{
  "day": "2026-06-22",
  "boundary": "UTC calendar day",
  "published_count": 220,
  "by_severity": {
    "CRITICAL": 21,
    "HIGH": 80,
    "MEDIUM": 105,
    "LOW": 14
  },
  "kev_count": 0,
  "exploit_reference_count": 22,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-48746",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01152,
      "epss_percentile": 0.64418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-444",
      "title": "vLLM: OpenAI auth bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48746"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-11834",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01023,
      "epss_percentile": 0.60775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Archer MR200 v07",
      "cwe": "CWE-78",
      "title": "Unauthenticated Command Injection via DHCP Option Handling in Multiple TP-Link Routers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11834"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2025-66389",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0094,
      "epss_percentile": 0.58158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-552",
      "title": "GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there is indirect prompt injection.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66389"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-10561",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00914,
      "epss_percentile": 0.57346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Unauthenticated Remote Code Execution in Langflow OSS PythonREPLComponent via Builtins Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10561"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-54236",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00823,
      "epss_percentile": 0.54509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-532",
      "title": "vLLM: incomplete CVE-2026-22778 fix leaks PIL repr addresses via Anthropic router",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54236"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-41523",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00746,
      "epss_percentile": 0.51988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-94",
      "title": "vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41523"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-10789",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00701,
      "epss_percentile": 0.50397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "Fusion",
      "cwe": "CWE-94",
      "title": "MCP Extension Code Injection Vulnerability in Autodesk Fusion Desktop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10789"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-56323",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00638,
      "epss_percentile": 0.47843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-200",
      "title": "Capgo - Unauthenticated Channel Enumeration and App Oracle via GET /channel_self",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56323"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2025-71344",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00638,
      "epss_percentile": 0.4783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-502",
      "title": "picklescan - Arbitrary Code Execution via Undetected ensurepip._run_pip Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71344"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2023-45796",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00627,
      "epss_percentile": 0.47361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pilz",
      "product": "PMI v8xx",
      "cwe": "CWE-79",
      "title": "XSS vulnerability in Pilz PASvisu and PMI v8xx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-45796"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-11748",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00618,
      "epss_percentile": 0.46924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LY Corporation",
      "product": "Central Dogma",
      "cwe": "CWE-90",
      "title": "A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the login username into an LDAP search filter without neutralizing LDAP filter metacharacters, allowing an unauthenticated attacker to manipulate the filter to cause authentication confusion and enumerate the directory structure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11748"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-56422",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00603,
      "epss_percentile": 0.46204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-639",
      "title": "MISP Core: Mass Assignment and Object Re-ownership via Unvalidated Request Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56422"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-49468",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00591,
      "epss_percentile": 0.45684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BerriAI",
      "product": "litellm",
      "cwe": "CWE-290",
      "title": "LiteLLM: Authentication Bypass via Host Header Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49468"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-53779",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00587,
      "epss_percentile": 0.45511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webp-sh",
      "product": "webp_server_go",
      "cwe": "CWE-22",
      "title": "WebP Server Go < 0.15.0 Path Traversal via Backslash Encoding on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53779"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-53571",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00587,
      "epss_percentile": 0.45514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vitejs",
      "product": "vite",
      "cwe": "CWE-22",
      "title": "Vite: `server.fs.deny` bypass on Windows alternate paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53571"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-56450",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00577,
      "epss_percentile": 0.44986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ail project",
      "product": "ail framework",
      "cwe": "CWE-307",
      "title": "AIL Framework - Missing Rate Limiting Enables Brute-Force Attacks Against Two-Factor Authentication Codes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56450"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-7167",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00571,
      "epss_percentile": 0.44727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gaudire",
      "product": "Assassin game",
      "cwe": "CWE-200",
      "title": "Multiple vulnerabilities in the Assassin game by Gaudire",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7167"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-11373",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00569,
      "epss_percentile": 0.446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JASEI",
      "product": "Net::Statsite::Client",
      "cwe": "CWE-93",
      "title": "Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11373"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-54232",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00563,
      "epss_percentile": 0.44332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-427",
      "title": "vLLM: Dependency Confusion Vulnerability in vLLM Dockerfile",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54232"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2025-66336",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00561,
      "epss_percentile": 0.44235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Doris MCP Server",
      "cwe": "CWE-89",
      "title": "Apache Doris MCP Server: SQL injection leading the authentication bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66336"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-54293",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00555,
      "epss_percentile": 0.43901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nltk",
      "product": "nltk",
      "cwe": "CWE-22",
      "title": "NLTK: URL-Encoded Path Traversal in nltk.data.load() Allows Arbitrary Local File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54293"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-9071",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00549,
      "epss_percentile": 0.43572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-400",
      "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by Uncontrolled Resource Consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9071"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-7166",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00544,
      "epss_percentile": 0.43356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gaudire",
      "product": "Assassin game",
      "cwe": "CWE-200",
      "title": "Multiple vulnerabilities in the Assassin game by Gaudire",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7166"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2025-71339",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00523,
      "epss_percentile": 0.42201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Picklescan",
      "product": "Picklescan",
      "cwe": "CWE-502",
      "title": "Picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran._eval_length Gadget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71339"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-8934",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0051,
      "epss_percentile": 0.41359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google Cloud",
      "product": "Cloud Console UIs",
      "cwe": "CWE-862",
      "title": "Cross-Project Information Leakage in Google App Engine UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8934"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-48109",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00509,
      "epss_percentile": 0.41281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MessagePack-CSharp",
