "Price Alert",
      "cwe": "CWE-89",
      "title": "Joomla! Component Price Alert 3.0.2 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20260"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2017-20261",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Weborange",
      "product": "Bargain Product VM3",
      "cwe": "CWE-89",
      "title": "Joomla! Component Bargain Product VM3 1.0 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20261"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2017-20262",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "Ajax Quiz",
      "cwe": "CWE-89",
      "title": "Joomla! Component Ajax Quiz 1.8 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20262"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2017-20263",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.3749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Focalpointx",
      "product": "FocalPoint Pro / Free",
      "cwe": "CWE-89",
      "title": "Joomla! FocalPoint Pro Free 1.2.3 SQL Injection via location",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20263"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2017-20266",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.3749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomshaper",
      "product": "SP Movie Database",
      "cwe": "CWE-89",
      "title": "Joomla SP Movie Database 1.3 SQL Injection via searchword",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20266"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2017-20267",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomlathat",
      "product": "Calendar Planner",
      "cwe": "CWE-89",
      "title": "Joomla! Component Calendar Planner 1.0.1 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20267"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2017-20268",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zcontent",
      "product": "Zap Calendar Lite",
      "cwe": "CWE-89",
      "title": "Joomla! Component Zap Calendar Lite 4.3.4 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20268"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2017-20269",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Terrywcarter",
      "product": "KissGallery",
      "cwe": "CWE-89",
      "title": "Joomla! Component KissGallery 1.0.0 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20269"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2017-20270",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Raindropsinfotech",
      "product": "Twitch Tv",
      "cwe": "CWE-89",
      "title": "Joomla! Component Twitch Tv 1.1 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20270"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2019-25748",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cmsjunkie",
      "product": "JHotelReservation",
      "cwe": "CWE-89",
      "title": "Joomla JHotelReservation 6.0.7 SQL Injection via search-hotels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25748"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2019-25750",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cmsjunkie",
      "product": "MultipleHotelReservation",
      "cwe": "CWE-89",
      "title": "Joomla J-MultipleHotelReservation 6.0.7 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25750"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2019-25751",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cmsjunkie",
      "product": "ClassifiedsManager",
      "cwe": "CWE-89",
      "title": "Joomla J-ClassifiedsManager 3.0.5 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25751"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2019-25752",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cmsjunkie",
      "product": "J-BusinessDirectory",
      "cwe": "CWE-89",
      "title": "Joomla! Component J-BusinessDirectory 4.9.7 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25752"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2019-25753",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wdmtech",
      "product": "VMap",
      "cwe": "CWE-89",
      "title": "Joomla! Component VMap 1.9.6 SQL Injection via loadmarker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25753"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2019-25754",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wdmtech",
      "product": "vRestaurant",
      "cwe": "CWE-89",
      "title": "Joomla vRestaurant 1.9.4 SQL Injection via menu-listing-layout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25754"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2019-25755",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wdmtech",
      "product": "vReview",
      "cwe": "CWE-89",
      "title": "Joomla vReview 1.9.11 SQL Injection via editReview",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25755"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2019-25756",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00449,
      "epss_percentile": 0.37496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wdmtech",
      "product": "vAccount",
      "cwe": "CWE-89",
      "title": "Joomla! Component vAccount 2.0.2 SQL Injection via vaccount-dashboard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25756"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-48140",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.3723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NI",
      "product": "grpc-device",
      "cwe": "CWE-704",
      "title": "Unchecked enum cast vulnerability in NI grpc-device in BeginSidebandStream",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48140"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-48129",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00445,
      "epss_percentile": 0.37204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kestra-io",
      "product": "kestra",
      "cwe": "CWE-22",
      "title": "Kestra task inputFiles accepts traversal filenames for worker file writes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48129"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-9013",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00442,
      "epss_percentile": 0.3696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rocklobsterinc",
      "product": "Bogo",
      "cwe": "CWE-862",
      "title": "Bogo <= 3.9.1 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9013"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-51843",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00438,
      "epss_percentile": 0.36664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51843"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-51844",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00438,
      "epss_percentile": 0.36664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51844"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-51845",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00438,
      "epss_percentile": 0.36664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51845"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-9142",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00434,
