{
  "day": "2026-06-23",
  "boundary": "UTC calendar day",
  "published_count": 258,
  "by_severity": {
    "CRITICAL": 28,
    "HIGH": 98,
    "MEDIUM": 117,
    "LOW": 11
  },
  "kev_count": 4,
  "exploit_reference_count": 56,
  "awaiting_enrichment_count": 4,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-34910",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.86958,
      "epss_percentile": 0.99731,
      "kev": true,
      "kev_due_at": "2026-06-26",
      "vendor": "Ubiquiti Inc",
      "product": "UniFi OS Server",
      "cwe": "CWE-20",
      "title": "Ubiquiti UniFi OS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34910"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-34908",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.85194,
      "epss_percentile": 0.99697,
      "kev": true,
      "kev_due_at": "2026-06-26",
      "vendor": "Ubiquiti Inc",
      "product": "UniFi OS Server",
      "cwe": "CWE-284",
      "title": "Ubiquiti UniFi OS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34908"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-34909",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.63897,
      "epss_percentile": 0.99156,
      "kev": true,
      "kev_due_at": "2026-06-26",
      "vendor": "Ubiquiti Inc",
      "product": "UniFi OS Server",
      "cwe": "CWE-22",
      "title": "Ubiquiti UniFi OS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34909"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2025-67038",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.13549,
      "epss_percentile": 0.96147,
      "kev": true,
      "kev_due_at": "2026-06-26",
      "vendor": "Lantronix",
      "product": "EDS5000",
      "cwe": null,
      "title": "Lantronix EDS5000",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67038"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-28496",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.17612,
      "epss_percentile": 0.96901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-1336",
      "title": "FOSSBilling: Server-side template injection in Twig template rendering enables information disclosure and RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28496"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-55450",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.11819,
      "epss_percentile": 0.95748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langflow-ai",
      "product": "langflow",
      "cwe": "CWE-200",
      "title": "Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55450"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-56274",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.03273,
      "epss_percentile": 0.87417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-78",
      "title": "Flowise - Remote Code Execution via MCP Security Bypass in validateCommandFlags and validateArgsForLocalFileAccess",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56274"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-53753",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02086,
      "epss_percentile": 0.80068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "unclecode",
      "product": "crawl4ai",
      "cwe": "CWE-94",
      "title": "Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53753"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-11374",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0196,
      "epss_percentile": 0.78718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zohocorp",
      "product": "manageengine_adselfservice_plus",
      "cwe": "CWE-287",
      "title": "Account Takeover via Predictable SSO Ticket Generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11374"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-54157",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01782,
      "epss_percentile": 0.76486,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lobehub",
      "product": "lobehub",
      "cwe": "CWE-918",
      "title": "LobeHub: Unauthenticated SSRF in `/webapi/proxy`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54157"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-53755",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00997,
      "epss_percentile": 0.59966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "unclecode",
      "product": "crawl4ai",
      "cwe": "CWE-918",
      "title": "Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53755"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-56379",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00884,
      "epss_percentile": 0.56398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-116",
      "title": "ImageMagick - Command Injection via SVG Decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56379"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-44789",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00876,
      "epss_percentile": 0.56184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-1321",
      "title": "n8n: HTTP Request Node Pagination Prototype Pollution to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44789"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-48020",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00866,
      "epss_percentile": 0.55843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-288",
      "title": "Traefik StripPrefix Route-Level Auth Bypass via Path Normalization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48020"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-48519",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00823,
      "epss_percentile": 0.54501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langflow-ai",
      "product": "langflow",
      "cwe": "CWE-94",
      "title": "Langflow: Unauthenticated RCE in Shareable Playgrounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48519"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-39253",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00805,
      "epss_percentile": 0.53927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-502",
      "title": "An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39253"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-54512",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00779,
      "epss_percentile": 0.53057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FasterXML",
      "product": "jackson-databind",
      "cwe": "CWE-184",
      "title": "jackson-databind: PolymorphicTypeValidator bypass via generic type parameters allows arbitrary class instantiation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54512"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-56315",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00757,
      "epss_percentile": 0.52363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-184",
      "title": "picklescan - Remote Code Execution via Unblocked Standard Library Modules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56315"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-34916",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00754,
      "epss_percentile": 0.5224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revive Adserver",
      "product": "Revive Adserver",
      "cwe": "CWE-94",
      "title": "A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject malicious PHP code into the compiledlimitations field on the database and have it executed during banner delivery. Input sanitisation has been improved to ensure that the parameter is properly validated.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34916"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-11940",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0075,
      "epss_percentile": 0.52136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Software Foundation",
      "product": "CPython",
      "cwe": "CWE-22",
      "title": "tarfile extraction filter bypass allows escaping the destination directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11940"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-54513",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00712,
      "epss_percentile": 0.50781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FasterXML",
      "product": "jackson-databind",
      "cwe": "CWE-184",
      "title": "jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54513"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-54892",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00707,
      "epss_percentile": 0.50609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-plug",
      "product": "plug",
      "cwe": "CWE-407",
      "title": "Plug: quadratic-time decoding of nested query/body parameters enables denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54892"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-56258",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0067,
      "epss_percentile": 0.49183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crawl4AI",
      "product": "Crawl4AI",
      "cwe": "CWE-22",
      "title": "Crawl4AI - Arbitrary File Write via output_path Symlink and TOCTOU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56258"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-35018",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00664,
      "epss_percentile": 0.48972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NetComm Wireless Pty Ltd",
      "product": "NF20MESH",
      "cwe": "CWE-78",
      "title": "NetComm NF20MESH < R6B032 Authenticated RCE via OS Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35018"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-44790",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00646,
      "epss_percentile": 0.48216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-88",
      "title": "n8n: Arbitrary File Read via Git Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44790"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-44791",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00634,
      "epss_percentile": 0.4766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-1321",
      "title": "n8n: XML Node Prototype Pollution Patch Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44791"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-50023",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0062,
      "epss_percentile": 0.47002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yt-dlp",
      "product": "yt-dlp",
      "cwe": "CWE-641",
      "title": "yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50023"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2023-54365",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00566,
      "epss_percentile": 0.44514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Traefik",
      "product": "Traefik",
      "cwe": "CWE-400",
      "title": "Traefik - Denial of Service via HTTP/2 Request Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-54365"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-45135",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00501,
      "epss_percentile": 0.40808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "caddyserver",
      "product": "caddy",
      "cwe": "CWE-20",
      "title": "Caddy: Unsafe Unicode Handling in FastCGI splitPos Allows Execution of Non-PHP Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45135"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-12866",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00496,
      "epss_percentile": 0.40538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "expr-eval",
      "cwe": "CWE-94",
      "title": "All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code within the application's context.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12866"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-49465",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00495,