      "product": "MessagePack-CSharp",
      "cwe": "CWE-20",
      "title": "MessagePack-CSharp: LZ4 decompression may fail with AccessViolationException after dereferencing memory from bad input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48109"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2025-62198",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00505,
      "epss_percentile": 0.41092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Atlas",
      "cwe": "CWE-80",
      "title": "Apache Atlas: Stored XSS in Create Entity page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62198"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-7664",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00498,
      "epss_percentile": 0.40681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-287",
      "title": "Unauthenticated Flow Execution via Webhook Endpoint in Langflow OSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7664"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-54281",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00498,
      "epss_percentile": 0.40684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nestjs",
      "product": "nest",
      "cwe": "CWE-863",
      "title": "Nest: Middleware Bypass on Fastify via Trailing Slash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54281"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-47240",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00491,
      "epss_percentile": 0.40215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ruby",
      "product": "net-imap",
      "cwe": "CWE-77",
      "title": "Net::IMAP: Command Injection via non-synchronizing literal in \"raw\" argument",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47240"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-7165",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0048,
      "epss_percentile": 0.39578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gaudire",
      "product": "Assassin game",
      "cwe": "CWE-20",
      "title": "Multiple vulnerabilities in the Assassin game by Gaudire",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7165"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-56266",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00476,
      "epss_percentile": 0.39316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crawl4AI",
      "product": "Crawl4AI",
      "cwe": "CWE-918",
      "title": "Crawl4AI - Server-Side Request Forgery via Direct Crawl Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56266"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-48506",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00471,
      "epss_percentile": 0.38964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MessagePack-CSharp",
      "product": "MessagePack-CSharp",
      "cwe": "CWE-674",
      "title": "MessagePack-CSharp: MessagePackReader.Skip can recurse without enforcing maximum object graph depth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48506"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-10845",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.3863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-287",
      "title": "IBM WebSphere Application Server is affected by an authentication bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10845"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-56324",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00465,
      "epss_percentile": 0.38535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-770",
      "title": "Capgo - Rate Limit Bypass via User-Controlled device_id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56324"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-48712",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0046,
      "epss_percentile": 0.38241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "protobufjs",
      "product": "protobuf.js",
      "cwe": "CWE-674",
      "title": "protobufjs: Denial of service through unbounded Any expansion during JSON conversion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48712"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-56321",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00455,
      "epss_percentile": 0.37924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-306",
      "title": "Capgo - Missing Authentication Middleware on GET /private/role_bindings Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56321"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-55388",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00454,
      "epss_percentile": 0.37884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "piscinajs",
      "product": "piscina",
      "cwe": "CWE-94",
      "title": "piscina: Prototype Pollution Gadget → RCE via inherited options.filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55388"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-12581",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00454,
      "epss_percentile": 0.37835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Digiwin",
      "product": "EasyFlow .NET",
      "cwe": "CWE-384",
      "title": "Digiwin｜EasyFlow .NET - Session Fixation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12581"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-12888",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00444,
      "epss_percentile": 0.37093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thinkst Applied Research",
      "product": "Canarytokens",
      "cwe": "CWE-74",
      "title": "HTML injection in the Canarytoken Google Chat notification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12888"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-42129",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00443,
      "epss_percentile": 0.37026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana OSS",
      "cwe": "CWE-22",
      "title": "Path traversal in the Loki data source plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42129"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-11942",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00441,
      "epss_percentile": 0.36905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Akaunting",
      "product": "Akaunting",
      "cwe": "CWE-79",
      "title": "Akaunting 3.1.21 - Stored XSS in delete confirmation modal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11942"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-11943",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00441,
      "epss_percentile": 0.36904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Akaunting",
      "product": "Akaunting",
      "cwe": "CWE-79",
      "title": "Akaunting 3.1.21 - Authenticated stored XSS in document timeline",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11943"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-11994",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00441,
      "epss_percentile": 0.36905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Akaunting",
      "product": "Akaunting",
      "cwe": "CWE-79",
      "title": "Akaunting 3.1.21 - Authenticated stored XSS in report description rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11994"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-56448",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00437,
      "epss_percentile": 0.3657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ail project",
      "product": "ail framework",
      "cwe": "CWE-22",
      "title": "Authenticated Path Traversal in AIL Framework Investigation Downloads Allows Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56448"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-39904",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00436,
      "epss_percentile": 0.36473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gophish",
      "product": "gophish",
      "cwe": "CWE-770",
      "title": "Gophish 0.12.1 Denial of Service via Office Document Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39904"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-54286",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00433,
      "epss_percentile": 0.36253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "hono",
      "cwe": "CWE-22",
      "title": "Hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54286"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-42127",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana Enterprise",
      "cwe": "CWE-400",
      "title": "Pre-authentication denial of service in the public dashboard query endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42127"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2025-71358",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00431,
      "epss_percentile": 0.36118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-502",
      "title": "picklescan - Remote Code Execution via idlelib.autocomplete.AutoComplete.get_entity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71358"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-56314",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00426,
      "epss_percentile": 0.357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-672",
      "title": "Capgo - Deleted Bundle Selection via Missing Deletion Filter in /updates Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56314"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-54233",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00422,
      "epss_percentile": 0.35391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-409",
      "title": "vLLM: OOM Denial of Service via Audio Decompression Bomb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54233"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2024-54178",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0042,
      "epss_percentile": 0.35225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data",
      "cwe": "CWE-770",
      "title": "Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-54178"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-8157",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00417,
