{
  "day": "2026-06-24",
  "boundary": "UTC calendar day",
  "published_count": 520,
  "by_severity": {
    "CRITICAL": 56,
    "HIGH": 226,
    "MEDIUM": 227,
    "LOW": 10
  },
  "kev_count": 0,
  "exploit_reference_count": 16,
  "awaiting_enrichment_count": 1,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-52806",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.05509,
      "epss_percentile": 0.92155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-77",
      "title": "Gogs: RCE via git rebase --exec argument injection in pull request merge",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52806"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-9775",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.03248,
      "epss_percentile": 0.87319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATEN",
      "product": "Unizon",
      "cwe": "CWE-22",
      "title": "ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9775"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-54066",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01892,
      "epss_percentile": 0.77927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-22",
      "title": "SiYuan: Path Traversal via Double URL Encoding in /assets/*path (publish mode arbitrary file─read)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54066"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-12486",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01795,
      "epss_percentile": 0.76665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-I/O Box 4E",
      "cwe": "CWE-78",
      "title": "GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12486"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-12850",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01795,
      "epss_percentile": 0.76666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-I/O Box 4E",
      "cwe": "CWE-78",
      "title": "GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12850"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-12849",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01759,
      "epss_percentile": 0.76163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-I/O Box 4E",
      "cwe": "CWE-78",
      "title": "GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12849"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-12851",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01759,
      "epss_percentile": 0.76162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-I/O Box 4E",
      "cwe": "CWE-78",
      "title": "GeoVision GV-I/O Box 4E libNetSetObj.so OS command injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12851"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-9776",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0158,
      "epss_percentile": 0.7352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATEN",
      "product": "Unizon",
      "cwe": "CWE-22",
      "title": "ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9776"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-9777",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.01477,
      "epss_percentile": 0.71792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATEN",
      "product": "Unizon",
      "cwe": "CWE-22",
      "title": "ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9777"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-9778",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.01477,
      "epss_percentile": 0.71792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATEN",
      "product": "Unizon",
      "cwe": "CWE-22",
      "title": "ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9778"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-9787",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01403,
      "epss_percentile": 0.70393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quest",
      "product": "NetVault Backup",
      "cwe": "CWE-78",
      "title": "Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9787"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-39938",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01305,
      "epss_percentile": 0.68247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cacti",
      "product": "cacti",
      "cwe": "CWE-22",
      "title": "Cacti: Unauthenticated RCE on Graph Image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39938"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-32315",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01199,
      "epss_percentile": 0.65671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "motioneye-project",
      "product": "motioneye",
      "cwe": "CWE-200",
      "title": "motionEye: World-Readable Configuration File Exposes Admin Password Hash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32315"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-9774",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01195,
      "epss_percentile": 0.65579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATEN",
      "product": "Unizon",
      "cwe": "CWE-22",
      "title": "ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9774"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-56121",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01143,
      "epss_percentile": 0.64145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "feast-dev",
      "product": "feast",
      "cwe": "CWE-502",
      "title": "Feast < 0.63.0 Unauthenticated RCE via ApplyFeatureView gRPC Deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56121"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-40079",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01137,
      "epss_percentile": 0.64017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cacti",
      "product": "cacti",
      "cwe": "CWE-78",
      "title": "Cacti: Command Injection via escape_command() no-op in RRDtool execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40079"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-9773",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01128,
      "epss_percentile": 0.63772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unraid",
      "product": "Unraid",
      "cwe": "CWE-78",
      "title": "Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9773"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-9772",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01115,
      "epss_percentile": 0.63452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unraid",
      "product": "Unraid",
      "cwe": "CWE-78",
      "title": "Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9772"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-52815",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01103,
      "epss_percentile": 0.63133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-200",
      "title": "Gogs: Unauthenticated Organization Teams Information Disclosure via API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52815"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-48732",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01007,
      "epss_percentile": 0.6029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "warpdotdev",
      "product": "warp",
      "cwe": "CWE-78",
      "title": "Warp: Remote SSH cwd can lead to unauthorized remote command execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48732"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-48719",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00948,
      "epss_percentile": 0.5842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "warpdotdev",
      "product": "warp",
      "cwe": "CWE-78",
      "title": "Warp branch selector command injection via Git branch names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48719"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-52813",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00922,
      "epss_percentile": 0.57542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-23",
      "title": "Gogs: Path Traversal in organization name results in RCE through Git hooks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52813"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-8663",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00833,
      "epss_percentile": 0.54813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "InsightConnect RPM Plugin",
      "cwe": "CWE-78",
      "title": "OS Command Injection in Rapid7 InsightConnect RPM Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8663"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-49980",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00744,
      "epss_percentile": 0.51911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rclone",
      "product": "rclone",
      "cwe": "CWE-306",
      "title": "Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49980"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-7570",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00689,
      "epss_percentile": 0.4997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quest",
      "product": "NetVault Backup",
      "cwe": "CWE-89",
      "title": "Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7570"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-9781",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00689,
      "epss_percentile": 0.4997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quest",
      "product": "NetVault Backup",
      "cwe": "CWE-89",
      "title": "Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9781"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-9782",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00689,
      "epss_percentile": 0.49969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quest",
      "product": "NetVault Backup",
      "cwe": "CWE-89",
      "title": "Quest NetVault Backup NVBUDeviceDrive SQL Injection Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9782"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-9783",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00689,
      "epss_percentile": 0.4997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quest",
      "product": "NetVault Backup",
      "cwe": "CWE-89",
      "title": "Quest NetVault Backup NVBURemovableMedia SQL Injection Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9783"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-9784",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00689,
      "epss_percentile": 0.49969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quest",
      "product": "NetVault Backup",
      "cwe": "CWE-89",
      "title": "Quest NetVault Backup NVBULibraryPort SQL Injection Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9784"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-9785",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00689,
      "epss_percentile": 0.49969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quest",
      "product": "NetVault Backup",
      "cwe": "CWE-89",
      "title": "Quest NetVault Backup NVBULibrarySlot SQL Injection Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9785"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-9786",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00689,
      "epss_percentile": 0.4997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quest",
      "product": "NetVault Backup",
      "cwe": "CWE-89",
      "title": "Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9786"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-7569",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0067,
      "epss_percentile": 0.49205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quest",
      "product": "NetVault Backup",
      "cwe": "CWE-79",
      "title": "Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7569"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-9780",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0067,
      "epss_percentile": 0.49206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quest",
      "product": "NetVault Backup",
      "cwe": "CWE-79",
      "title": "Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9780"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2025-60474",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00633,
      "epss_percentile": 0.47623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60474"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-12485",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00629,
      "epss_percentile": 0.47443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-I/O Box 4E",
      "cwe": "CWE-121",
      "title": "GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12485"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-54069",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00623,
      "epss_percentile": 0.47172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-346",
      "title": "SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54069"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-57296",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00595,
      "epss_percentile": 0.45834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins External Workspace Manager Plugin",
      "cwe": "CWE-22",
      "title": "Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exwsAllocate Pipeline step, allowing attackers with Item/Configure permission to read arbitrary files on the Jenkins controller file system, which can lead to remote code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57296"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-57281",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00594,
      "epss_percentile": 0.45797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Script Security Plugin",
      "cwe": "CWE-93",
      "title": "Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scripts to execute code outside the sandbox if a suitable script is present on the classpath of the component that evaluates the script.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57281"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-25119",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00582,
      "epss_percentile": 0.45245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-290",
      "title": "Gogs: Authentication Bypass via Unvalidated Reverse Proxy Headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25119"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-12416",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00563,