      "epss_percentile": 0.36334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NI",
      "product": "grpc-device",
      "cwe": "CWE-306",
      "title": "Insecure Default Credentials vulnerability in NI grpc-device when TLS configuration is not present",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9142"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2017-20252",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00434,
      "epss_percentile": 0.36349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextgeneditor",
      "product": "NextGen Editor",
      "cwe": "CWE-89",
      "title": "Joomla NextGen Editor 2.1.0 SQL Injection via plname Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20252"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2017-20281",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00434,
      "epss_percentile": 0.36349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomlaboat",
      "product": "Extra Search",
      "cwe": "CWE-89",
      "title": "Joomla! Component Extra Search 2.2.8 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20281"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2017-20282",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00434,
      "epss_percentile": 0.36349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Soft-Php",
      "product": "jCart for OpenCart",
      "cwe": "CWE-89",
      "title": "Joomla! Component jCart for OpenCart 2.0 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20282"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-47341",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0043,
      "epss_percentile": 0.36044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-294",
      "title": "Apache APISIX: Session replay issue in hmac-auth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47341"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-49340",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00428,
      "epss_percentile": 0.35838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sentriz",
      "product": "gonic",
      "cwe": "CWE-22",
      "title": "gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49340"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-39999",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00424,
      "epss_percentile": 0.35578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-290",
      "title": "Apache APISIX: JWT Algorithm Confusion allows authentication bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39999"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-49359",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00422,
      "epss_percentile": 0.35435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pontedilana",
      "product": "php-weasyprint",
      "cwe": "CWE-918",
      "title": "PhpWeasyPrint vulnerable to SSRF and local file disclosure via the attachment option",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49359"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2017-20277",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00412,
      "epss_percentile": 0.34541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomboost",
      "product": "Joomla JoomRecipe",
      "cwe": "CWE-89",
      "title": "Joomla JoomRecipe 1.0.4 Component Blind SQL Injection via search_author",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20277"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-27878",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00411,
      "epss_percentile": 0.34417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Enterprise Traces (GET)",
      "cwe": "CWE-400",
      "title": "Tempo TraceQL query with exemplar hint could result in unbounded memory usage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27878"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-49293",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sunnyadn",
      "product": "js-toml",
      "cwe": "CWE-400",
      "title": "CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49293"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-56079",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00409,
      "epss_percentile": 0.34275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-200",
      "title": "Capgo - Cross-Tenant Authorization Bypass via PostgREST Webhook Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56079"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-48895",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00409,
      "epss_percentile": 0.34277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-601",
      "title": "Apache APISIX: Cas-auth Host header influence on CAS service URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48895"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2017-20264",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00407,
      "epss_percentile": 0.34103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pulseextensions",
      "product": "Sponsor Wall",
      "cwe": "CWE-89",
      "title": "Joomla! Component Sponsor Wall 8.0 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20264"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2017-20265",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00407,
      "epss_percentile": 0.34103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pulseextensions",
      "product": "Flip Wall",
      "cwe": "CWE-89",
      "title": "Joomla! Component Flip Wall 8.0 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20265"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-39998",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00403,
      "epss_percentile": 0.33701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-20",
      "title": "Apache APISIX: Identity Injection via forward-auth Plugin Missing Header Cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39998"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-49342",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00403,
      "epss_percentile": 0.33701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lsegal",
      "product": "yard",
      "cwe": "CWE-22",
      "title": "YARD static cache reads raw traversal paths before router sanitization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49342"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-44915",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.004,
      "epss_percentile": 0.3344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-601",
      "title": "Apache APISIX: Cas-auth plugin open redirect via unsanitized cookie value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44915"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-42895",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00399,
      "epss_percentile": 0.33257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Copilot",
      "cwe": "CWE-77",