      "epss_percentile": 0.34974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Vitepos",
      "cwe": "CWE-269",
      "title": "Vitepos < 3.4.2 - Outlet Manager+ Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8157"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-56698",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00413,
      "epss_percentile": 0.3462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nuxt",
      "product": "Nuxt",
      "cwe": "CWE-79",
      "title": "Nuxt - Cross-Site Scripting via navigateTo open Option",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56698"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-12549",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00411,
      "epss_percentile": 0.34419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-805",
      "title": "Libsoup: incomplete fix for cve-2026-2443: range suffix overflow in libsoup soupserver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12549"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-9072",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00409,
      "epss_percentile": 0.34248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-94",
      "title": "WebSphere Application Server Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9072"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-12725",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00403,
      "epss_percentile": 0.33704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-122",
      "title": "Dnsmasq: dnsmasq: heap buffer overflow in log_query() when logging unsupported ds/dnskey replies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12725"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-54269",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00402,
      "epss_percentile": 0.33589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "protobufjs",
      "product": "protobuf.js",
      "cwe": "CWE-674",
      "title": "protobufjs: Schema-derived names can shadow runtime-significant properties",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54269"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-54270",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00402,
      "epss_percentile": 0.33589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "protobufjs",
      "product": "protobuf.js",
      "cwe": "CWE-770",
      "title": "protobufjs: Memory amplification from preserved unknown fields in binary decode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54270"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-54283",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.33106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kludex",
      "product": "starlette",
      "cwe": "CWE-770",
      "title": "Starlette: request.form() limits silently ignored for application/x-www-form-urlencoded enable DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54283"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-54278",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00397,
      "epss_percentile": 0.33072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aio-libs",
      "product": "aiohttp",
      "cwe": "CWE-409",
      "title": "AIOHTTP: Unread Compressed Request Bodies Bypass client_max_size During Cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54278"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-44914",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache NiFi",
      "cwe": "CWE-862",
      "title": "Apache NiFi: Missing Authorization of Restricted Permissions when Replacing Flow Contents",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44914"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-56446",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00391,
      "epss_percentile": 0.32391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-94",
      "title": "Authenticated Remote Code Execution via Arbitrary NDJSON Error Log Path in MISP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56446"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-44913",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00385,
      "epss_percentile": 0.31868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache NiFi",
      "cwe": "CWE-116",
      "title": "Apache NiFi: Improper Escaping of Table Names in CaptureChangeMySQL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44913"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-12479",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00384,
      "epss_percentile": 0.31699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "keras-team",
      "product": "keras-team/keras",
      "cwe": "CWE-22",
      "title": "Path Traversal in keras-team/keras",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12479"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-12862",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00382,
      "epss_percentile": 0.31511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "Venueless",
      "cwe": "CWE-148",
      "title": "XLSX formula injection in exports",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12862"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-53539",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kludex",
      "product": "python-multipart",
      "cwe": "CWE-400",
      "title": "Python-Multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53539"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-56221",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00379,
      "epss_percentile": 0.31256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo",
      "cwe": "CWE-89",
      "title": "Cap-go - SQL Injection in Cloudflare Analytics Engine Queries via cloudflare.ts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56221"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-53550",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00378,
      "epss_percentile": 0.31069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodeca",
      "product": "js-yaml",
      "cwe": "CWE-407",
      "title": "js-yaml: Quadratic-complexity DoS in merge key handling via repeated aliases",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53550"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-56255",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00373,
      "epss_percentile": 0.30612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-770",
      "title": "Capgo - Denial of Service via Unlimited Demo App Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56255"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-56280",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.30442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo",
      "cwe": "CWE-862",
      "title": "Cap-go - Privilege Inversion in Build Log Stream via SSE Disconnect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56280"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-55602",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0037,
      "epss_percentile": 0.30206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chimurai",
      "product": "http-proxy-middleware",
      "cwe": "CWE-20",
      "title": "http-proxy-middleware `router` host+path substring matching allows Host-header-driven backend routing bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55602"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-8646",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00365,
      "epss_percentile": 0.29745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-444",
      "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8646"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-56311",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00364,
      "epss_percentile": 0.29651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-285",
      "title": "Capgo - Unauthenticated Cross-Tenant Disclosure via get_current_plan_max_org RPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56311"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-56326",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00362,
      "epss_percentile": 0.29414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nuxt",
      "product": "Nuxt",
      "cwe": "CWE-601",
      "title": "Nuxt - Server-Side Open Redirect via Path-Normalization Bypass in navigateTo",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56326"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-56424",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-639",
      "title": "Broken access control in MISP core allows cross-organization unauthorized modification or deletion of analyst data, event reports, collections, templates, and decaying models",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56424"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-12628",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00357,
      "epss_percentile": 0.28986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Storage Protect Client",
      "cwe": "CWE-798",
      "title": "Hardcoded credential in the IBM Storage Protect Snapshot For Windows leads to unauthorized access to system",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12628"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-6653",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.2877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "libxml2",
      "cwe": "CWE-416",
      "title": "libxml2: Use after free in xmlParseInternalSubset via improper entity resolution handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6653"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-45034",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00351,
      "epss_percentile": 0.28338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHPOffice",
      "product": "PhpSpreadsheet",
      "cwe": "CWE-502",
      "title": "PhpSpreadsheet: File::prohibitWrappers bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45034"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-12863",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00351,