      "epss_percentile": 0.44353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pravel",
      "product": "Invoice Generator",
      "cwe": "CWE-640",
      "title": "Invoice Generator <= 1.0.0 - Unauthenticated Account Takeover via Weak Password Reset Validation via 'reset_user_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12416"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2025-60467",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00554,
      "epss_percentile": 0.43874,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-416",
      "title": "A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60467"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-52986",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00552,
      "epss_percentile": 0.43746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "netfilter: nf_conntrack_sip: don't use simple_strtoul",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52986"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-2050",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00552,
      "epss_percentile": 0.43743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GIMP",
      "product": "GIMP",
      "cwe": "CWE-122",
      "title": "GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2050"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-56111",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00542,
      "epss_percentile": 0.43218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MarlinFirmware",
      "product": "Marlin",
      "cwe": "CWE-129",
      "title": "Marlin Firmware 2.1.2.7 Out-of-Bounds Write via M421 G-code Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56111"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-52958",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00537,
      "epss_percentile": 0.42966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "libceph: Fix potential out-of-bounds access in osdmap_decode()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52958"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-52982",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00536,
      "epss_percentile": 0.42926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "net: usb: rtl8150: fix use-after-free in rtl8150_start_xmit()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52982"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-52981",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00532,
      "epss_percentile": 0.42691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "neigh: let neigh_xmit take skb ownership",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52981"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-55488",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00529,
      "epss_percentile": 0.42534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "motioneye-project",
      "product": "motioneye",
      "cwe": "CWE-22",
      "title": "motionEye's Absolute Path Traversal in Media File Handlers Allows Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55488"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-53046",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00524,
      "epss_percentile": 0.42243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53046"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-52954",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00523,
      "epss_percentile": 0.42223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-617",
      "title": "libceph: handle rbtree insertion error in decode_choose_args()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52954"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-52957",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00523,
      "epss_percentile": 0.42223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "libceph: Fix potential null-ptr-deref in decode_choose_args()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52957"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-53045",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00514,
      "epss_percentile": 0.41633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "memory: tegra124-emc: Fix dll_change check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53045"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-52999",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00514,
      "epss_percentile": 0.41634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "netfilter: nfnetlink_osf: fix out-of-bounds read on option matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52999"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-53043",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00514,
      "epss_percentile": 0.41634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "ocfs2/dlm: validate qr_numregions in dlm_match_regions()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53043"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-52914",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00513,
      "epss_percentile": 0.41545,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "batman-adv: fix fragment reassembly length accounting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52914"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-1840",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00511,
      "epss_percentile": 0.41413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hubbell",
      "product": "Aclara Metrum Cellular Web Interface",
      "cwe": "CWE-306",
      "title": "Missing authentication for critical function in Hubbell Aclara Metrum Cellular Web Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1840"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-7761",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00508,
      "epss_percentile": 0.41238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ultimatemember",
      "product": "Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin",
      "cwe": "CWE-862",
      "title": "Ultimate Member <= 2.11.4 - Authenticated (Contributor+) Account Takeover via Password Reset Link Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7761"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-8705",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00505,
      "epss_percentile": 0.41055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "clearsale",
      "product": "ClearSale Total",
      "cwe": "CWE-89",
      "title": "ClearSale Total <= 3.4.2 - Unauthenticated SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8705"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-39948",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00501,
      "epss_percentile": 0.40839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cacti",
      "product": "cacti",
      "cwe": "CWE-89",
      "title": "Cacti has SQL Injection via rfilter parameter in RLIKE clauses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39948"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-52998",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00501,
      "epss_percentile": 0.40836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "netfilter: nfnetlink_osf: fix potential NULL dereference in ttl check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52998"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-53003",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00501,
      "epss_percentile": 0.40835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "pppoe: drop PFC frames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53003"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-52974",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.005,
      "epss_percentile": 0.40769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "net: tls: fix strparser anchor skb leak on offload RX setup failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52974"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-48731",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00496,
      "epss_percentile": 0.40551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "warpdotdev",
      "product": "warp",
      "cwe": "CWE-78",
      "title": "Warp: Linux external editor command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48731"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-54297",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00487,
      "epss_percentile": 0.39996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lostisland",
      "product": "faraday",
      "cwe": "CWE-674",
      "title": "Faraday: Uncontrolled recursion in NestedParamsEncoder allows stack exhaustion DoS via deeply nested query parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54297"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-56270",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00475,
      "epss_percentile": 0.39212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-306",
      "title": "Flowise - Unauthenticated OAuth Secrets Disclosure via /api/v1/loginmethod Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56270"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-52816",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00475,
      "epss_percentile": 0.39235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-80",
      "title": "Gogs: Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52816"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-44017",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00472,
      "epss_percentile": 0.38995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docling-project",
      "product": "docling",
      "cwe": "CWE-22",
      "title": "Docling: Unsafe Zip Extraction in EasyOCR Model Download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44017"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-12242",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00469,
      "epss_percentile": 0.38798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "adegans",
      "product": "AdRotate Banner Manager",
      "cwe": "CWE-94",
      "title": "AdRotate Banner Manager <= 5.17.7 - Authenticated (Contributor+) PHP Code Injection via 'banner' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12242"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-52802",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00456,
      "epss_percentile": 0.37965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-601",
      "title": "Gogs: Open Redirect via redirect_to in Gogs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52802"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-52811",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00455,
      "epss_percentile": 0.37892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-22",
      "title": "Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52811"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-52946",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00455,
      "epss_percentile": 0.37905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52946"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-12417",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00454,
      "epss_percentile": 0.37876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pravel",
      "product": "SignUp & SignIn",
      "cwe": "CWE-640",
      "title": "SignUp & SignIn <= 1.0.0 - Unauthenticated Privilege Escalation via Weak Password Reset Validation via 'reset_activation_code' Leading to Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12417"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-45677",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00451,
      "epss_percentile": 0.37635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RocketChat",
      "product": "Rocket.Chat",
      "cwe": "CWE-862",
      "title": "Rocket.Chat: Lack of SAML Signature Check During Logout Could Lead To DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45677"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-4297",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0045,
      "epss_percentile": 0.3755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "newscred",
      "product": "Welcome Software Publishing",
      "cwe": "CWE-862",
      "title": "Welcome Software Publishing <= 0.0.31 - Authenticated (Subscriber+) Arbitrary Options Update to Privilege Escalation via 'nc.setOption' XML-RPC Method",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4297"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-12846",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00446,
      "epss_percentile": 0.37309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-I/O Box 4E",
      "cwe": "CWE-121",
      "title": "GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12846"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-12847",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00446,
      "epss_percentile": 0.37309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-I/O Box 4E",
      "cwe": "CWE-121",
      "title": "GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12847"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-12848",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00446,
      "epss_percentile": 0.3731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-I/O Box 4E",
      "cwe": "CWE-121",
      "title": "GeoVision GV-I/O Box DVRSearch buffer overflow vulnerabilities in CMD_IP_SET command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12848"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-52983",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.37213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: airoha: fix BQL imbalance in TX path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52983"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-52797",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00443,
      "epss_percentile": 0.37033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-22",
      "title": "Gogs: Overwriting critical files results in a denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52797"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-50551",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0044,
      "epss_percentile": 0.36842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50551"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-54699",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00436,