      "title": "Microsoft Copilot Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42895"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2017-20271",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.32732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nordmograph",
      "product": "StreetGuessr Game",
      "cwe": "CWE-89",
      "title": "Joomla StreetGuessr Game 1.1.8 SQL Injection via catid",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20271"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2017-20272",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.32731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Faboba",
      "product": "Ultimate Property Listing",
      "cwe": "CWE-89",
      "title": "Joomla Ultimate Property Listing 1.0.2 SQL Injection via sf_selectuser_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20272"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2017-20273",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.32732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomlashowroom",
      "product": "Event Registration Pro Calendar",
      "cwe": "CWE-89",
      "title": "Joomla Event Registration Pro Calendar 4.1.3 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20273"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2017-20274",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.32731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "King-products",
      "product": "LMS King Professional",
      "cwe": "CWE-89",
      "title": "Joomla LMS King Professional 3.2.4.0 SQL Injection via learningpath",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20274"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2017-20275",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.32732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Henryschorradt",
      "product": "Bridge",
      "cwe": "CWE-89",
      "title": "Joomla! Component PHP-Bridge 1.2.3 SQL Injection via id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20275"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2017-20276",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.32733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Simbunch",
      "product": "SIMGenealogy",
      "cwe": "CWE-89",
      "title": "Joomla! Component SIMGenealogy 2.1.5 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20276"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2017-20278",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.3273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomboost",
      "product": "JoomRecipe",
      "cwe": "CWE-89",
      "title": "Joomla JoomRecipe 1.0.3 SQL Injection via category parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20278"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2017-20279",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.32731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Extensions",
      "product": "Joomla Payage",
      "cwe": "CWE-89",
      "title": "Joomla Payage 2.05 SQL Injection via aid Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20279"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2017-20280",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.32731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Myportfolio",
      "product": "Myportfolio",
      "cwe": "CWE-89",
      "title": "Joomla Component Myportfolio 3.0.2 SQL Injection via pid Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2017-20280"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-49339",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00388,
      "epss_percentile": 0.32155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sentriz",
      "product": "gonic",
      "cwe": "CWE-22",
      "title": "Path traversal in getPlaylist/deletePlaylist bypasses ownership check: any authenticated user can read or delete any other user's playlist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49339"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-8118",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00386,
      "epss_percentile": 0.31895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wproyal",
      "product": "Royal Addons for Elementor – Addons and Templates Kit for Elementor",
      "cwe": "CWE-73",
      "title": "Royal Addons for Elementor – Addons and Templates Kit for Elementor 1.7.1058 - 1.7.1059 - Authenticated (Contributor+) Arbitrary File Read via Data Table Widget CSV File Source",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8118"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-49344",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.3151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sourcentis",
      "product": "mercator",
      "cwe": "CWE-359",
      "title": "Mercator has a Personal Identifiable Information Leak from Query Executor feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49344"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-56082",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.30446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo",
      "cwe": "CWE-284",
      "title": "Capgo - Unauthenticated Cross-Tenant Billing Log Tampering via public.record_build_time RPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56082"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-10779",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "techlabpro1",
      "product": "Classified Listing – AI-Powered Classified ads & Business Directory",
      "cwe": "CWE-862",
      "title": "Classified Listing <= 5.4.2 - Missing Authorization to Authenticated (Subscriber+) Feature Modification via Multiple AJAX Handlers ('listingId'/'id' Parameters)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10779"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2019-25749",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00367,
      "epss_percentile": 0.29915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cmsjunkie",
      "product": "J-CruisePortal",
      "cwe": "CWE-89",
      "title": "Joomla J-CruisePortal 6.0.4 SQL Injection via cruises",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25749"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2019-25757",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00367,
      "epss_percentile": 0.29915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wdmtech",
      "product": "vWishlist",
      "cwe": "CWE-89",
      "title": "Joomla vWishlist 1.0.1 SQL Injection via vproductid Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25757"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2019-25761",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00367,
      "epss_percentile": 0.29916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomboost",
      "product": "JoomCRM",
      "cwe": "CWE-89",
      "title": "Joomla! Component JoomCRM 1.1.1 SQL Injection via deal_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25761"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-48089",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00364,
      "epss_percentile": 0.29673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "l3montree-dev",
      "product": "devguard",
      "cwe": "CWE-285",