      "epss_percentile": 0.40483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-22",
      "title": "n8n: Git Node Clone and Push Operations Bypass File Sandbox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49465"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-52844",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00478,
      "epss_percentile": 0.3942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "caddyserver",
      "product": "caddy",
      "cwe": "CWE-22",
      "title": "Caddy: Windows `file_server` path authorization bypass via encoded backslash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52844"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2025-61018",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00476,
      "epss_percentile": 0.39307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61018"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2025-61020",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00476,
      "epss_percentile": 0.39308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61020"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2025-61023",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00476,
      "epss_percentile": 0.39308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61023"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2025-61028",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00476,
      "epss_percentile": 0.39308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61028"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-35019",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NetComm Wireless Pty Ltd",
      "product": "NF20MESH",
      "cwe": "CWE-321",
      "title": "NetComm NF20MESH < R6B032 Hardcoded AES Key Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35019"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-55447",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00469,
      "epss_percentile": 0.38786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langflow-ai",
      "product": "langflow",
      "cwe": "CWE-61",
      "title": "Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55447"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-44959",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revive",
      "product": "Adserver",
      "cwe": "CWE-94",
      "title": "A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an unexpected component parameter and inject malicious PHP code into the compiledlimitations field, which would then be executed during banner delivery. Input sanitisation has been improved to ensure that unexpected parameters are filtered out.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44959"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2025-71341",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-502",
      "title": "picklescan - Remote Code Execution via Undetected profile.Profile.runctx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71341"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-50193",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00459,
      "epss_percentile": 0.38153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FasterXML",
      "product": "jackson-databind",
      "cwe": "CWE-400",
      "title": "jackson-databind: Deeply nested JsonNode throws StackOverflowError for toString()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50193"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-11972",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.37184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Software Foundation",
      "product": "CPython",
      "cwe": "CWE-252",
      "title": "tarfile opened in streaming mode mishandles EOF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11972"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-52673",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00437,
      "epss_percentile": 0.36585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote attacker to execute arbitrary code via the getDimensionsValues component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52673"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-13007",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tenable",
      "product": "Tenable Identity Exposure",
      "cwe": "CWE-306",
      "title": "Insecure Public Caching on REST API Endpoints in Tenable Identity Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13007"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-54305",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00431,
      "epss_percentile": 0.36081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-200",
      "title": "n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54305"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-55654",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00431,
      "epss_percentile": 0.36097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Openssh: heap out-of-bounds read in red hat enterprise linux versions of openssh gssapi indicator cleanup due to missing null sentinel termination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55654"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-54314",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00426,
      "epss_percentile": 0.3574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-409",
      "title": "n8n: Denial of Service via ZIP decompression in webhook workflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54314"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-41862",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Statemachine",
      "cwe": "CWE-502",
      "title": "Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM. Affected versions: Spring Statemachine 4.0.0 through 4.0.1 Spring Statemachine 3.2.0 through 3.2.4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41862"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-11807",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00416,
      "epss_percentile": 0.34908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-862",
      "title": "Eda-server: websocket missing authorization allows credential theft via activation_id spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11807"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-48520",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00409,
      "epss_percentile": 0.34251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langflow-ai",
      "product": "langflow",
      "cwe": "CWE-73",
      "title": "Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48520"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-27604",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00408,
      "epss_percentile": 0.34143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-200",
      "title": "FOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privileged Admin Functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27604"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-54762",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00407,
      "epss_percentile": 0.34063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-636",
      "title": "Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54762"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-50574",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00406,
      "epss_percentile": 0.34007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yt-dlp",
      "product": "yt-dlp",
      "cwe": "CWE-74",
      "title": "yt-dlp: Arbitrary code execution via manifest downloads with aria2c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50574"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-54309",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-306",
      "title": "n8n: n8n MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54309"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-54316",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00403,
      "epss_percentile": 0.3378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "anthropics",
      "product": "claude-code",
      "cwe": "CWE-183",
      "title": "Claude Code: Out-of-Band Data Exfiltration via Pre-Approved HuggingFace Domain in WebFetch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54316"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-54310",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00394,
      "epss_percentile": 0.32812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-89",
      "title": "n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54310"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2025-55639",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00383,
      "epss_percentile": 0.3158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomedia/isom_write.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55639"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2025-71370",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00379,
      "epss_percentile": 0.31249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-502",
      "title": "picklescan - Remote Code Execution via torch.jit.unsupported_tensor_ops.execWrapper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71370"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-11772",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00378,
      "epss_percentile": 0.31078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DRIMO",
      "product": "DRIMO CMS",
      "cwe": "CWE-79",
      "title": "Reflected XSS in DRIMO CMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11772"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-56248",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00359,
      "epss_percentile": 0.29105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo",
      "cwe": "CWE-400",
      "title": "Capgo - Unauthenticated Denial-of-Service via audit_logs RLS Policy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56248"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-33760",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00357,
      "epss_percentile": 0.28912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langflow-ai",
      "product": "langflow",
      "cwe": "CWE-639",
      "title": "Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33760"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-56222",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00356,
      "epss_percentile": 0.28843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-639",
      "title": "Capgo - Cross-Organization App Takeover via Mismatched org_id and app_id in /private/role_bindings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56222"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-49444",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00356,
      "epss_percentile": 0.28837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-20",
      "title": "n8n: Python sandbox escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49444"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-54304",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-200",
      "title": "n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54304"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2025-71337",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-620",