      "epss_percentile": 0.36471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "warpdotdev",
      "product": "warp",
      "cwe": "CWE-78",
      "title": "Warp: OS command injection when opening terminal links from WSL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54699"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-52814",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00431,
      "epss_percentile": 0.3613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-400",
      "title": "Gogs: Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52814"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-53010",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0043,
      "epss_percentile": 0.36013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "ksmbd: fix use-after-free in smb2_open during durable reconnect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53010"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-53055",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0043,
      "epss_percentile": 0.36013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "crypto: hisilicon/sec2 - prevent req used-after-free for sec",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53055"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-57301",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00428,
      "epss_percentile": 0.35891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins OWASP ZAP Plugin",
      "cwe": "CWE-610",
      "title": "Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned agent, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57301"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-53026",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00426,
      "epss_percentile": 0.3573,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "NFSD: fix nfs4_file access extra count in nfsd4_add_rdaccess_to_wrdeleg",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53026"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-56262",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00417,
      "epss_percentile": 0.34913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crawl4AI",
      "product": "Crawl4AI",
      "cwe": "CWE-306",
      "title": "Crawl4AI - Unauthenticated Access to Monitor Endpoints via Docker API Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56262"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-52801",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-20",
      "title": "Gogs: Ability to import local repositories via Mirror Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52801"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-54904",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00413,
      "epss_percentile": 0.34621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ruby-concurrency",
      "product": "concurrent-ruby",
      "cwe": "CWE-835",
      "title": "concurrent-ruby: `AtomicReference#update` livelocks when the stored value is `Float::NAN`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54904"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-13164",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00406,
      "epss_percentile": 0.3396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mailerup",
      "product": "Mailerup",
      "cwe": "CWE-306",
      "title": "Unauthenticated self-registration in MailerUp allows access to stored email data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13164"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-23879",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miurahr",
      "product": "py7zr",
      "cwe": "CWE-59",
      "title": "py7zr: Arbitrary File Write Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23879"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-39893",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00399,
      "epss_percentile": 0.33249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cacti",
      "product": "cacti",
      "cwe": "CWE-89",
      "title": "Cacti: Pre-authentication SQL injection via rfilter RLIKE clause in graph_view.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39893"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-52931",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00399,
      "epss_percentile": 0.33269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "batman-adv: tp_meter: avoid use of uninit sender vars",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52931"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-53088",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00399,
      "epss_percentile": 0.33268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-193",
      "title": "net: bcmgenet: fix off-by-one in bcmgenet_put_txcb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53088"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-9779",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.33098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATEN",
      "product": "Unizon",
      "cwe": "CWE-347",
      "title": "ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9779"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-53006",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00395,
      "epss_percentile": 0.32851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "ipv6: fix possible UAF in icmpv6_rcv()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53006"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-52967",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "smb/client: fix possible infinite loop and oob read in symlink_data()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52967"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-55454",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00392,
      "epss_percentile": 0.32485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "appsmithorg",
      "product": "appsmith",
      "cwe": "CWE-749",
      "title": "Appsmith: Caddy admin API exposed without authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55454"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-52922",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00389,
      "epss_percentile": 0.32211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "batman-adv: dat: handle forward allocation error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52922"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-52929",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00389,
      "epss_percentile": 0.32212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "sctp: stream: fully roll back denied add-stream state",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52929"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-53049",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00388,
      "epss_percentile": 0.32138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "gfs2: add some missing log locking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53049"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-10735",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00387,
      "epss_percentile": 0.32033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "smart-post-show-pro",
      "cwe": null,
      "title": "ShapedPlugin Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10735"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-44016",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docling-project",
      "product": "docling",
      "cwe": "CWE-94",
      "title": "Docling: Unsafe Playwright-based HTML Rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44016"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-10749",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00383,
      "epss_percentile": 0.31605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Post Duplicator",
      "cwe": null,
      "title": "Post Duplicator < 3.0.15 - Contributor+ PHP Object Injection via customMetaData",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10749"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-52955",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0038,
      "epss_percentile": 0.31317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "libceph: Fix potential out-of-bounds access in crush_decode()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52955"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-57280",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.3128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Script Security Plugin",
      "cwe": "CWE-693",
      "title": "Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed for-each loops in sandboxed Groovy scripts, allowing attackers able to provide such scripts to invoke arbitrary constructors and bypass the sandbox protection.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57280"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-53069",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "net, bpf: fix null-ptr-deref in xdp_master_redirect() for down master",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53069"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-52799",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00379,
      "epss_percentile": 0.31226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-639",
      "title": "Gogs: Missing Authorization in Attachment Download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52799"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-9179",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.3086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hancock11",
      "product": "WP Forms Connector",
      "cwe": "CWE-89",
      "title": "WP Forms Connector <= 1.8 - Unauthenticated SQL Injection via 'order' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9179"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-53087",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "net: bcmgenet: fix leaking free_bds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53087"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-52993",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00368,
      "epss_percentile": 0.30015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-415",
      "title": "tipc: fix double-free in tipc_buf_append()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52993"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-52807",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00368,
      "epss_percentile": 0.30057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-79",
      "title": "Gogs: DOM-based XSS via Milestone Name on New Issue Page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52807"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-52804",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0036,
      "epss_percentile": 0.29258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-193",
      "title": "Gogs: Privilege Escalation via Collaboration Access Mode Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52804"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-52956",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00359,
      "epss_percentile": 0.29146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "libceph: Fix potential out-of-bounds access in __ceph_x_decrypt()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52956"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-52960",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00359,
      "epss_percentile": 0.29146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ceph: put folios not suitable for writeback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52960"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-48793",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00357,
      "epss_percentile": 0.28984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jellyfin",
      "product": "jellyfin",
      "cwe": "CWE-88",
      "title": "Jellyfin: Potential FFmpeg argument injection via unescaped subtitle file path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48793"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-53002",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.2868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "netfilter: conntrack: remove sprintf usage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53002"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-35025",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00349,
      "epss_percentile": 0.2806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ProFTPD Project",
      "product": "ProFTPD",
      "cwe": "CWE-59",
      "title": "ProFTPD ACL Bypass via /proc/self/root Path Prefix in RNFR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35025"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-9175",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00348,
      "epss_percentile": 0.2798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ajitdas",
      "product": "Devs Accounting – Simple Accounting and Invoicing Solution",
      "cwe": "CWE-862",
      "title": "Devs Accounting <= 1.2.0 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9175"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-9178",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hancock11",
      "product": "WP Forms Connector",
      "cwe": "CWE-862",
      "title": "WP Forms Connector <= 1.8 - Missing Authorization to Unauthenticated Information Exposure via 'user/list' REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9178"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-39955",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00346,
      "epss_percentile": 0.27709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cacti",
      "product": "cacti",
      "cwe": "CWE-89",
      "title": "Cacti has Pre-Authentication SQL Injection via unanchored FILTER_VALIDATE_REGEXP in graph_view.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39955"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-49851",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lepture",
      "product": "mistune",
      "cwe": "CWE-400",
      "title": "Mistune: Potential DoS via quadratic-time parsing in parse_link_text",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49851"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-53070",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sctp: disable BH before calling udp_tunnel_xmit_skb()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53070"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2025-71332",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-89",