      "title": "DevGuard has improper authorization on public assets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48089"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-49231",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00359,
      "epss_percentile": 0.29164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-290",
      "title": "Apache APISIX: Identity spoofing issue in APISIX opa plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49231"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-4026",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flexera",
      "product": "FlexNet Manager Suite",
      "cwe": "CWE-284",
      "title": "FlexNet Manager Suite Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4026"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-4027",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flexera",
      "product": "FlexNet Manager Suite",
      "cwe": "CWE-284",
      "title": "FlexNet Manager Suite Attachment File Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4027"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-12157",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00349,
      "epss_percentile": 0.2808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevteam",
      "product": "BetterDocs –  AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot",
      "cwe": "CWE-79",
      "title": "BetterDocs <= 4.5.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'blockId' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12157"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-56208",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10.0 Extended Update Support",
      "cwe": "CWE-122",
      "title": "Libaom: libaom: heap buffer overflow in av1 encoder first-pass stats buffer via lap mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56208"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-4328",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00342,
      "epss_percentile": 0.27379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "addonspress",
      "product": "Advanced Import",
      "cwe": "CWE-918",
      "title": "Advanced Import: One-Click Demo Import for WordPress <= 1.4.6 - Authenticated (Author+) Server-Side Request Forgery via 'demo_file' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4328"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-12238",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00342,
      "epss_percentile": 0.27374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpgmaps",
      "product": "WP Go Maps – Google Map, OpenStreetMap, Leaflet Map",
      "cwe": "CWE-862",
      "title": "WP Go Maps <= 10.1.01 - Unauthenticated Arbitrary Record Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12238"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-9822",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0034,
      "epss_percentile": 0.27159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Hotel Booking",
      "cwe": null,
      "title": "WP Hotel Booking < 2.3.1 - Subscriber+ Missing Authorization in Multiple AJAX Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9822"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-12430",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00335,
      "epss_percentile": 0.26502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "creativethemeshq",
      "product": "Blocksy Companion",
      "cwe": "CWE-79",
      "title": "Blocksy Companion <= 2.1.45 - Authenticated (Editor+) Stored Cross-Site Scripting via 'product_description' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12430"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-1856",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.26153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "creavi",
      "product": "Creavi Appointment Booking Calendar",
      "cwe": "CWE-79",
      "title": "Appointment Booking Calendar <= 1.4.4 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Booking Field Label",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1856"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-56209",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux AI 3.3 for RHEL 9",
      "cwe": "CWE-787",
      "title": "Libaom: libaom: arbitrary address write via svc layer context oob and cyclic refresh map pointer hijack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56209"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-12726",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00326,
      "epss_percentile": 0.25575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-918",
      "title": "Awx: automation-controller: awx: github webhook second-order ssrf via unvalidated statuses_url exfiltrates pat credential",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12726"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-49872",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0032,
      "epss_percentile": 0.24878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-287",
      "title": "Apache APISIX: Improper authentication in cas-auth plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49872"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-11752",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00317,
      "epss_percentile": 0.24494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LY Corporation",
      "product": "Armeria",
      "cwe": null,
      "title": "A vulnerability has been identified in armeria-xds versions 1.38.0 through 1.39.0, where DataSourceStream in the xDS module can resolve control-plane-supplied filenames and environment variables without restriction, allowing a compromised or semi-trusted xDS control plane to read arbitrary local files and environment variables on the xDS client host.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11752"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-8296",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00317,
      "epss_percentile": 0.24494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Octopus Deploy",
      "product": "Octopus Server",
      "cwe": "CWE-79",
      "title": "In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8296"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-44046",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00314,
      "epss_percentile": 0.2422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-348",
      "title": "Apache APISIX: wolf-rbac plugin Identity Spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44046"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-10720",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.22579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "Microceph",
      "cwe": "CWE-23",
      "title": "MicroCeph path traversal issue in the remote-import API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10720"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-56210",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux AI 3.3 for RHEL 9",
      "cwe": "CWE-125",