      "title": "Flowise - Unverified Email Change via Account Profile Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71337"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2025-61019",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61019"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2025-61021",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61021"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2025-61022",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.2825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61022"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2025-61024",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.2825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61024"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2025-61025",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.2825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61025"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2025-61027",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.2825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61027"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2025-61029",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-61029"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-42867",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00348,
      "epss_percentile": 0.27991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langflow-ai",
      "product": "langflow",
      "cwe": "CWE-22",
      "title": "Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42867"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-54307",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-863",
      "title": "n8n: Credential Exfiltration via Permission Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54307"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-55446",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langflow-ai",
      "product": "langflow",
      "cwe": "CWE-400",
      "title": "Langflow: Unauthenticated DoS through multipart form boundary file upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55446"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-54515",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FasterXML",
      "product": "jackson-databind",
      "cwe": "CWE-915",
      "title": "jackson-databind: Case-insensitive deserialization bypasses per-property @JsonIgnoreProperties",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54515"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-56115",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "garybowers",
      "product": "bootimus",
      "cwe": "CWE-862",
      "title": "Bootimus 0.1.70 Broken Access Control via JWTMiddleware Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56115"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-9733",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00339,
      "epss_percentile": 0.26919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HAYAJO",
      "product": "Mojolicious::Plugin::Web::Auth::OAuth2",
      "cwe": "CWE-338",
      "title": "Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9733"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-44956",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.00339,
      "epss_percentile": 0.27034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revive",
      "product": "Adserver",
      "cwe": "CWE-79",
      "title": "Low‑privileged users could use their Full Name as a vector for a stored XSS attack. The name is included in system‑generated emails, whose content is stored in the details field of the userlog table. An admin user viewing the email content through userlog-details.php would have any malicious JavaScript payload executed due to missing output sanitisation. Proper escaping has been added to the userlog details output.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44956"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-44960",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.00339,
      "epss_percentile": 0.27034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revive",
      "product": "Adserver",
      "cwe": "CWE-79",
      "title": "A stored XSS can be exploited by leveraging the usernames as an attack vector. When an admin user viewed the audit log details for affected entries, any malicious JavaScript payload embedded in the username would be executed due to missing output sanitisation. Proper escaping has been added to the audit log details output.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44960"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-44961",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.00338,
      "epss_percentile": 0.26811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revive",
      "product": "Adserver",
      "cwe": "CWE-287",
      "title": "The XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users could create usernames that enabled impersonation or stored XSS attacks. Proper validation has been added where it was missing.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44961"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-49402",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.2649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "denoland",
      "product": "deno",
      "cwe": "CWE-78",
      "title": "Deno: Command Injection via spawnSync & spawn on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49402"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-54018",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-918",
      "title": "Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54018"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-54019",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00335,
      "epss_percentile": 0.26514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-862",
      "title": "Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54019"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-56322",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-200",
      "title": "Capgo - Information Disclosure via Unauthenticated /updates defaultChannel Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56322"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-44792",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00331,
      "epss_percentile": 0.26131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-89",
      "title": "n8n: Source Control Pull SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44792"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-55249",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00331,
      "epss_percentile": 0.26133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rtk-ai",
      "product": "rtk",
      "cwe": "CWE-78",
      "title": "@rtk-ai/rtk-rewrite: OpenClaw Rewrite Plugin Command Injection via execSync Template String",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55249"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-47385",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00324,
      "epss_percentile": 0.25319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-22",
      "title": "NocoDB: Path Traversal via SQLite Source Filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47385"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2025-71382",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArtifexSoftware",
      "product": "mupdf",
      "cwe": "CWE-674",
      "title": "MuPDF < 1.27.0-rc1 Stack Exhaustion DoS via EPUB CSS Rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71382"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-45732",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.25041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-639",
      "title": "n8n: Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45732"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-34917",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00321,
      "epss_percentile": 0.25039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revive",
      "product": "Adserver",
      "cwe": "CWE-287",
      "title": "Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restricted to admin users. An attacker could leverage this to gain unauthorised access and exploit API‑level vulnerabilities. The session context (web/API) is now recorded along with other session data, preventing session IDs from being used interchangeably.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34917"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-54022",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0032,
      "epss_percentile": 0.24898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-706",
      "title": "Open WebUI: Any authenticated user can read other users' private notes via Socket.IO",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54022"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-54761",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-284",
      "title": "Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54761"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-54311",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-488",
      "title": "n8n: Merge Node SQL Mode Prototype Pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54311"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-10521",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.24073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-425",
      "title": "Authenticated unintended access to critical program parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10521"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-47381",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-290",
      "title": "NocoDB: Cross-Workspace Integration Use in Connection Test",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47381"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-54588",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00312,
      "epss_percentile": 0.24045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "poweradmin",
      "product": "poweradmin",
      "cwe": "CWE-20",
      "title": "Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54588"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-34914",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revive",
      "product": "Adserver",
      "cwe": "CWE-89",
      "title": "A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters processed by the script are properly validated.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34914"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-46552",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.23386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-285",
      "title": "NocoDB: Shared-base link access can invite arbitrary users as persistent base members",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46552"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-47384",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00306,
      "epss_percentile": 0.23322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-89",
      "title": "NocoDB: SQL Injection via Column Title in Bulk GroupBy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47384"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2025-71365",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-502",
      "title": "picklescan - Arbitrary Code Execution via numpy.f2py.crackfortran.myeval Detection Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71365"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2025-71376",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-502",
      "title": "picklescan - Arbitrary Code Execution via Undetected idlelib.autocomplete.AutoComplete.fetch_completions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71376"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-54517",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00297,
      "epss_percentile": 0.22305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FasterXML",
      "product": "jackson-databind",
      "cwe": "CWE-863",