      "epss_percentile": 0.28247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "Venueless",
      "cwe": "CWE-601",
      "title": "Open redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12863"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-9320",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00349,
      "epss_percentile": 0.2813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-400",
      "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9320"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-53632",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00349,
      "epss_percentile": 0.28087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vitejs",
      "product": "launch-editor",
      "cwe": "CWE-73",
      "title": "NTLMv2 hash disclosure via UNC path handling on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53632"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-48166",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filamentphp",
      "product": "filament",
      "cwe": "CWE-208",
      "title": "Filament: Timing-based user enumeration on login page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48166"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-56306",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-20",
      "title": "Capgo - Subkey Enforcement Bypass via x-limited-key-id Header Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56306"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-48931",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00345,
      "epss_percentile": 0.27632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodejs",
      "product": "node",
      "cwe": "CWE-367",
      "title": "A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48931"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-54285",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00344,
      "epss_percentile": 0.27528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-js",
      "cwe": "CWE-770",
      "title": "opentelemetry-js: Unbounded memory allocation in W3C Baggage propagation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54285"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-48500",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filamentphp",
      "product": "filament",
      "cwe": "CWE-862",
      "title": "Filament: Unauthenticated temporary file upload on auth pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48500"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-56447",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00342,
      "epss_percentile": 0.2734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-829",
      "title": "MISP remote code execution via arbitrary rdkafka configuration path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56447"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-56268",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00337,
      "epss_percentile": 0.26763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-863",
      "title": "Flowise - Cross-Workspace Information Disclosure via chatflows/apikey Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56268"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-56697",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00337,
      "epss_percentile": 0.26713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nuxt",
      "product": "Nuxt",
      "cwe": "CWE-601",
      "title": "Nuxt - Open Redirect via Protocol-Relative Paths in reloadNuxtApp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56697"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-9162",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00334,
      "epss_percentile": 0.26473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-613",
      "title": "Global session revocation does not invalidate active WebSocket connections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9162"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-54299",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00333,
      "epss_percentile": 0.26262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "withastro",
      "product": "astro",
      "cwe": "CWE-20",
      "title": "Astro: Host-header full-read SSRF in core prerendered error-page fetch (prerenderedErrorPageFetch default + unvalidated createRequestFromNodeRequest URL)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54299"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2025-4994",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00331,
      "epss_percentile": 0.26139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SafeLine",
      "product": "SafeLine SL6/SL6+",
      "cwe": "CWE-305",
      "title": "Authentication Bypass for SafeLine SL6 and SL6+",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-4994"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-54290",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "hono",
      "cwe": "CWE-942",
      "title": "Hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54290"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-56423",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00327,
      "epss_percentile": 0.25647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-862",
      "title": "MISP Core: Broken access control allows instance-wide unauthorized deletion of event reports and sharing groups via bulk deletion endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56423"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-54268",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-400",
      "title": "Angular: Denial of Service (DoS) via OOM in Date Formatting (formatDate)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54268"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-44911",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00327,
      "epss_percentile": 0.25648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache NiFi",
      "cwe": "CWE-863",
      "title": "Apache NiFi: Incorrect Authorization for Configuration Verification Requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44911"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-54277",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.25088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aio-libs",
      "product": "aiohttp",
      "cwe": "CWE-770",
      "title": "AIOHTTP: C HTTP Parser Bypasses max_line_size for Fragmented Lines",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54277"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-8074",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00318,
      "epss_percentile": 0.24642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-863",
      "title": "Improper Permission Check Allows User Manager to Deactivate Bot Accounts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8074"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-8823",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00318,
      "epss_percentile": 0.24643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-863",
      "title": "User Manager can demote bot accounts to guest without bot-management permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8823"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-54300",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "withastro",
      "product": "astro",
      "cwe": "CWE-918",
      "title": "@astrojs/netlify broadens Astro image.remotePatterns in Netlify Image CDN config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54300"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-54287",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0031,
      "epss_percentile": 0.23788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "hono",
      "cwe": "CWE-116",
      "title": "Hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54287"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-44727",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00305,
      "epss_percentile": 0.23212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyter-server",
      "product": "jupyter_server",
      "cwe": "CWE-79",
      "title": "Jupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44727"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-54274",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.23182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aio-libs",
      "product": "aiohttp",
      "cwe": "CWE-770",
      "title": "AIOHTTP: Incomplete websocket frame payloads bypass memory limits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54274"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-54271",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "protobufjs",
      "product": "protobufjs-cli",
      "cwe": "CWE-94",
      "title": "protobufjs-cli: Code injection in pbjs static output from crafted JSON descriptor names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54271"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-50269",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00301,
      "epss_percentile": 0.22788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aio-libs",
      "product": "aiohttp",
      "cwe": "CWE-93",
      "title": "AIOHTTP: CRLF injection in multipart headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50269"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-48067",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.22592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filamentphp",
      "product": "filament",
      "cwe": "CWE-639",
      "title": "Filament: Inconsistent scope enforcement for AttachAction and AssociateAction Select fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48067"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-6673",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.2255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-306",
      "title": "Mattermost Jira plugin had unauthenticated {{/ac/installed}} lifecycle callback during pending Jira Cloud install",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6673"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-48505",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filamentphp",