      "title": "Libaom: libaom: heap-buffer-overflow read via missing bounds check in ctrl_set_layer_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56210"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-53915",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "GoLand",
      "cwe": "CWE-73",
      "title": "In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53915"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-49338",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.2143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sentriz",
      "product": "gonic",
      "cwe": "CWE-285",
      "title": "Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49338"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-47339",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-863",
      "title": "Apache APISIX: authz-casdoor incorrect session sharing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47339"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-48794",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00283,
      "epss_percentile": 0.2091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "authelia",
      "product": "authelia",
      "cwe": "CWE-178",
      "title": "Authelia has an Edge Case Access Control Rule Mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48794"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-48774",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sysown",
      "product": "proxysql",
      "cwe": "CWE-20",
      "title": "ProxySQL MCP run_sql_readonly executes side-effecting MySQL multi-statements despite read-only contract",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48774"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-56073",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0027,
      "epss_percentile": 0.19258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo",
      "cwe": "CWE-345",
      "title": "Cap-go - OTP Bypass via Response Manipulation in Email Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56073"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-49288",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "statamic",
      "product": "cms",
      "cwe": "CWE-200",
      "title": "Statamic CMS missing authorization on Control Panel fieldtype endpoints allows disclosure of restricted resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49288"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2019-25759",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wdmtech",
      "product": "vBizz",
      "cwe": "CWE-89",
      "title": "Joomla! Component vBizz 1.0.7 SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25759"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-49871",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00261,
      "epss_percentile": 0.17975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-352",
      "title": "Apache APISIX: cas-auth login CSRF / session injection issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49871"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-11941",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloudflare",
      "product": "Quiche",
      "cwe": "CWE-416",
      "title": "Use-after-free in connection ID iterator and FFI functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11941"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-12706",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.16041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux AI (RHEL AI) 3",
      "cwe": "CWE-416",
      "title": "Ffmpeg: ffmpeg: heap use-after-free read in rasc decoder decode_move()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12706"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-48141",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NI",
      "product": "grpc-device",
      "cwe": "CWE-401",
      "title": "Memory leak in NI grpc-device BeginSidebandStream",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48141"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-49295",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.1376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libde265",
      "cwe": "CWE-787",
      "title": "libde265 has an out-of-bounds write in process_reference_picture_set via predicted short-term RPS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49295"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-49346",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.1376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libde265",
      "cwe": "CWE-190",
      "title": "libde265 has a heap buffer overflow in de265_image_get_buffer via SPS dimension integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49346"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-12620",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microchip",
      "product": "GridTime 3000",
      "cwe": "CWE-200",
      "title": "Access Token Exposure in URL Parameters in GridTime™ 3000 GNSS Time Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12620"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-49260",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pontedilana",
      "product": "php-weasyprint",
      "cwe": "CWE-78",
      "title": "PhpWeasyPrint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49260"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-49230",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-354",
      "title": "Apache APISIX: Authentication bypass in jwe-decrypt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49230"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-44087",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache APISIX",
      "cwe": "CWE-345",
      "title": "Apache APISIX: Openid-connect plugin Identity Header Spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44087"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-48772",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00212,
      "epss_percentile": 0.11762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sysown",
      "product": "proxysql",
      "cwe": "CWE-348",
      "title": "ProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql_query_rules.client_addr ACL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48772"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2022-50971",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Malwarebytes",
      "product": "Malwarebytes",
      "cwe": "CWE-428",
      "title": "Malwarebytes 4.5 Unquoted Service Path Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-50971"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-48715",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "radvd-project",
      "product": "radvdump",
      "cwe": "CWE-121",
      "title": "radvdump's Route Information Option Parser has a Stack Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48715"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-49271",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-125",
      "title": "libheif: Wrapped icef compressed-unit range check causes out-of-bounds read in uncompressed HEIF decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49271"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-49337",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libde265",