      "title": "jackson-databind: @JsonView bypass for setterless creator properties",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54517"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-53931",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-441",
      "title": "NocoDB: Server-Side Request Forgery via Spreadsheet Import Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53931"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-53926",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-613",
      "title": "NocoDB: OAuth Tokens Persist Through Security Events",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53926"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-54312",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.22001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-1321",
      "title": "n8n: Microsoft SQL Node Prototype Pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54312"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-56225",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.2182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-269",
      "title": "Capgo - Authorization Bypass in API Key Management via App-Limited Keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56225"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-54010",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-284",
      "title": "Open WebUI: Forged chat-file link allows cross-user file read and deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54010"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-54317",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.2176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "home-assistant",
      "product": "core",
      "cwe": "CWE-200",
      "title": "Home Assistant: Konnected alarm-panel switch state and zone topology disclosed to unauthenticated actors on the LAN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54317"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-52845",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "caddyserver",
      "product": "caddy",
      "cwe": "CWE-287",
      "title": "Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52845"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-55653",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-415",
      "title": "Openssh: double free in red hat enterprise linux versions of openssh dh-gex client path during fips known-group validation leads to client-side denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55653"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-53622",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-288",
      "title": "Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53622"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-47383",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-79",
      "title": "NocoDB: Stored Cross-Site Scripting via Row Comments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47383"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-53929",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21431,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-79",
      "title": "NocoDB: Stored Cross-Site Scripting via Secure Attachment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53929"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-53930",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-918",
      "title": "NocoDB: Server-Side Request Forgery via Base Migration URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53930"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-11820",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.2128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-532",
      "title": "Community.general: community.general nexmo — api credentials exposed in get url query string[security] community.general nexmo — api credentials exposed in get url query string",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11820"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-54014",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.21227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-22",
      "title": "Open WebUI: Sibling-Prefix Path Traversal via /cache/{path} in open-webui/open-webui",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54014"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-56968",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.21136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "GNU SASL",
      "cwe": "CWE-908",
      "title": "GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56968"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-54516",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00283,
      "epss_percentile": 0.20842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FasterXML",
      "product": "jackson-databind",
      "cwe": "CWE-915",
      "title": "jackson-databind: Renamed @JsonIgnore'd setters can deserialize via private fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54516"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-23513",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-863",
      "title": "FOSSBilling: Broken Authorization in Client Transaction and Order Listings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23513"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-53927",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-918",
      "title": "NocoDB: Server-Side Request Forgery via Spreadsheet Fetch URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53927"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-48491",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-288",
      "title": "Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48491"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-54308",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-290",
      "title": "n8n: Missing Token Validation on Microsoft Agent 365 Trigger Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54308"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-54324",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "daytonaio",
      "product": "daytona",
      "cwe": "CWE-639",
      "title": "Daytona: Cross-tenant data leak in notification WebSocket gateway via unverified organizationId join",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54324"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-44958",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.19882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revive",
      "product": "Adserver",
      "cwe": "CWE-284",
      "title": "An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and earlier, even when such permissions were not granted. The banner-edit.php script allowed the banner status to be overwritten solely based on banner edit permissions. The status field has been removed from the hidden form fields in the banner edit screen.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44958"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-56243",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-288",
      "title": "Capgo - Hashed API Key Enforcement Bypass via PostgREST/RLS Plane",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56243"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-12891",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Gstreamer1-plugins-bad: gstreamer1-plugins-bad: global buffer overflow (oob read) in h.266/vvc vui parameter parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12891"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-50019",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yt-dlp",
      "product": "yt-dlp",
      "cwe": "CWE-200",
      "title": "yt-dlp: File Downloader cookie leak with curl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50019"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-53754",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "unclecode",
      "product": "crawl4ai",
      "cwe": "CWE-918",
      "title": "Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT64 / 6to4 / unspecified / v4-mapped)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53754"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-54009",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00267,
      "epss_percentile": 0.18971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-639",
      "title": "Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54009"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2025-64105",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.18559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-639",
      "title": "FOSSBilling: IDOR Vulnerability in Support Ticket Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64105"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-54518",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.1847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FasterXML",
      "product": "jackson-databind",
      "cwe": "CWE-863",
      "title": "jackson-databind: @JsonView bypass for unwrapped creator parameters in jackson-databind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54518"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-47376",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.18154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-79",
      "title": "NocoDB: Reflected Cross-Site Scripting via Password Reset Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47376"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-54313",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-89",
      "title": "n8n: NoSQL Injection in MongoDB Node Find And Replace Operation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54313"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-54306",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.1774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-1321",
      "title": "n8n: Prototype Pollution enables confused-deputy execution via public webhooks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54306"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-54016",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-639",
      "title": "Open WebUI: Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54016"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-56784",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openremote",
      "product": "openremote",
      "cwe": "CWE-639",
      "title": "OpenRemote < 1.25.0 IDOR via Bulk Alarm Deletion Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56784"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-56371",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.1756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-401",
      "title": "ImageMagick - Memory Leak in TXT File Processing via Texture Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56371"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-12958",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amazon Web Services",
      "product": "Language Servers for AWS",
      "cwe": "CWE-61",
      "title": "Arbitrary file write in Language Servers for AWS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12958"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-54257",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00253,
      "epss_percentile": 0.16993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron",
      "product": "electron",
      "cwe": "CWE-120",
      "title": "Electron: Buffer performs incorrect byte length calculations resulting in heap buffer under/overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54257"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-47379",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.16994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-200",