      "product": "filament",
      "cwe": "CWE-362",
      "title": "Filament: Multi-factor authentication (app) recovery codes can still be used multiple times via concurrent submission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48505"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-10852",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.21886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-476",
      "title": "Websphere Application Server is Affected By a Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10852"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-6858",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.2187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Transbank Webpay",
      "cwe": "CWE-79",
      "title": "Transbank Webpay < 1.14.0 - Unauthenticated Stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6858"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-5139",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.21294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-862",
      "title": "GitLab Plugin Allows Non-Admin Users to Modify Default Instance Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5139"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-54100",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.2108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift for Windows Containers 10.22",
      "cwe": "CWE-295",
      "title": "Windows-machine-config-operator: windows-machine-config-operator: ssh host key not verified enables credential theft",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54100"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-55409",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.21026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filamentphp",
      "product": "filament",
      "cwe": "CWE-79",
      "title": "Filament: Disabled RichEditor field state can be used for XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55409"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-53923",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-200",
      "title": "vLLM GGUF Kernels: int64_t to int truncation of tensor dimensions causes GPU buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53923"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-54280",
      "cvss_base": 1.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00281,
      "epss_percentile": 0.20709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aio-libs",
      "product": "aiohttp",
      "cwe": "CWE-404",
      "title": "AIOHTTP: Payload Response Resources Are Not Closed After Mid-Body Disconnect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54280"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-10651",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-20",
      "title": "Out-of-bounds read in Bluetooth Classic SDP attribute parsing (`bt_sdp_parse_attribute`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10651"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-12580",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Digiwin",
      "product": "EasyFlow .NET",
      "cwe": "CWE-79",
      "title": "Digiwin｜EasyFlow .NET - Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12580"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-8918",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Armoury Crate",
      "cwe": "CWE-183",
      "title": "A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mechanism.Refer to the ' Security Update for Armoury Crate App ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8918"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-54273",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.20435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aio-libs",
      "product": "aiohttp",
      "cwe": "CWE-770",
      "title": "AIOHTTP: HTTP/1 Pipelined Requests Queue Without Limit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54273"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-54279",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00279,
      "epss_percentile": 0.20435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aio-libs",
      "product": "aiohttp",
      "cwe": "CWE-665",
      "title": "AIOHTTP: Host-Only Cookies Become Domain Cookies After CookieJar Persistence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54279"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-50178",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.1995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-79",
      "title": "Angular: Remote Code Execution via JSDoc Hover Command Injection in VS Code Angular Language Service Extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50178"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-54911",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ultrajson",
      "product": "ultrajson",
      "cwe": "CWE-20",
      "title": "UltraJSON: Malformed/Truncated UTF-8 Accepted and Silently Rewritten in ujson.dumps()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54911"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-54235",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-1287",
      "title": "vLLM: temperature=NaN and temperature=Infinity bypass validation and propagate to GPU kernels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54235"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-50170",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-524",
      "title": "Angular: Information Leak via Default Caching of Credentialed Requests in HttpTransferCache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50170"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-54665",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache NiFi",
      "cwe": "CWE-346",
      "title": "Apache NiFi: Missing Validation for Proxy Host Headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54665"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-50146",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.1909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "withastro",
      "product": "astro",
      "cwe": "CWE-80",
      "title": "Astro: Reflected XSS via unescaped slot name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50146"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-54275",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00266,
      "epss_percentile": 0.18619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aio-libs",
      "product": "aiohttp",
      "cwe": "CWE-297",
      "title": "AIOHTTP: TLS Server Hostname Override Is Ignored When Reusing HTTPS Connections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54275"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-55603",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.18523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chimurai",
      "product": "http-proxy-middleware",
      "cwe": "CWE-93",
      "title": "http-proxy-middleware: multipart/form-data field injection via unescaped CRLF in `fixRequestBody`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55603"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-56348",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.18166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-918",
      "title": "n8n - Credential Exfiltration via Allowed HTTP Request Domains Bypass in Dynamic Node Parameters Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56348"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-8858",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.1795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-94",
      "title": "WebSphere Application Server Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8858"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-56425",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00258,
      "epss_percentile": 0.17719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-384",
      "title": "MISP AAD authentication plugin - Improper OAuth State Handling, Missing Session Rotation, Insecure Redirect URI Validation, and Log Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56425"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-10601",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana OSS",
      "cwe": "CWE-22",
      "title": "Path traversal in the Tempo and Loki data source plugins",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10601"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-56104",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chainlit",
      "product": "chainlit",
      "cwe": "CWE-862",
      "title": "Chainlit < 2.10.1 Session Hijacking via WebSocket Session Restoration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56104"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-48502",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MessagePack-CSharp",
      "product": "MessagePack-CSharp",
      "cwe": "CWE-125",
      "title": "MessagePack-CSharp: Denial of service vulnerabilities can swamp the CPU or crash the process with stack and heap overflows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48502"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-4110",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ultimate-woocommerce-auction-pro",
      "cwe": null,
      "title": "Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_auctions_bids_list",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4110"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-4259",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ultimate-woocommerce-auction-pro",
      "cwe": "CWE-79",
      "title": "Ultimate WooCommerce Auction Pro <= 2.4.5 - Reflected XSS via uwa_manage_auctions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4259"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-9029",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana OSS",
      "cwe": "CWE-79",
      "title": "Stored XSS in the Geomap panel tile-layer attribution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9029"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2023-33854",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data",