      "cwe": "CWE-770",
      "title": "libde265 has an unbounded memory leak via orphaned slice headers in `read_slice_NAL`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49337"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-11775",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.09018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "adamsilverstein",
      "product": "User Admin Simplifier",
      "cwe": "CWE-352",
      "title": "User Admin Simplifier <= 3.0.0 - Cross-Site Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11775"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2025-71326",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.08158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Avast",
      "product": "AVAST Antivirus",
      "cwe": "CWE-428",
      "title": "AVAST Antivirus 25.11 Unquoted Service Path Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71326"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2016-20094",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.08037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anydesk",
      "product": "AnyDesk",
      "cwe": "CWE-428",
      "title": "AnyDesk 2.5.0 Unquoted Service Path Elevation of Privilege",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20094"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-9143",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NI",
      "product": "grpc-device",
      "cwe": "CWE-681",
      "title": "Incorrect Conversion between Numeric Types in NI grpc-device due to missing range checks in CodeGen",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9143"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2016-20087",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Networkdls",
      "product": "Fortitude HTTP",
      "cwe": "CWE-428",
      "title": "Fortitude HTTP 1.0.4.0 Unquoted Service Path Elevation of Privilege",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20087"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2016-20088",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Comodo",
      "product": "Chromodo Browser",
      "cwe": "CWE-428",
      "title": "Comodo Chromodo Browser 52.15.25.664 Unquoted Service Path Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20088"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2016-20089",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Iperiusremote",
      "product": "Iperius Remote",
      "cwe": "CWE-428",
      "title": "Iperius Remote 1.7.0 Unquoted Service Path Elevation of Privilege",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20089"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2016-20090",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Comodo",
      "product": "Dragon Browser",
      "cwe": "CWE-428",
      "title": "Comodo Dragon Browser 52.15.25.663 Privilege Escalation via Unquoted Service Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20090"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2016-20092",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netdrive",
      "product": "NetDrive",
      "cwe": "CWE-428",
      "title": "NetDrive 2.6.12 Unquoted Service Path Elevation of Privilege",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20092"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2016-20093",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wisecleaner",
      "product": "Wise Care 365",
      "cwe": "CWE-428",
      "title": "Wise Care 365 4.27 and Wise Disk Cleaner 9.29 Unquoted Service Path Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20093"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2019-25747",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Network-Inventory-Advisor",
      "product": "Network Inventory Advisor",
      "cwe": "CWE-428",
      "title": "Network Inventory Advisor 5.0.26.0 Unquoted Service Path Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25747"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2020-37254",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wondershare",
      "product": "PDFelement",
      "cwe": "CWE-428",
      "title": "Wondershare PDFelement 5.2.9 Privilege Escalation via Unquoted Service Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-37254"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2023-54353",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Personifyinc",
      "product": "Chromacam",
      "cwe": "CWE-428",
      "title": "Chromacam 4.0.3.0 Unquoted Service Path Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-54353"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2016-20095",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Matrix42",
      "product": "Matrix42 Remote Control Host",
      "cwe": "CWE-428",
      "title": "Matrix42 Remote Control Host 3.20.0031 Unquoted Path Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20095"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2020-37250",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Weird-Solutions",
      "product": "TFTP Broadband",
      "cwe": "CWE-428",
      "title": "TFTP Broadband 4.3.0.1465 Unquoted Service Path Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-37250"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2020-37251",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Real",
      "product": "RealTimes Desktop Service",
      "cwe": "CWE-428",
      "title": "RealTimes Desktop Service 18.1.4 Unquoted Service Path Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-37251"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2020-37252",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Realtek",
      "product": "Realtek Audio Service",
      "cwe": "CWE-428",
      "title": "Realtek Audio Service 1.0.0.55 Unquoted Service Path Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-37252"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-3195",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06885,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "qemu",
      "cwe": "CWE-122",
      "title": "Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb (incomplete fix for cve-2024-7730)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3195"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2016-20085",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00168,
      "epss_percentile": 0.06552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Realtek",
      "product": "Realtek High Definition Audio Driver",
      "cwe": "CWE-428",
      "title": "Realtek High Definition Audio Driver 6.0.1.6730 Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20085"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2016-20086",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00168,
      "epss_percentile": 0.06552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Vembu",
      "product": "Vembu StoreGrid",
      "cwe": "CWE-428",