      "title": "NocoDB: Plaintext Password Comparison in Shared Views",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47379"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-54321",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16486,
      "kev": false,
      "kev_due_at": null,
      "vendor": "daytonaio",
      "product": "daytona",
      "cwe": "CWE-613",
      "title": "Daytona: Public sandbox previews remain accessible for up to one hour after being made private",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54321"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-56234",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.1625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-307",
      "title": "Capgo - Password Spraying via Public-Key Accessible Credential Validation Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56234"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-56762",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hono",
      "product": "Hono",
      "cwe": "CWE-20",
      "title": "Hono - Missing Cookie Name Validation in setCookie()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56762"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-8379",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.15964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Frontend File Manager Plugin",
      "cwe": null,
      "title": "Frontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8379"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-34913",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revive",
      "product": "Adserver",
      "cwe": "CWE-284",
      "title": "A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to link their trackers to campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that campaigns can only be linked to trackers owned by the same advertiser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34913"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-44957",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revive",
      "product": "Adserver",
      "cwe": "CWE-284",
      "title": "A missing access control check when invoking various modify methods in the XML‑RPC API of Revive Adserver 6.0.6 and earlier. The API allowed entities to be reassigned to different parent entities, leading to inconsistent ownership relationships. This issue was exploitable only in combination with CVE‑2026‑34917 or with third‑party API extensions that expose API functionality to low‑privileged users. Access control checks have been added to validate access to parent entities in the API modify methods.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44957"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-56785",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.1572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FlatPress",
      "product": "FlatPress",
      "cwe": "CWE-79",
      "title": "FlatPress - Stored Cross-Site Scripting via Unescaped Comment and Contact Form Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56785"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-53928",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-613",
      "title": "NocoDB: Refresh Tokens Persist Through Password Recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53928"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-46553",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0024,
      "epss_percentile": 0.15318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-770",
      "title": "NocoDB: Attachment Size Limit Bypass via Upload-by-URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46553"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-54012",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-284",
      "title": "Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54012"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-47279",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-284",
      "title": "NocoDB: Hidden LTAR Column Exposure in Public Shared-View Relation Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47279"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-47378",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-639",
      "title": "NocoDB: Hidden Column Exposure in Public Shared View Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47378"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-12969",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Dnsmasq: dnsmasq: out-of-bounds read in find_soa() due to missing extrabytes validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12969"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-47377",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.1531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-601",
      "title": "NocoDB: Open Redirect via Hash Fragment in hashRedirect Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47377"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-8163",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Infility Global",
      "cwe": null,
      "title": "Infility Global < 2.15.19 - Subscriber+ SQL Injection via order Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8163"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-53662",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00235,
      "epss_percentile": 0.1479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "immich-app",
      "product": "immich",
      "cwe": "CWE-79",
      "title": "immich: One-click account takeover via XSS in login page continue redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53662"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-46551",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-770",
      "title": "NocoDB: Missing File Size Enforcement in Upload-by-URL Allows Denial of Service via Disk Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46551"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-34912",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revive",
      "product": "Adserver",
      "cwe": "CWE-284",
      "title": "A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier, or via its API allows a low‑privileged user could link their zones to banners or campaigns owned by other managers on the same instance, resulting in inconsistent ownership relationships. Ownership validation has been added to ensure that banners and campaigns can only be linked to zones managed by the same account.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34912"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-10711",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AKIN Software Computer Import Export Industry and Trade Ltd.",
      "product": "CafePlus",
      "cwe": "CWE-306",
      "title": "RCE in Akınsoft's CafePlus",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10711"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-47387",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-79",
      "title": "NocoDB: Stored Cross-Site Scripting via Form View Redirect URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47387"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-56701",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00233,
      "epss_percentile": 0.14479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grav",
      "product": "Grav",
      "cwe": "CWE-611",
      "title": "Grav - XML External Entity Injection via SVG Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56701"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-54008",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-918",
      "title": "Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54008"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-56695",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "OpenHarness",
      "cwe": "CWE-862",
      "title": "OpenHarness - Cross-Session Disclosure via /resume and /summary Commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56695"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-54011",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-79",
      "title": "Open WebUI: Stored XSS in Mermaid Markdown Preview",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54011"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-44089",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0023,
      "epss_percentile": 0.14045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Totolink",
      "product": "EX1200L",
      "cwe": "CWE-121",
      "title": "Buffer Overflow in Totolink EX1200L router",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44089"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-47693",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "poweradmin",
      "product": "poweradmin",
      "cwe": "CWE-1236",
      "title": "Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47693"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-10609",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Logging Subsystem for Red Hat OpenShift",
      "cwe": "CWE-862",
      "title": "Openshift/cluster-logging-operator: cluster logging operator creates and forwards serviceaccount tokens without verifying clf creator authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10609"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-34915",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revive",
      "product": "Adserver",
      "cwe": "CWE-79",
      "title": "A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit the clientid parameter to perform blind SQL injection attacks. Input sanitisation has been improved to ensure that all parameters processed by the script are properly validated.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34915"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-12957",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.1326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amazon Web Services",
      "product": "Language Servers for AWS",
      "cwe": "CWE-732",
      "title": "Arbitrary Code Execution in Language Servers for AWS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12957"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-7842",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Infility Global",
      "cwe": null,
      "title": "Infility Global < 2.15.20 - Editor+ SQL Injection via orderby Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7842"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-4983",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Open VSX",
      "cwe": "CWE-79",
      "title": "Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content-Type: image/svg+xml without security headers such as Content-Security-Policy or Content-Disposition: attachment. This allows an attacker to publish an extension with a malicious SVG icon and achieve stored cross-site scripting (XSS) when a user navigates directly to the icon URL. On deployments using local storage, script execution occurs within the Open VSX application origin, enabling session hijacking, authentication token theft, and unauthorized extension publishing. On deployments backed by external storage (such as open-vsx.org with an S3-backed CDN), execution is confined to the storage origin, reducing impact but still permitting phishing attacks and credential harvesting through attacker-crafted pages.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4983"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-54514",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FasterXML",
      "product": "jackson-databind",
      "cwe": "CWE-918",
      "title": "jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (SSRF)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54514"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-11833",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00217,
      "epss_percentile": 0.12455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yokogawa Electric Corporation",