      "cwe": "CWE-294",
      "title": "Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-33854"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-44271",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.1663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Wyse Management Suite (WMS)",
      "cwe": "CWE-89",
      "title": "Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44271"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-44272",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.1663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Wyse Management Suite (WMS)",
      "cwe": "CWE-89",
      "title": "Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44272"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-48509",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MessagePack-CSharp",
      "product": "MessagePack-CSharp",
      "cwe": "CWE-1188",
      "title": "MessagePack-CSharp: ASP.NET Core MessagePackInputFormatter defaults to TrustedData for HTTP request bodies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48509"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-47155",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-345",
      "title": "vLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47155"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-48167",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.1627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filamentphp",
      "product": "filament",
      "cwe": "CWE-79",
      "title": "Filament: Unvalidated ImageColumn and ImageEntry values can be used for XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48167"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-48517",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MessagePack-CSharp",
      "product": "MessagePack-CSharp",
      "cwe": "CWE-470",
      "title": "MessagePack-CSharp: Typeless deserialization type restrictions do not recurse into arrays or generic arguments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48517"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-6062",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-639",
      "title": "IDOR in Jira plugin subscription edit endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6062"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-9006",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00239,
      "epss_percentile": 0.15298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-918",
      "title": "IBM WebSphere Application Server is affected by server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9006"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-47241",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00239,
      "epss_percentile": 0.15226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ruby",
      "product": "net-imap",
      "cwe": "CWE-162",
      "title": "Net::IMAP: Denial of Service via incomplete raw argument validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47241"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-50556",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-79",
      "title": "Angular: Missing `<noscript>` Raw-Text Serialization Escaping leads to Cross-Site Scripting (XSS) in Angular SSR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50556"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-48510",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MessagePack-CSharp",
      "product": "MessagePack-CSharp",
      "cwe": "CWE-409",
      "title": "MessagePack-CSharp: LZ4 decompression allocates from unbounded declared output lengths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48510"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-8059",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Datacap",
      "cwe": "CWE-79",
      "title": "Multiple Vulnerabilities in IBM Datacap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8059"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-54264",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-200",
      "title": "Angular: Sensitive Header Leakage on Cross-Origin Redirects in Angular Service Worker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54264"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-52725",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-79",
      "title": "Angular Template and Dynamic Component Namespace Bypass leading to Cross-Site Scripting (XSS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52725"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-48511",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MessagePack-CSharp",
      "product": "MessagePack-CSharp",
      "cwe": "CWE-407",
      "title": "MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48511"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-48512",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MessagePack-CSharp",
      "product": "MessagePack-CSharp",
      "cwe": "CWE-674",
      "title": "MessagePack-CSharp: JSON conversion APIs can recurse without consistent depth enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48512"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-48513",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MessagePack-CSharp",
      "product": "MessagePack-CSharp",
      "cwe": "CWE-674",
      "title": "MessagePack-CSharp: DynamicUnionResolver generated deserializers miss depth enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48513"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-48515",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MessagePack-CSharp",
      "product": "MessagePack-CSharp",
      "cwe": "CWE-770",
      "title": "MessagePack-CSharp: Multi-dimensional array formatters allocate from unchecked dimensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48515"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-48514",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MessagePack-CSharp",
      "product": "MessagePack-CSharp",
      "cwe": "CWE-770",
      "title": "MessagePack-CSharp: Unity unsafe blit formatter allocates from unbounded byte length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48514"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-48516",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MessagePack-CSharp",
      "product": "MessagePack-CSharp",
      "cwe": "CWE-407",
      "title": "MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48516"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2025-33128",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Engineering Workflow Management",
      "cwe": "CWE-79",
      "title": "IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities HTML / XSS Injection observed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-33128"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-11372",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "TRIRIGA Application Platform",
      "cwe": "CWE-79",
      "title": "IBM TRIRIGA Cross-Site Scripting Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11372"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-44311",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fabricjs",
      "product": "fabric.js",
      "cwe": "CWE-79",
      "title": "Fabric.js: Improper escaping in fabric.Gradient colorStops leads to XSS in SVG serialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44311"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-54298",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "withastro",
      "product": "astro",
      "cwe": "CWE-79",
      "title": "Astro: XSS via Unescaped Attribute Names in Spread Props",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54298"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-46417",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-918",
      "title": "Angular: SSRF via Hostname Hijacking in @angular/platform-server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46417"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-11745",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00219,
      "epss_percentile": 0.12671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LY Corporation",
      "product": "Central Dogma",
      "cwe": "CWE-322",
      "title": "A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host keys for git+ssh:// connections, allowing an on-path attacker to perform man-in-the-middle attacks and compromise mirrored repositories.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11745"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-53540",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00218,
      "epss_percentile": 0.12492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kludex",
      "product": "python-multipart",
      "cwe": "CWE-1284",
      "title": "Python-Multipart: Negative Content-Length in parse_form buffers the entire body in memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53540"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2023-45795",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pilz",
      "product": "PMI v8xx",
      "cwe": "CWE-79",
      "title": "Pilz: XSS vulnerability in Pilz PASvisu and PMI v8xx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-45795"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-7253",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.11049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Sterling B2B Integrator",
      "cwe": "CWE-89",
      "title": "IBM Sterling File Gateway SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7253"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-28381",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Snowflake Datasource",
      "cwe": "CWE-284",
      "title": "Local File Read/Write to Potential Privilege Escalation via Snowflake GET/PUT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28381"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-10530",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Pie Register",
      "cwe": null,