      "title": "Vembu StoreGrid 4.0 Unquoted Service Path Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20086"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2016-20091",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Binisoft",
      "product": "Windows Firewall Control",
      "cwe": "CWE-428",
      "title": "Windows Firewall Control 4.8.6.0 Unquoted Service Path Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2016-20091"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2021-47985",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Brother",
      "product": "SAPSprint",
      "cwe": "CWE-428",
      "title": "Brother SAPSprint 7.60 Unquoted Service Path Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-47985"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-34192",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-416",
      "title": "GPU DDK - _MMU_AllocLevel error recovery paths leave dangling page table entries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34192"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-41156",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-416",
      "title": "GPU DDK - kernel<->fw CCB contains SYNC_PRIMITIVE_BLOCK firmware address without holding reference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41156"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2020-37253",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.05378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Winstep",
      "product": "Winstep",
      "cwe": "CWE-428",
      "title": "Winstep 18.06.0096 Unquoted Service Path Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-37253"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-21768",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Verse for Android",
      "cwe": "CWE-20",
      "title": "HCL Verse for Android is susceptible to an injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21768"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-49358",
      "cvss_base": 3,
      "cvss_severity": "LOW",
      "epss_score": 0.00149,
      "epss_percentile": 0.0466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pontedilana",
      "product": "php-weasyprint",
      "cwe": "CWE-73",
      "title": "PhpWeasyPrint vulnerable to arbitrary file deletion at shutdown via public $temporaryFiles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49358"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-3196",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04119,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "qemu",
      "cwe": "CWE-190",
      "title": "Qemu-kvm: virtio-snd: integer overflow leading to unbounded memory allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3196"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-46461",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.03601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Server Hardware Manager",
      "cwe": "CWE-284",
      "title": "Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46461"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-12621",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microchip",
      "product": "GridTime 3000",
      "cwe": "CWE-79",
      "title": "Cross-Site Scripting (XSS) Vulnerability in Password Reset Redirect in GridTime™ 3000 GNSS Time Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12621"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-12619",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microchip",
      "product": "GridTime 3000",
      "cwe": "CWE-79",
      "title": "GridTime™ 3000 GNSS Time Server CSRF to XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12619"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-56131",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libexpat project",
      "product": "libexpat",
      "cwe": "CWE-416",
      "title": "libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56131"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-52908",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA: During rereg_mr ensure that REREG_ACCESS is compatible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52908"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-12622",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microchip",
      "product": "GridTime 3000",
      "cwe": "CWE-601",
      "title": "Open Redirect Vulnerability in Password Reset Submission in GridTime™ 3000 GNSS Time Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12622"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-52909",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ip6_vti: set netns_immutable on the fallback device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52909"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-56132",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libexpat project",
      "product": "libexpat",
      "cwe": "CWE-821",
      "title": "In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56132"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-52910",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00104,
      "epss_percentile": 0.0116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "bpf: Free reuseport cBPF prog after RCU grace period.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52910"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-62821",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-62821. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48772",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48772 (sysown proxysql). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48773",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48773 (sysown proxysql). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48774",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48774 (sysown proxysql). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49293",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49293 (sunnyadn js-toml). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49295",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49295 (strukturag libde265). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49346",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49346 (strukturag libde265). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50559",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50559 (quarkusio quarkus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-51843",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-51843. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-51844",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-51844. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-51845",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-51845. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-51846",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-51846. Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-54420",
      "detail": "DUE DATE PASSED — CVE-2026-54420 (LiteSpeed Technologies cPanel Plugin). CISA remediation deadline was June 18, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