      "product": "FAST/TOOLS",
      "cwe": "CWE-319",
      "title": "Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing the CI Server setting information. This information could be exploited by an attacker for other attacks. The affected products and versions are as follows: FAST/TOOLS (Packages: RVSVRN, UNSVRN, HMIWEB, FTEES, HMIMOB) R9.01 to R10.04 CI Server (All packages) R1.01 to R1.04",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11833"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-54301",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00217,
      "epss_percentile": 0.12386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-79",
      "title": "n8n: Same-Origin XSS in Respond to Webhook Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54301"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-56696",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "OpenHarness",
      "cwe": "CWE-862",
      "title": "OpenHarness - Prompt Injection via /issue and /pr_comments Slash Commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56696"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-54320",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.1218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "daytonaio",
      "product": "daytona",
      "cwe": "CWE-287",
      "title": "Daytona: Cross-tenant organization takeover via invitation acceptance with an unverified email",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54320"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2025-62180",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pegasystems",
      "product": "Pega Infinity",
      "cwe": "CWE-639",
      "title": "Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62180"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-47375",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-89",
      "title": "NocoDB: Postgres SQL Injection in Formula `ARRAYSORT`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47375"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-56275",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-918",
      "title": "Flowise - Server-Side Request Forgery via Execute Flow Base URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56275"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-56402",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.11948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nanocoai",
      "product": "nanoclaw",
      "cwe": "CWE-862",
      "title": "NanoClaw < 2.1.17 - Privilege Escalation via Unverified Approval Response Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56402"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-54302",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-79",
      "title": "n8n: Stored XSS in Chat Trigger Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54302"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-54021",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-863",
      "title": "Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54021"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-47388",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-639",
      "title": "NocoDB: Missing Ownership Check in MCP Attachment Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47388"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-47382",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-918",
      "title": "NocoDB: Server-Side Request Forgery via Database Connection Host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47382"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-54006",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-639",
      "title": "Open WebUI: Calendar event re-parenting allows writing events into another user's calendar",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54006"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-54013",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.10411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-79",
      "title": "Open WebUI: Stored XSS to Account Takeover via Model Profile Images in Open WebUI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54013"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-54015",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-284",
      "title": "Open WebUI: Prompt history IDOR: unbound history_id allows cross-prompt read and deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54015"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-47380",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-208",
      "title": "NocoDB: User Enumeration via Sign-In Timing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47380"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-47386",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-362",
      "title": "NocoDB: OAuth Authorization Code Race Condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47386"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-46554",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00197,
      "epss_percentile": 0.09767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-613",
      "title": "NocoDB: Stale Auth Cache After API Token Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46554"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-4610",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "metagauss",
      "product": "ProfileGrid – User Profiles, Groups and Communities",
      "cwe": "CWE-79",
      "title": "ProfileGrid <= 5.9.9.2 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Message Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4610"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-56263",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crawl4AI",
      "product": "Crawl4AI",
      "cwe": "CWE-79",
      "title": "Crawl4AI - Stored Cross-Site Scripting in Monitor Dashboard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56263"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-55423",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langflow-ai",
      "product": "langflow",
      "cwe": "CWE-613",
      "title": "Langflow: Logout button does not clear session",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55423"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-52846",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "caddyserver",
      "product": "caddy",
      "cwe": "CWE-116",
      "title": "Caddy: stripHTML template function bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52846"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-56116",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.08735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NetworkConfiguration",
      "product": "dhcpcd",
      "cwe": "CWE-401",
      "title": "dhcpcd Memory Leak DoS via IPv6 Router Advertisement Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56116"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-49401",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00187,
      "epss_percentile": 0.08608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "denoland",
      "product": "deno",
      "cwe": "CWE-41",
      "title": "Deno Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49401"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-54322",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "daytonaio",
      "product": "daytona",
      "cwe": "CWE-639",
      "title": "Daytona: Cross-org IDOR in organization role update/delete — any org owner can rewrite or destroy another org's roles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54322"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2020-9711",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-125",
      "title": "Acrobat Reader | Out-of-bounds Read (CWE-125)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-9711"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2020-9713",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-125",
      "title": "Acrobat Reader | Out-of-bounds Read (CWE-125)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-9713"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-56376",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-416",
      "title": "ImageMagick - Heap Use-After-Free in Meta Coder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56376"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-55517",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "denoland",
      "product": "deno",
      "cwe": "CWE-248",
      "title": "Deno: Denial of service via non-ASCII bytes in WebSocket response headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55517"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-48493",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-863",
      "title": "Snipe-IT Vulnerable to Privilege Escalation for self via API Permissions Assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48493"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2020-9695",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.08045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-787",
      "title": "Acrobat Reader | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-9695"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-54303",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-79",
      "title": "n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54303"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-46548",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-918",
      "title": "NocoDB: SSRF Protection Bypass in Notification Webhook Plugins (Slack, Discord, Mattermost, Teams)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46548"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-54007",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-346",
      "title": "Open WebUI: Cross-origin postMessage confirmation bypass via action:submit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54007"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-56113",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NetworkConfiguration",
      "product": "dhcpcd",
      "cwe": "CWE-416",
      "title": "dhcpcd Heap Use-After-Free in dhcp6_deprecateaddrs via DHCPv6 RENEW",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56113"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-56114",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NetworkConfiguration",
      "product": "dhcpcd",
      "cwe": "CWE-787",
      "title": "dhcpcd Stack Out-of-Bounds Write in dhcp6_makemessage()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56114"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-54319",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "daytonaio",
      "product": "daytona",
      "cwe": "CWE-22",
      "title": "Daytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54319"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-49406",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "denoland",
      "product": "deno",
      "cwe": "CWE-22",
      "title": "Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49406"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-56694",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nanocoai",
      "product": "nanoclaw",
      "cwe": "CWE-863",
      "title": "NanoClaw < 2.1.0 - Privilege Escalation via Forged Channel Approval Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56694"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-44726",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00169,
      "epss_percentile": 0.06665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "denoland",
      "product": "deno",
      "cwe": "CWE-319",