      "title": "Flowise - SQL Injection in importChatflows API via chatflow.id Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71332"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-13033",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13033"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-13038",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13038"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-49247",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jellyfin",
      "product": "jellyfin",
      "cwe": "CWE-22",
      "title": "Jellyfin: Potential Authenticated path traversal in /ClientLog/Document",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49247"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2025-64719",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00344,
      "epss_percentile": 0.27548,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-20",
      "title": "Gogs: Denial of Service in repository/wiki file listing web pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64719"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-52989",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00342,
      "epss_percentile": 0.27384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "nvmet-tcp: propagate nvmet_tcp_build_pdu_iovec() errors to its callers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52989"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2025-71361",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-95",
      "title": "picklescan - Remote Code Execution via Undetected idlelib.calltip.Calltip.fetch_tip",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71361"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-46348",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mastodon",
      "product": "mastodon",
      "cwe": "CWE-918",
      "title": "Mastodon: SSRF Bypass via IPv6 Unspecified Address (::)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46348"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-52810",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-284",
      "title": "Gogs: Write to readonly repositories using receive-pack + service=git-upload-pack confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52810"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-52932",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: ipcomp: Free destination pages on acomp errors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52932"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-52808",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.2657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-269",
      "title": "Gogs: Write-level collaborators can mutate admin-only repository settings via API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52808"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-11998",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00333,
      "epss_percentile": 0.26324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "AngularJS",
      "cwe": "CWE-791",
      "title": "AngularJS XSS via SCE resource URL sanitization bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11998"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-52924",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00331,
      "epss_percentile": 0.26111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "sctp: purge outqueue on stale COOKIE-ECHO handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52924"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-44020",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.25987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docling-project",
      "product": "docling",
      "cwe": "CWE-776",
      "title": "Docling: Unsafe XML Entity Expansion in USPTO Patent Backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44020"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-13163",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00329,
      "epss_percentile": 0.25892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mailerup",
      "product": "Mailerup",
      "cwe": "CWE-601",
      "title": "Lack of input validation in Mailerup input parameter leads to Open Redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13163"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-55570",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00327,
      "epss_percentile": 0.25636,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan: Stored XSS results to Electron RCE in SiYuan marketplace via unescaped `data-obj` attribute (Bypass for CVE-2026-45375's patch)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55570"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-50189",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.25535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "appsmithorg",
      "product": "appsmith",
      "cwe": "CWE-183",
      "title": "Appsmith: RCE via Supervisord XML-RPC Admin Interface Exposed via /supervisor Caddy Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50189"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-55762",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RocketChat",
      "product": "Rocket.Chat",
      "cwe": "CWE-862",
      "title": "Rocket.Chat: Any Authenticated User Can Permanently Deregister Workspace from Rocket.Chat Cloud via Unprotected `/api/v1/fingerprint` Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55762"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-47267",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-918",
      "title": "Gogs: SSRF in webhook deliveries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47267"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-50699",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.2414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frappe",
      "product": "Frappe Framework",
      "cwe": "CWE-79",
      "title": "Frappe Framework 17.0.0-dev - Stored XSS in Auto Repeat dashboard schedule rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50699"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-33235",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Significant-Gravitas",
      "product": "AutoGPT",
      "cwe": "CWE-400",
      "title": "AutoGPT: Denial of Service (DoS) via Resource Exhaustion in text templating features",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33235"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-52945",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Revert \"wireguard: device: enable threaded NAPI\"",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52945"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-45689",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00308,
      "epss_percentile": 0.23523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RocketChat",
      "product": "Rocket.Chat",
      "cwe": "CWE-943",
      "title": "Rocket.Chat: Pre-Auth NoSQL Injection in OAuth2 Token Endpoint leading to Arbitrary User ATO",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45689"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-9612",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yapacdev",
      "product": "WhatsOrder – Instant Checkout for WooCommerce",
      "cwe": "CWE-200",
      "title": "WhatsOrder <= 1.0.1 - Unauthenticated Sensitive Information Exposure via Predictable Invoice File URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9612"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-54067",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00307,
      "epss_percentile": 0.23381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54067"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-47110",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ueberdosis",
      "product": "tiptap-php",
      "cwe": "CWE-241",
      "title": "Tiptap for PHP < 2.1.1 DoS via Malformed href Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47110"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-53086",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00304,
      "epss_percentile": 0.23094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "net: bcmgenet: fix racing timeout handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53086"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-52920",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00299,
      "epss_percentile": 0.22562,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: xt_policy: fix strict mode inbound policy matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52920"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-9619",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00298,
      "epss_percentile": 0.22444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "berfect",
      "product": "Reviews and Rating – Docplanner",
      "cwe": "CWE-862",
      "title": "Reviews and Rating <= 1.1.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via sync_reviews AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9619"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-10092",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.22349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nicashmu",
      "product": "Cincopa video and media plug-in",
      "cwe": "CWE-79",
      "title": "Cincopa video and media plug-in <= 1.163 - Unauthenticated Stored Cross-Site Scripting via cincopa Shortcode in Post Comments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10092"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-52798",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-79",
      "title": "Gogs: Stored XSS in `.ipynb` Preview",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52798"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-55666",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00295,
      "epss_percentile": 0.22156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RocketChat",
      "product": "Rocket.Chat",
      "cwe": "CWE-287",
      "title": "Rocket.Chat: Email Parameter Fallback Leads To Account Takeover Within Apple OAuth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55666"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-7617",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "secufor",
      "product": "Secufor_OAuth",
      "cwe": "CWE-862",
      "title": "Secufor_OAuth <= 1.0.7 - Missing Authorization to Unauthenticated Account Logout via 'secuforoauth_unregister_action' AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7617"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-12094",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iamranit",
      "product": "Advanced Contact Form 7 – Compact DB",
      "cwe": "CWE-862",
      "title": "Advanced Contact Form 7 <= 1.0.0 - Missing Authorization to Unauthenticated Arbitrary Contact Form Submission Deletion via 'form_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12094"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-10043",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.21984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MosaicML",
      "product": "Composer",
      "cwe": "CWE-502",
      "title": "MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10043"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-56237",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00293,
      "epss_percentile": 0.21899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-287",
      "title": "Capgo - Unauthenticated API Key Generation via Client-Side Parameter Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56237"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-13036",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.21945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13036"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-13150",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pentestify",
      "product": "Pentestify",
      "cwe": "CWE-918",
      "title": "SSRF in Pentestify PDF generation endpoint via Host header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13150"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-12095",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.21614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bytuncay",
      "product": "Kargo Takip",
      "cwe": "CWE-918",
      "title": "Kargo Takip <= 1.2 - Unauthenticated Server-Side Request Forgery via 'api_url' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12095"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-12100",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.21608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "abhisheksaha11",
      "product": "URL Preview",
      "cwe": "CWE-918",
      "title": "URL Preview <= 1.0 - Unauthenticated Server-Side Request Forgery via 'url' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12100"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-54158",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00289,
      "epss_percentile": 0.21488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan: Stored XSS to RCE via attribute-view cell rendering in genAVValueHTML()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54158"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-33543",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00289,
      "epss_percentile": 0.21437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-288",
      "title": "FOSSBilling: Authentication bypass allows unauthenticated administrator creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33543"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-45688",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00289,
      "epss_percentile": 0.21478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RocketChat",
      "product": "Rocket.Chat",
      "cwe": "CWE-943",
      "title": "Rocket.Chat: Pre-Auth NoSQL Injection in CAS Login Handler leading to Arbitrary CAS/SAML User Session Hijack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45688"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-13028",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00287,
      "epss_percentile": 0.2129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13028"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-13032",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00287,