      "title": "Pie Register < 3.8.4.10 - Unauthenticated Email Verification Bypass via Predictable Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10530"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-50557",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-79",
      "title": "Angular: Template and Attribute Namespace Sanitization Bypass (XSS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50557"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-54265",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-79",
      "title": "Angular: Two-Way Property Binding Sanitization Bypass (XSS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54265"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2025-2669",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data",
      "cwe": "CWE-295",
      "title": "Multiple vulnerabilities affect IBM Db2® on Cloud Pak for Data, and Db2 Warehouse on Cloud Pak for Data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-2669"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-50168",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00193,
      "epss_percentile": 0.09396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-346",
      "title": "Angular: URL Parser Differential in @angular/platform-server leading to SSRF Allowlist Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50168"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-9610",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08874,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Datacap",
      "cwe": "CWE-425",
      "title": "Multiple Vulnerabilities in IBM Datacap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9610"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-54282",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kludex",
      "product": "starlette",
      "cwe": "CWE-706",
      "title": "Starlette: Unvalidated request path concatenated into authority poisons request.url.hostname",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54282"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-56357",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-290",
      "title": "n8n - Webhook Forgery via Missing HMAC-SHA256 Signature Verification in GitHub Webhook Trigger",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56357"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-41046",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "presire",
      "product": "qSnapper",
      "cwe": "CWE-23",
      "title": "path traversal via `config` parameter in qSnapper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41046"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-41479",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "authlib",
      "product": "authlib",
      "cwe": "CWE-601",
      "title": "Authlib OAuth 2.0 authorization endpoint open redirects to attacker-controlled redirect_uri on unsupported response_type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41479"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-54267",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.07952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-79",
      "title": "Angular Client Hydration DOM Clobbering & Response-Cache Poisoning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54267"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2024-51454",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.0799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Engineering Workflow Management",
      "cwe": "CWE-644",
      "title": "IBM Engineering Lifecycle Management - Engineering Workflow Management is impacted by vulnerabilities Host Header Injection observed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-51454"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-6645",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00178,
      "epss_percentile": 0.07702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PaperCut",
      "product": "Print Deploy",
      "cwe": "CWE-427",
      "title": "Insecure Search Path Vulnerability in PaperCut Print Deploy Client for Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6645"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-54276",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aio-libs",
      "product": "aiohttp",
      "cwe": "CWE-601",
      "title": "AIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect Challenges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54276"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-54289",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "hono",
      "cwe": "CWE-348",
      "title": "Hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54289"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-53537",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07545,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kludex",
      "product": "python-multipart",
      "cwe": "CWE-20",
      "title": "Python-Multipart: Content-Disposition parameter smuggling via RFC 2231/5987 extended parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53537"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-53538",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00176,
      "epss_percentile": 0.0741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kludex",
      "product": "python-multipart",
      "cwe": "CWE-436",
      "title": "Python-Multipart: Semicolon treated as querystring field separator enables parameter smuggling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53538"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-12602",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aruba",
      "product": "ArubaSign",
      "cwe": "CWE-276",
      "title": "Incorrect permissions in ArubaSign by Aruba",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12602"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-10658",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds access in Bluetooth ISO receive (`bt_iso_recv`) due to missing SDU-header length validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10658"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-50555",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00168,
      "epss_percentile": 0.06493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-79",
      "title": "Angular: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in @angular/platform-server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50555"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-50169",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-200",
      "title": "Angular Service Worker Policy-Bypass & Credential-Stripping Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50169"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-7859",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Motors",
      "cwe": "CWE-862",
      "title": "Motors Car Dealership & Classified Listings < 1.4.110 - Unauthenticated Post-Meta Write via stm_ajax_add_a_car_media",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7859"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-44889",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pylons",
      "product": "webob",
      "cwe": "CWE-601",
      "title": "WebOb: Location header normalization during redirect leads to open redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44889"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-50171",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00161,
      "epss_percentile": 0.05782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-400",
      "title": "Angular: Denial of Service (DoS) via OOM in Number Formatting (digitsInfo)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50171"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-55443",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langchain-ai",
      "product": "langchain",
      "cwe": "CWE-22",
      "title": "LangChain: Path traversal and sandbox escape in LangChain file-search middleware and loaders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55443"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-55599",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phpseclib",
      "product": "phpseclib",
      "cwe": "CWE-918",
      "title": "phpseclib: X.509 certificate validation sends attacker-controlled outbound requests (server-side request forgery) via Authority Information Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55599"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-49241",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.0515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-79",
      "title": "Angular: Multiple Remote Code Execution Vulnerabilities in Angular Language Service VS Code Extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49241"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-50184",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.0477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-200",
      "title": "Angular: Request Credential & Cache Policy Stripping in Angular Service Worker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50184"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-10645",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.04814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in Zephyr ext2 directory entry traversal from a crafted filesystem image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10645"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-41047",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.0473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "presire",
      "product": "qSnapper",
      "cwe": "CWE-306",
      "title": "Information leak via “diff” methods in qSnapper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41047"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-53663",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00148,
      "epss_percentile": 0.04516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "remix-run",
      "product": "react-router",
      "cwe": "CWE-352",