      "title": "Deno: TLS retry copies stale upgrade hook, risking plaintext traffic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44726"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-45692",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00167,
      "epss_percentile": 0.06407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "caddyserver",
      "product": "caddy",
      "cwe": "CWE-187",
      "title": "Caddy: Remote Admin Authorization Bypass in `/config` API via Array Index Normalization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45692"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-8172",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Simple Basic Contact Form",
      "cwe": null,
      "title": "Simple Basic Contact Form <= 20250114 - Reflected XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8172"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-55766",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guzzle",
      "product": "psr7",
      "cwe": "CWE-93",
      "title": "guzzlehttp/psr7: CRLF Injection in HTTP Start-Line Serialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55766"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-46547",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-79",
      "title": "NocoDB: Reflected Cross-Site Scripting via Page Leaving Redirect URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46547"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-56815",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.05208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rasta-mouse",
      "product": "pwnlift",
      "cwe": "CWE-61",
      "title": "pwnlift before d7a9544, in a privileged deployment, contains a symlink following vulnerability in the upload handler in Components/Pages/Home.razor.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56815"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-5818",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.05232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Caliptra",
      "product": "Core Runtime Firmware",
      "cwe": "CWE-253",
      "title": "MCU Firmware Update Authentication Bypass on Caliptra Core",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5818"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-12112",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00153,
      "epss_percentile": 0.04978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6.18",
      "cwe": "CWE-287",
      "title": "Foreman-mcp-server: mcp server: active session hijacking via insecure session state reuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12112"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-9073",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6.18",
      "cwe": "CWE-532",
      "title": "Foreman-mcp-server: mcp server: insecure sensitive http header sanitization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9073"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-55736",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04874,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ash-project",
      "product": "ash",
      "cwe": "CWE-915",
      "title": "Private action arguments can be set by user input in Ash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55736"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-46549",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00151,
      "epss_percentile": 0.04771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-863",
      "title": "NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46549"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-49440",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "denoland",
      "product": "deno",
      "cwe": "CWE-325",
      "title": "Deno: Miller-Rabin Primality Test Allows Zero Rounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49440"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-10857",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AKIN Software Computer Import Export Industry and Trade Ltd.",
      "product": "e-Commerce",
      "cwe": "CWE-79",
      "title": "Reflected XSS in Akinsoft's e-Commerce",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10857"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-57053",
      "cvss_base": 2.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00149,
      "epss_percentile": 0.04619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "libidn",
      "cwe": "CWE-1284",
      "title": "GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57053"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-12163",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortra",
      "product": "File Integrity Monitoring (FIM)",
      "cwe": "CWE-79",
      "title": "Stored XSS in Fortra File Integrity Monitoring (FIM)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12163"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-49411",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "denoland",
      "product": "deno",
      "cwe": "CWE-284",
      "title": "Deno Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49411"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-50221",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Swift",
      "cwe": "CWE-918",
      "title": "In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redirect container update requests to an attacker-controlled server, enabling server-side request forgery. The SSRF requests expose internal cluster metadata including storage policy indexes, partition mappings, device names, and when at rest encryption is enabled, cipher text and initialization vectors for the container-level encryption key. The attacker can also cause \"ghost listings\" in arbitrary containers via the shard-range redirect mechanism.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50221"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-55767",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guzzle",
      "product": "guzzle",
      "cwe": "CWE-346",
      "title": "Guzzle: Dot-Only Cookie Domains Match All Hosts in guzzlehttp/guzzle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55767"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-57062",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00142,
      "epss_percentile": 0.04042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GnuPG",
      "product": "GnuPG",
      "cwe": "CWE-1284",
      "title": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57062"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-7574",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anthropic",
      "product": "Claude Desktop Cowork",
      "cwe": "CWE-353",
      "title": "Anthropic Claude Desktop Cowork VM Image Contents Not Validated Before Use",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7574"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-54318",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "home-assistant",
      "product": "core",
      "cwe": "CWE-926",
      "title": "Home Assistant: Exported BroadcastReceiver allows local apps to spoof device location",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54318"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-8378",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Frontend File Manager Plugin",
      "cwe": null,
      "title": "Frontend File Manager Plugin <= 23.6 - Subscriber+ Stored Cross-Site Scripting via File Rename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8378"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-54326",
      "cvss_base": 2.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00132,
      "epss_percentile": 0.03234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "earendil-works",
      "product": "pi",
      "cwe": "CWE-79",
      "title": "Pi: Potential XSS in HTML session exports via Markdown URL sanitization bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54326"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-56692",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.0314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nanocoai",
      "product": "nanoclaw",
      "cwe": "CWE-59",
      "title": "NanoClaw < 2.1.17 - Arbitrary File Read via Symlink Following in forwardAttachedFiles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56692"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-54555",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rtk-ai",
      "product": "rtk",
      "cwe": "CWE-863",
      "title": "rtk: Permission-gate bypass in rtk rewrite auto-allow via unsplit shell separators",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54555"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-6458",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Caliptra",
      "product": "Core Runtime Firmware",
      "cwe": "CWE-325",
      "title": "AES-256-GCM Authentication Tag Does Not Cover First Ciphertext Blocks When AAD Is Empty",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6458"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-0864",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Software Foundation",
      "product": "CPython",
      "cwe": "CWE-74",
      "title": "Configuration Injection via Carriage Return (\\r) in write() method",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0864"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-11819",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-532",
      "title": "Community.general: community.general keyring_info — os keyring passphrase returned in plaintext",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11819"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-54325",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.02039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "earendil-works",
      "product": "pi",
      "cwe": "CWE-829",
      "title": "Pi loads project-local extensions without approval",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54325"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-54323",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "daytonaio",
      "product": "daytona",
      "cwe": "CWE-295",
      "title": "Daytona: Git credential leak via git clone with TLS verification disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54323"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-12892",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Gstreamer1-plugins-bad: gstreamer1-plugins-bad: 1-byte heap out-of-bounds read in h.264 nal extension slice parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12892"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-54328",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "earendil-works",
      "product": "pi",
      "cwe": "CWE-379",
      "title": "Pi: Predictable temporary extension install paths allow local privilege escalation on shared Linux hosts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54328"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-56693",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nanocoai",
      "product": "nanoclaw",
      "cwe": "CWE-602",
      "title": "NanoClaw < 2.1.17 - Privilege Escalation via Unauthorized create_agent System Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56693"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-55568",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guzzle",
      "product": "guzzle",
      "cwe": "CWE-311",
      "title": "Guzzle: Silent HTTPS-Proxy Downgrade to Cleartext",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55568"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-56301",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nuxt",
      "product": "Nuxt",
      "cwe": "CWE-276",