      "epss_percentile": 0.2129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13032"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-39899",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00283,
      "epss_percentile": 0.20877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cacti",
      "product": "cacti",
      "cwe": "CWE-22",
      "title": "Cacti: Path Traversal via filename parameter in package_import.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39899"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-56338",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-703",
      "title": "Capgo - Denial of Service in 2FA Email Verification via /auth/v1/otp Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56338"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-31978",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "motioneye-project",
      "product": "motioneye",
      "cwe": "CWE-22",
      "title": "motionEye: Arbitrary File Read via Path Traversal in Picture/Movie Preview Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31978"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-52805",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-918",
      "title": "Gogs: Migration Redirect Bypass Leads to Internal Repository Theft",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52805"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-53943",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00278,
      "epss_percentile": 0.20313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-524",
      "title": "Ghost: Cache-poisoning XSS in Ghost frontend via x-ghost-preview header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53943"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-54686",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "warpdotdev",
      "product": "warp",
      "cwe": "CWE-78",
      "title": "Warp: DCS lifecycle hook spoofing can alter terminal session metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54686"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-10745",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "upKeeper Solutions",
      "product": "upKeeper Instant Privilege Access",
      "cwe": "CWE-117",
      "title": "Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log Injection-Tampering-Forging. This issue affects upKeeper Instant Privilege Access: through 1.6.1.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10745"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-57284",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Pipeline: Groovy Plugin",
      "cwe": "CWE-470",
      "title": "Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier does not restrict the types that can be instantiated through the Pipeline Snippet Generator, allowing attackers to instantiate types related to job or system configuration other than Pipeline steps.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57284"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-56245",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo",
      "cwe": "CWE-269",
      "title": "Supabase Capgo - Unauthenticated Cross-Tenant Build-Time Accounting Poisoning via record_build_time RPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56245"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-50701",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frappe",
      "product": "Frappe Framework",
      "cwe": "CWE-79",
      "title": "Frappe Framework 17.0.0-dev - Reflected DOM XSS in dashboard-view breadcrumb rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50701"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-52794",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getsentry",
      "product": "sentry",
      "cwe": "CWE-1333",
      "title": "Sentry: Inefficient Regular Expression Complexity in sentry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52794"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-56232",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-863",
      "title": "Capgo - Subkey Scope Bypass in middlewareKey via x-limited-key-id Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56232"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-27708",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.18559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-284",
      "title": "FOSSBilling: IDOR in Servicecustom Client API allows cross-client data access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27708"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-50129",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.1824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mastodon",
      "product": "mastodon",
      "cwe": "CWE-248",
      "title": "Mastodon: Persistent anonymous DoS via unhandled NoMethodError in MATH_TRANSFORMER",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50129"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-52918",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.1819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: serialize accept_q access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52918"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-54759",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan: Lute HTML sanitizer allows `<iframe>` tags in Bazaar package README, leading to arbitrary command execution via SiYuan Electron client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54759"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-56337",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-200",
      "title": "Capgo - Information Disclosure via Unauthenticated RPC Function exist_app_v2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56337"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-53071",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53071"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-56368",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.1794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-401",
      "title": "ImageMagick - Memory Leak in Raw Pixel Data Coders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56368"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-49246",
      "cvss_base": 1.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00258,
      "epss_percentile": 0.17647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jellyfin",
      "product": "jellyfin",
      "cwe": "CWE-22",
      "title": "Jellyfin: Potential MKV attachment filename path traversal to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49246"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-10091",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17486,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cgarvey",
      "product": "Email JavaScript Cloak",
      "cwe": "CWE-79",
      "title": "Email JavaScript Cloak <= 1.03 - Unauthenticated Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10091"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-50698",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frappe",
      "product": "Frappe Framework",
      "cwe": "CWE-79",
      "title": "Frappe Framework 17.0.0-dev - Stored XSS in Audit Trail template rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50698"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-50700",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frappe",
      "product": "Frappe Framework",
      "cwe": "CWE-79",
      "title": "Frappe Framework 17.0.0-dev - Stored XSS in frappe.get_avatar image rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50700"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-50704",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frappe",
      "product": "Frappe Framework",
      "cwe": "CWE-79",
      "title": "Frappe Framework 17.0.0-dev - Reflected/Stored XSS in File View breadcrumbs rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50704"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-50705",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frappe",
      "product": "Frappe Framework",
      "cwe": "CWE-79",
      "title": "Frappe Framework 17.0.0-dev - Stored XSS in Form Dashboard headline rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50705"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-50710",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frappe",
      "product": "Frappe Framework",
      "cwe": "CWE-79",
      "title": "Frappe Framework 17.0.0-dev - Stored XSS via eval in Number Card filters_config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50710"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-50711",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frappe",
      "product": "Frappe Framework",
      "cwe": "CWE-79",
      "title": "Frappe Framework 17.0.0-dev - Stored XSS in Number Card filter fields rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50711"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-48704",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "warpdotdev",
      "product": "warp",
      "cwe": "CWE-20",
      "title": "Warp Markdown notebook links may open executable local files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48704"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-8690",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rentmy",
      "product": "RentMy Real-Time Rental Management Plugin",
      "cwe": "CWE-862",
      "title": "RentMy Real-Time Rental Management Plugin <= 4.0.4.1 - Missing Authorization to Unauthenticated Settings Update via rentmy_cdn_request AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8690"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-49979",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "appsmithorg",
      "product": "appsmith",
      "cwe": "CWE-918",
      "title": "Appsmith: SSRF via `POST /api/v1/admin/send-test-email` — JavaMail Bypasses WebClient IP Filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49979"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2025-71354",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.17078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-502",
      "title": "picklescan - Remote Code Execution via idlelib.debugobj.ObjectTreeItem.SetText",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71354"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-53075",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ppp: require CAP_NET_ADMIN in target netns for unattached ioctls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53075"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-11614",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.16437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xpro",
      "product": "Xpro Addons — 140+ Widgets for Elementor",
      "cwe": "CWE-79",
      "title": "Xpro Addons <= 1.7.2 - Authenticated (Author+) Stored Cross-Site Scripting via 'custom_attributes' Parameter of Multiple Widgets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11614"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-48720",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "warpdotdev",
      "product": "warp",
      "cwe": "CWE-20",
      "title": "Warp: SSH remote output can lead to local file overwrite and persistence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48720"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-56223",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00244,
      "epss_percentile": 0.15884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-287",
      "title": "Capgo - Account Takeover via Cross-Domain SSO Email Assertion in provision-user",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56223"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-52934",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.15933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "batman-adv: tvlv: reject oversized TVLV packets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52934"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-55759",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RocketChat",
      "product": "Rocket.Chat",
      "cwe": "CWE-287",
      "title": "Rocket.Chat: Apple Sign-In skips JWT claims validation, allowing expired and cross-audience token replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55759"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-49278",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RocketChat",
      "product": "Rocket.Chat",
      "cwe": "CWE-285",
      "title": "Rocket.Chat: Livechat Visitor Profile Disclosure Leaks Bearer Token and Enables Visitor Impersonation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49278"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-9643",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomunited",
      "product": "WP Meta SEO",
      "cwe": "CWE-79",
      "title": "WP Meta SEO <= 4.5.18 - Unauthenticated Stored Cross-Site Scripting via REQUEST_URI in 404 Logging",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9643"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-54068",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-306",
      "title": "SiYuan: Unauthenticated SQLite Data Exfiltration via Template Injection in /api/icon/getDynamicIcon",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54068"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-50703",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frappe",
      "product": "Frappe Framework",
      "cwe": "CWE-79",
      "title": "Frappe Framework 17.0.0-dev - Stored XSS in Desktop Icon label rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50703"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-50708",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frappe",
      "product": "Frappe Framework",
      "cwe": "CWE-79",
      "title": "Frappe Framework 17.0.0-dev - Stored XSS in Multi Select Dialog result rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50708"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-50709",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.1527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frappe",
      "product": "Frappe Framework",
      "cwe": "CWE-79",
      "title": "Frappe Framework 17.0.0-dev - Stored XSS in Notifications Events color rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50709"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-50712",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frappe",