      "title": "React Router: `handleDocumentRequest` CSRF check covers `POST` only; PUT/PATCH/DELETE bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53663"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-54288",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "hono",
      "cwe": "CWE-345",
      "title": "Hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54288"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-8636",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Datacap",
      "cwe": "CWE-316",
      "title": "Multiple Vulnerabilities in IBM Datacap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8636"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-11746",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00145,
      "epss_percentile": 0.04293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LY Corporation",
      "product": "Central Dogma",
      "cwe": "CWE-798",
      "title": "A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secret causes the server to silently fall back to a hard-coded, publicly known secret. This default credential authenticates the embedded ZooKeeper ensemble, allowing an attacker with network access to read the full replication log or join the quorum and execute arbitrary replicated commands across the cluster.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11746"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-12249",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00143,
      "epss_percentile": 0.04091,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "adsys",
      "cwe": "CWE-348",
      "title": "Canonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-Enrollment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12249"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-53655",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "isaacs",
      "product": "node-tar",
      "cwe": "CWE-436",
      "title": "node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53655"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-56109",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "alsa-project",
      "product": "alsa-lib",
      "cwe": "CWE-415",
      "title": "ALSA Library < 1.2.16.1 Double-Free via parse_def() in conf.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56109"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-41049",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.03575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "presire",
      "product": "qSnapper",
      "cwe": "CWE-863",
      "title": "Caching of Authentication allows Authentication Bypass between users in qSnapper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41049"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-41045",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.03472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "presire",
      "product": "qSnapper",
      "cwe": "CWE-367",
      "title": "Weak polkit authentication check in qSnapper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41045"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-41048",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.03289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "presire",
      "product": "qSnapper",
      "cwe": "CWE-863",
      "title": "Caching of Authentication allows Authentication Bypass in qSnapper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41048"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-47242",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.03179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ruby",
      "product": "net-imap",
      "cwe": "CWE-77",
      "title": "Net::IMAP: Command Injection via ID command argument",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47242"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-44274",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Wyse Management Suite (WMS)",
      "cwe": "CWE-59",
      "title": "Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44274"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-49356",
      "cvss_base": 3.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00126,
      "epss_percentile": 0.02697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "babel",
      "product": "babel",
      "cwe": "CWE-22",
      "title": "Babel: Arbitrary File Read via sourceMappingURL Comment in @babel/core",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49356"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-49461",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-400",
      "title": "pypdf: Possible large memory usage for form XObjects during text extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49461"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-54530",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-835",
      "title": "pypdf: Possible infinite loop when retrieving fonts for layout-mode text extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54530"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-54531",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-835",
      "title": "pypdf: Possible infinite loop when processing outlines/bookmarks in writer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54531"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-49460",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-407",
      "title": "pypdf: Inefficient decoding of FlateDecode PNG predictor streams",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49460"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-54099",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift for Windows Containers 10.22",
      "cwe": "CWE-269",
      "title": "Windows-machine-config-operator: windows-machine-config-operator: wicd csr extra-organization allows privilege escalation to system:masters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54099"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-54651",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0011,
      "epss_percentile": 0.01472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-835",
      "title": "pypdf: Possible infinite loop when processing threads/articles in writer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54651"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-44273",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.01168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Wyse Management Suite (WMS)",
      "cwe": "CWE-1392",
      "title": "Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44273"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-54266",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0009,
      "epss_percentile": 0.0052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-328",
      "title": "Angular: Weak 32-Bit Cache Key Hashing in `HttpTransferCache` Leading to Cross-Request Data Leakage and State Poisoning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54266"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-66389",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-66389. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10645",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10645 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10651",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10651 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-12549",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-12549 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41479",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41479 (authlib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41523",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41523 (vllm-project vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44311",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44311 (fabricjs fabric.js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48931",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48931 (nodejs node). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50146",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50146 (withastro astro). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-53550",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-53550 (nodeca js-yaml). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-53571",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-53571 (vitejs vite). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-53655",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-53655 (isaacs node-tar). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54232",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54232 (vllm-project vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54235",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54235 (vllm-project vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54236",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54236 (vllm-project vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54293",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54293 (nltk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54298",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54298 (withastro astro). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55599",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55599 (phpseclib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55602",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55602 (chimurai http-proxy-middleware). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55603",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55603 (chimurai http-proxy-middleware). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56268",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56268 (Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-6653",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-6653 (GNOME libxml2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-6858",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-6858 (Unknown Transbank Webpay). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-20253",
      "detail": "DUE DATE PASSED — CVE-2026-20253 (Splunk Enterprise). CISA remediation deadline was June 21, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