      "title": "Nuxt - Arbitrary File Read via World-Connectable vite-node IPC Socket on Linux",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56301"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-49859",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.01019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "denoland",
      "product": "deno",
      "cwe": "CWE-693",
      "title": "Deno: `fetch()` API sandbox bypass via missing DNS resolution check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49859"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-49860",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.01019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "denoland",
      "product": "deno",
      "cwe": "CWE-918",
      "title": "Deno: WebSocket API sandbox bypass via missing post-DNS check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49860"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-12164",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.01017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortra",
      "product": "File Integrity Monitoring (FIM)",
      "cwe": "CWE-266",
      "title": "Privilege Escalation in Fortra File Integrity Monitoring (FIM)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12164"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-46550",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00099,
      "epss_percentile": 0.00913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocodb",
      "product": "nocodb",
      "cwe": "CWE-614",
      "title": "NocoDB: Refresh Token Cookie Set Without `Secure` and `SameSite` Flags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46550"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-49983",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00098,
      "epss_percentile": 0.00873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "denoland",
      "product": "deno",
      "cwe": "CWE-863",
      "title": "Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49983"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2025-15619",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00098,
      "epss_percentile": 0.0088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Connections",
      "cwe": "CWE-284",
      "title": "HCL Connections is vulnerable to broken access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15619"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-56117",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NetworkConfiguration",
      "product": "dhcpcd",
      "cwe": "CWE-416",
      "title": "dhcpcd Heap Use-After-Free via Control Socket Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56117"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-55655",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00089,
      "epss_percentile": 0.00509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-923",
      "title": "Openssh: local mitm of x11 forwarding via abstract unix socket pre-binding in red hat enterprise linux openssh client versions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55655"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2025-13162",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00083,
      "epss_percentile": 0.00292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ABB",
      "product": "Control Builder A",
      "cwe": "CWE-427",
      "title": "Advant Master Online Builder DLL vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13162"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-45792",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00078,
      "epss_percentile": 0.0016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rtk-ai",
      "product": "rtk",
      "cwe": "CWE-345",
      "title": "RTK improperly trusts project-local filter configuration, allowing silent tampering of command output shown to LLM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45792"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-54327",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00074,
      "epss_percentile": 0.00082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "earendil-works",
      "product": "pi",
      "cwe": "CWE-367",
      "title": "Pi: Race condition in auth.json writes could expose stored credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54327"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-55639",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-55639. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-71337",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-71337 (Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33760",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33760 (langflow-ai langflow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-34908",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-34908 (Ubiquiti Inc UniFi OS Server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-34909",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-34909 (Ubiquiti Inc UniFi OS Server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-34910",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-34910 (Ubiquiti Inc UniFi OS Server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42867",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42867 (langflow-ai langflow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44726",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44726 (denoland deno). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45135",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45135 (caddyserver caddy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45692",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45692 (caddyserver caddy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48020",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48020 (traefik). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48491",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48491 (traefik). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48519",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48519 (langflow-ai langflow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48520",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48520 (langflow-ai langflow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49401",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49401 (denoland deno). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49402",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49402 (denoland deno). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49406",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49406 (denoland deno). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49411",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49411 (denoland deno). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4983",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4983 (Eclipse Foundation Eclipse Open VSX). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50023",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50023 (yt-dlp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50193",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50193 (FasterXML jackson-databind). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50221",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50221 (OpenStack Swift). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-52844",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-52844 (caddyserver caddy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-52845",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-52845 (caddyserver caddy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-52846",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-52846 (caddyserver caddy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-53622",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-53622 (traefik). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54006",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54006 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54007",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54007 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54008",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54008 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54009",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54009 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54010",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54010 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54011",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54011 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54012",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54012 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54013",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54013 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54014",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54014 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54015",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54015 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54016",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54016 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54018",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54018 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54019",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54019 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54022",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54022 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54317",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54317 (home-assistant core). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54318",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54318 (home-assistant core). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54512",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54512 (FasterXML jackson-databind). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54761",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54761 (traefik). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54762",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54762 (traefik). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55249",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55249 (rtk-ai rtk). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55423",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55423 (langflow-ai langflow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55446",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55446 (langflow-ai langflow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55447",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55447 (langflow-ai langflow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55450",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55450 (langflow-ai langflow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55653",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55653 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55654",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55654 (Red Hat Enterprise Linux 10). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56274",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56274 (Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56275",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56275 (Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56968",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56968 (GNU SASL). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57053",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57053 (GNU libidn). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-42271",
      "detail": "DUE DATE PASSED — CVE-2026-42271 (BerriAI LiteLLM). CISA remediation deadline was June 22, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