      "product": "Frappe Framework",
      "cwe": "CWE-79",
      "title": "Frappe Framework 17.0.0-dev - Stored XSS in Tree View node label rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50712"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-52943",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "net: skbuff: fix missing zerocopy reference in pskb_carve helpers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52943"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-56256",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-602",
      "title": "Capgo - Two-Factor Authentication Bypass via Organization Management API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56256"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-55611",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.00236,
      "epss_percentile": 0.14865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mintplex-Labs",
      "product": "anything-llm",
      "cwe": "CWE-639",
      "title": "AnythingLLM: embed-parsed-file cleanup deletes any parsed file by ID without ownership scoping (cross-tenant IDOR deletion)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55611"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-11370",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomunited",
      "product": "WP Meta SEO",
      "cwe": "CWE-918",
      "title": "WP Meta SEO <= 4.5.18 - Authenticated (Contributor+) Server-Side Request Forgery via 'new_link' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11370"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-13031",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13031"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-9616",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.14437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "verenigingvanregistrars",
      "product": "Generate Security.txt",
      "cwe": "CWE-862",
      "title": "Generate Security.txt <= 1.0.12 - Missing Authorization to Authenticated (Subscriber+) Security.txt Deletion via delete_securitytxt AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9616"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-47389",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mastodon",
      "product": "mastodon",
      "cwe": "CWE-184",
      "title": "Mastodon: SSRF protection bypass on older Ruby versions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47389"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-8614",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "assistioai",
      "product": "Assistio",
      "cwe": "CWE-862",
      "title": "Assistio <= 1.1.2 - Missing Authorization to Authenticated (Subscriber+) Plugin Settings Deletion via assistio_plugin_delete_assistio_settings AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8614"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-48789",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mintplex-Labs",
      "product": "anything-llm",
      "cwe": "CWE-22",
      "title": "AnythingLLM: Windows path containment bypass in document folder route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48789"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-8617",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ailchev",
      "product": "SearchPlus",
      "cwe": "CWE-862",
      "title": "SearchPlus <= 1.7.1 - Missing Authorization to Unauthenticated Settings Modification and Deletion via searchplus_save_token & searchplus_reset_token AJAX Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8617"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-9172",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ajitdas",
      "product": "Devs Accounting – Simple Accounting and Invoicing Solution",
      "cwe": "CWE-862",
      "title": "Devs Accounting <= 1.2.0 - Missing Authorization to Unauthenticated Account Deletion via /delete-account/ REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9172"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-52796",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00226,
      "epss_percentile": 0.13578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-1336",
      "title": "Gogs: DoS in rendering issue index pattern",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52796"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-56052",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FunnelKit",
      "product": "Funnel Builder by FunnelKit",
      "cwe": "CWE-89",
      "title": "WordPress Funnel Builder by FunnelKit plugin <= 3.15.0.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56052"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-57303",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Assembla Plugin",
      "cwe": "CWE-918",
      "title": "Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to control the responses of the configured Assembla server to extract secrets from the Jenkins controller or perform server-side request forgery.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57303"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-57288",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00224,
      "epss_percentile": 0.13341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Active Directory Plugin",
      "cwe": "CWE-90",
      "title": "Jenkins Active Directory Plugin 2.41.1 and earlier does not escape the user name before building the LDAP search filter in the Windows native (ADSI) authentication path, allowing unauthenticated attackers to inject LDAP wildcard characters to enumerate directory entries and to authenticate as a matching user whose password they know without knowing their exact user name.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57288"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-12760",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Tapo C200 v3",
      "cwe": "CWE-770",
      "title": "Denial-of-Service Vulnerability via Malformed IPv4 Fragmentation Handling in TP-Link Tapo C200",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12760"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-39951",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cacti",
      "product": "cacti",
      "cwe": "CWE-89",
      "title": "Cacti: Stored SQL Injection via graph_name_regexp in Reports feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39951"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-55455",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "appsmithorg",
      "product": "appsmith",
      "cwe": "CWE-918",
      "title": "Appsmith: SSRF in REST API / GraphQL datasource plugins via insufficient host denylist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55455"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-10642",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-835",
      "title": "Unbounded TX busy-loop DoS in Zephyr PL011 UART driver under CTS hardware flow control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10642"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-8688",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "krishaweb",
      "product": "Advance Nav Menu Manager",
      "cwe": "CWE-862",
      "title": "Advance Nav Menu Manager <= 1.3 - Missing Authorization to Authenticated (Subscriber+) Nav Menu Item Modification via anmm_save_menu_data AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8688"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-56351",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-89",
      "title": "n8n - SQL Injection in MySQL, PostgreSQL, and Microsoft SQL Nodes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56351"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-13035",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00216,
      "epss_percentile": 0.12295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13035"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-52812",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00216,
      "epss_percentile": 0.1231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-345",
      "title": "Gogs: LFS dedupe path leaks private repo content across tenants",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52812"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-57285",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins GitHub Branch Source Plugin",
      "cwe": "CWE-862",
      "title": "A missing permission check in Jenkins GitHub Branch Source Plugin 1967.1969.v205fd594c821 and earlier allows attackers with Overall/Read permission to obtain the URLs of GitHub Enterprise servers configured in the global plugin configuration.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57285"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-57286",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Git Parameter Plugin",
      "cwe": "CWE-862",
      "title": "A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain information about the SCM repository used by a job, such as branch names, tag names, and revision metadata.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57286"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-45757",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00215,
      "epss_percentile": 0.12162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RocketChat",
      "product": "Rocket.Chat",
      "cwe": "CWE-613",
      "title": "Rocket.Chat: users.deactivateIdle` deactivates accounts without revoking existing login tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45757"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-49277",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00215,
      "epss_percentile": 0.12161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RocketChat",
      "product": "Rocket.Chat",
      "cwe": "CWE-613",
      "title": "Rocket.Chat: OAuth access and refresh tokens remain valid after account deactivation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49277"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-53949",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-200",
      "title": "Ghost Content API filter bypass reveals private fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53949"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-48725",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.11962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "warpdotdev",
      "product": "warp",
      "cwe": "CWE-276",
      "title": "Warp may allow terminal output to access the local clipboard through OSC 52",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48725"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-9709",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Cornerstone",
      "cwe": null,
      "title": "Themeco Cornerstone < 7.8.9 (Premium, bundled with X Theme) - Subscriber+ Arbitrary User Meta Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9709"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-9710",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Cornerstone",
      "cwe": null,
      "title": "Themeco Cornerstone < 7.8.8 (Premium, bundled with X Theme) - Subscriber+ Arbitrary User Password Hash Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9710"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-9184",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "24liveblog",
      "product": "24liveblog – live blog tool",
      "cwe": "CWE-862",
      "title": "24liveblog <= 2.2 - Missing Authorization to Authenticated (Author+) Settings Modification via update_lb24_token AJAX action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9184"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-56302",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-284",
      "title": "Capgo - Unsecured Supabase Images Bucket via Missing Row Level Security",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56302"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-57282",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Git client Plugin",
      "cwe": "CWE-78",
      "title": "Jenkins Git client Plugin 6.6.0 and earlier does not correctly escape the workspace directory name when it is embedded into a generated SSH wrapper script, allowing attackers able to control the name of a build's working directory to execute arbitrary operating system commands on the agent.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57282"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-53947",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.11018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-204",
      "title": "Ghost: Member existence leak via magic link sign-in response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53947"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-45687",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RocketChat",
      "product": "Rocket.Chat",
      "cwe": "CWE-915",
      "title": "Rocket.Chat: Authenticated Arbitrary Data Export Theft via Mass Assignment in sendFileMessage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45687"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-8628",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "owencutajar",
      "product": "EntreDroppers",
      "cwe": "CWE-79",
      "title": "EntreDroppers <= 1.1.2 - Reflected Cross-Site Scripting via PHP_SELF Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8628"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-53950",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.10771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-79",
      "title": "@tryghost/activitypub: XSS in Ghost's ActivityPub client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53950"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-9183",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "24liveblog",
      "product": "24liveblog – live blog tool",
      "cwe": "CWE-200",
      "title": "24liveblog <= 2.2 - Authenticated (Contributor+) Exposure of Sensitive Information via Block Editor Script Localization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9183"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2025-60468",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "GPAC Multimedia Open Source Project GPAC Project/MP4Box 2.5-DEV-rev1593-gfe88c3545-master is affected by: Buffer Overflow. The impact is: cause a denial of service (local). The component is: filter_core/filter_pid.c (L:574-580): function gf_filter_pid_inst_swap_delete_task() improperly accesses freed objects during PID instance swap/delete cleanup, leading to heap use-after-free. The attack vector is: Local (AV:L): a local, authenticated user who processes a specially crafted MPEG-2 TS/MP4 file with MP4Box can trigger the bug during filter teardown (PID instance swap/delete), causing a crash. ¶¶ In GPAC s MP4Box, gf_filter_pid_inst_swap_delete_task() in filter_core/filter_pid.c may dereference objects after they have been freed when cleaning up PID instances after a swap/delete operation. Crafted inputs (e.g., malformed MPEG-2 TS) can trigger a heap use-after-free and crash; exploitation may be possible.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60468"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-12488",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GeoVision",
      "cwe": "CWE-121",
      "title": "GeoVision GV-VMS V20 GV-Cloud memory corruption vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12488"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-9620",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomunited",
      "product": "WP Latest Posts",
      "cwe": "CWE-79",
      "title": "WP Latest Posts <= 5.0.11 - Authenticated (Author+) Stored Cross-Site Scripting via Post Content Image src Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9620"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-13026",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13026"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-13027",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13027"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-53944",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-184",
      "title": "Ghost: Private IP filtering bypass to make server-side requests to internal services",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53944"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-53072",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00195,
      "epss_percentile": 0.09583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53072"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-52800",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.09414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-352",
      "title": "Gogs: CSRF Leading to Organization Owner Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52800"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-56244",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.09427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-200",
      "title": "Capgo - Webhook Signing Secret Disclosure via Non-Admin API Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56244"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-49220",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.0942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jellyfin",
      "product": "jellyfin",
      "cwe": "CWE-79",
      "title": "Jellyfin: Potential XSS in user management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49220"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-12681",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.09161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "go-attestation",
      "cwe": "CWE-1285",
      "title": "Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSignatureList() does not advance the buffer past vendor bytes before reading entries. For hashSHA256SigGUID lists, this allows attacker-controlled vendor header bytes to be appended to the trusted SHA256 hash list. A crafted TPM event log could inject arbitrary SHA256 hashes into the verifier's trusted measurement database, enabling a remote attestation verifier to accept a compromised boot state. This issue affects go-attestation: through 0.6.0.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12681"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-55583",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.09098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "twentyhq",
      "product": "twenty",
      "cwe": "CWE-639",
      "title": "Twenty: Cross-workspace IDOR in AgentTurnResolver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55583"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-3652",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.09024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "ARforms",
      "cwe": "CWE-79",
      "title": "ARForms <= 7.1.3 - Unauthenticated Stored Cross-Site Scripting via 'value' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3652"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-54070",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.09055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan: Stored XSS in Bazaar marketplace via package README event handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54070"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-8865",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "paradigmatools",
      "product": "Avalon23 Products Filter for WooCommerce",
      "cwe": "CWE-79",
      "title": "Avalon23 Products Filter for WooCommerce <= 1.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8865"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-13023",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13023"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-13030",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13030"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-13140",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00185,
      "epss_percentile": 0.08448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thinkst Applied Research",
      "product": "Canarytokens",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting in Canarytokens.org",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13140"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-13025",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.08368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Race in DevTools in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13025"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-56257",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.08147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-284",
      "title": "Capgo - Authorization Bypass in App Ownership Transfer via Direct PostgREST Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56257"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2025-60473",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60473"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-56310",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo",
      "cwe": "CWE-285",
      "title": "Cap-go - Authorization Bypass in Organization Members Endpoint via API Key Scope Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56310"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-12986",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.08013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Payara",
      "product": "Payara Server",
      "cwe": "CWE-352",
      "title": "A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All platforms that allows the attacker to leak the admin gfresttoken to an attacker-controlled host that can result in a full unauthenticated takeover of Payara admin domain. A Server-Side Request Forgery (SSRF) vulnerability in the DownloadServlet of the Admin GUI in Payara Server allows a remote attacker to exfiltrate the administrator's REST session token (gfresttoken) to an attacker-controlled host via a crafted request URL. Combined with the absence of CSRF protection on DownloadServlet, an unauthenticated attacker can trick a logged-in administrator into triggering the token leak, then replay the stolen token to gain full administrative access to the Payara domain, leading to arbitrary code execution via WAR deployment. The vulnerability exists in the DownloadServlet and associated ContentSource implementations (LogViewerContentSource, LogFilesContentSource, LBConfigContentSource, ClientStubsContentSource) within the admingui:console-common module.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12986"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-8896",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.0805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mirsoftware",
      "product": "MIR blocks and shortcodes",
      "cwe": "CWE-79",
      "title": "MIR blocks and shortcodes <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8896"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-11877",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenText",
      "product": "Access Manager",
      "cwe": "CWE-648",
      "title": "Missing Authorization Vulnerability in OpenText Access Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11877"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-57300",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins MCP Server Plugin",
      "cwe": "CWE-862",
      "title": "A missing permission check in Jenkins MCP Server Plugin 0.177.v629fdb_2557fe and earlier allows attackers with Item/Read permission to read the Pipeline replay scripts of jobs they can access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57300"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-57302",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins FitNesse Plugin",
      "cwe": "CWE-256",
      "title": "Jenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Extended Read permission or access to the Jenkins controller file system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57302"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-48703",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00177,
      "epss_percentile": 0.07533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "warpdotdev",
      "product": "warp",
      "cwe": "CWE-78",
      "title": "Warp: Command Injection via Warp code search tool arguments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48703"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2025-60471",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-416",
      "title": "A use-after-free in the gf_filter_pid_reconfigure_task_discard function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60471"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-56231",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.07418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-285",
      "title": "Capgo - Broken Object Level Authorization in Build Job Control via jobId Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56231"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-6292",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "manuelpadillac",
      "product": "MP Customize Login Page",
      "cwe": "CWE-352",
      "title": "MP Customize Login Page <= 1.0 - Cross-Site Request Forgery to Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6292"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-56761",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hono",
      "product": "hono",
      "cwe": "CWE-79",
      "title": "hono - HTML Injection via Improper JSX Attribute Name Handling in SSR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56761"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-57293",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Gitee Plugin",
      "cwe": "CWE-862",
      "title": "An incorrect permission check in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers with global Item/Configure permission (while lacking Item/Configure permission on any particular job) to enumerate credentials IDs of credentials stored in Jenkins.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57293"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-8622",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pixelwelt",
      "product": "Image Sizes on Demand",
      "cwe": "CWE-79",
      "title": "Image Sizes on Demand <= 1.3 - Reflected Cross-Site Scripting via PHP_SELF Server Variable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8622"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-52795",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-863",
      "title": "Gogs: Authorization Bypass in Watch API allows any user to monitor private repository activity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52795"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-39897",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cacti",
      "product": "cacti",
      "cwe": "CWE-79",
      "title": "Cacti has a Reflected XSS Vulnerability via html_auth_footer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39897"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-39900",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cacti",
      "product": "cacti",
      "cwe": "CWE-79",
      "title": "Cacti: Reflected XSS via tab parameter in auth_profile.php JavaScript context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39900"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-57297",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Contrast Continuous Application Security Plugin",
      "cwe": "CWE-862",
      "title": "A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username, API key, and service key.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57297"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-57299",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Contrast Continuous Application Security Plugin",
      "cwe": "CWE-862",
      "title": "Missing permission checks in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allow attackers with Overall/Read permission to enumerate the names of configured Contrast metadata.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57299"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-44022",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docling-project",
      "product": "docling",
      "cwe": "CWE-22",
      "title": "Docling: Potential Path Traversal via LaTeX \\includegraphics and \\input Commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44022"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-10753",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00163,
      "epss_percentile": 0.06043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Site Kit by Google",
      "cwe": null,
      "title": "Site Kit by Google < 1.176.0 - Editor+ Email Reporting Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10753"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-13029",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13029"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-46349",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mastodon",
      "product": "mastodon",
      "cwe": "CWE-347",
      "title": "Mastodon: LD-Signature Bypass via JSON-LD Named-Graph Restructuring",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46349"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-57294",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins EC2 Fleet Plugin",
      "cwe": "CWE-862",
      "title": "A missing permission check in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing AWS credentials stored in Jenkins.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57294"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-57304",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Assembla Plugin",
      "cwe": "CWE-862",
      "title": "A missing permission check in Jenkins Assembla Plugin 1.4 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an attacker-specified username and password.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57304"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-54906",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0016,
      "epss_percentile": 0.05734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ruby-concurrency",
      "product": "concurrent-ruby",
      "cwe": "CWE-414",
      "title": "concurrent-ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54906"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2025-60466",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-416",
      "title": "A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60466"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-57283",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Pipeline: Groovy Plugin",
      "cwe": "CWE-352",
      "title": "A cross-site request forgery (CSRF) vulnerability in Jenkins Pipeline: Groovy Plugin 4331.v9d06ed4658ff and earlier allows attackers to instantiate types related to job or system configuration other than Pipeline steps through the Pipeline Snippet Generator.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57283"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-12537",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00153,
      "epss_percentile": 0.05025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google Cloud",
      "product": "Gemini CLI",
      "cwe": "CWE-78",
      "title": "Unauthenticated Remote Code Execution in Gemini CLI CI/CD Workflows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12537"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-52969",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.04911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-129",
      "title": "KVM: Reject wrapped offset in kvm_reset_dirty_gfn()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52969"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-57290",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Priority Sorter Plugin",
      "cwe": "CWE-352",
      "title": "A cross-site request forgery (CSRF) vulnerability in Jenkins Priority Sorter Plugin 936.v2c01c6b_84449 and earlier allows attackers to overwrite the global job priority configuration.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57290"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-52809",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.04823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gogs",
      "product": "gogs",
      "cwe": "CWE-324",
      "title": "Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52809"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-46423",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00149,
      "epss_percentile": 0.0467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RocketChat",
      "product": "Rocket.Chat",
      "cwe": "CWE-347",
      "title": "Rocket.Chat: SAML signature validation skipped when IdP certificate field is empty",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46423"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-13201",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00147,
      "epss_percentile": 0.04467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Container Native Virtualization 4.13",
      "cwe": "CWE-61",
      "title": "Kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-handler enables notify socket hijacking and node-level vm disruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13201"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-39894",
      "cvss_base": 2.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00147,
      "epss_percentile": 0.04435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cacti",
      "product": "cacti",
      "cwe": "CWE-474",
      "title": "Cacti: RRDtool metric shift via LC_NUMERIC locale comma decimal formatting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39894"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-10552",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jotis",
      "product": "Blue Captcha",
      "cwe": "CWE-352",
      "title": "Blue Captcha <= 2.0.1 - Cross-Site Request Forgery via 'blcap_action' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10552"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-13024",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13024"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-48721",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "warpdotdev",
      "product": "warp",
      "cwe": "CWE-180",
      "title": "Warp: Env-var prefixes can lead to denylisted command autoexecution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48721"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-57291",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Gitee Plugin",
      "cwe": "CWE-862",
      "title": "Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57291"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-9724",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "motordesk",
      "product": "MotorDesk",
      "cwe": "CWE-352",
      "title": "MotorDesk <= 1.1.2 - Cross-Site Request Forgery to Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9724"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-52961",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-617",
      "title": "ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52961"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-52972",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-190",
      "title": "crypto: af_alg - Cap AEAD AD length to 0x80000000",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52972"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-56358",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-79",
      "title": "n8n - Stored Cross-Site Scripting in Form Trigger Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56358"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-52976",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00143,
      "epss_percentile": 0.04145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52976"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-13034",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13034"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-13021",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13021"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-52912",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "netfilter: nf_queue: hold bridge skb->dev while queued",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52912"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-52973",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00141,
      "epss_percentile": 0.03944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "futex: Drop CLONE_THREAD requirement for private default hash alloc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52973"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-53016",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.03876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-805",
      "title": "crypto: ccp - copy IV using skcipher ivsize",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53016"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-53059",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.03876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-190",
      "title": "dm log: fix out-of-bounds write due to region_count overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53059"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-57307",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Zowe zDevOps Plugin",
      "cwe": "CWE-862",
      "title": "A missing permission check in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57307"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-53945",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-367",
      "title": "Ghost: Server-side request forgery via DNS rebinding in external request handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53945"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-52950",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "drm/xe/dma-buf: fix UAF with retry loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52950"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-52951",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "drm/xe/dma-buf: handle empty bo and UAF races",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52951"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-52962",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "ceph: fix a buffer leak in __ceph_setxattr()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52962"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-52975",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bonding: 3ad: implement proper RCU rules for port->aggregator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52975"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-52992",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "fs/adfs: validate nzones in adfs_validate_bblk()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52992"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-53036",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-193",
      "title": "bpf, arm64: Fix off-by-one in check_imm signed range check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53036"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-52968",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "KVM: s390: pci: fix GAIT table indexing due to double-scaling pointer arithmetic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52968"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-52952",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-617",
      "title": "iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52952"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-13022",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13022"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-52987",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.03581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-1341",
      "title": "drm/amdgpu: avoid double drm_exec_fini() in userq validate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52987"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-52947",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.0342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "net: qrtr: fix refcount saturation and potential UAF in qrtr_port_remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52947"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-53033",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "bpf, sockmap: Take state lock for af_unix iter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53033"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-8905",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.0343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "osiris8",
      "product": "Osiris Signature Banner",
      "cwe": "CWE-352",
      "title": "Osiris Signature Banner <= 0.5 - Cross-Site Request Forgery to Stored Cross-Site Scripting via 'prepend_text' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8905"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-52996",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "ksmbd: fix durable fd leak on ClientGUID mismatch in durable v2 open",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52996"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-53047",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "efi/capsule-loader: fix incorrect sizeof in phys array reallocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53047"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-52923",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "ipc: limit next_id allocation to the valid ID range",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52923"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-53005",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "af_unix: Drop all SCM attributes for SOCKMAP.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53005"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-52966",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.03353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm: Replace old pointer to new idr",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52966"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-52971",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.0326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "net: ena: PHC: Fix potential use-after-free in get_timestamp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52971"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-52953",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.03298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "iommu/vt-d: Fix oops due to out of scope access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52953"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-53948",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-434",
      "title": "Ghost: File Upload Content-Type Spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53948"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-54639",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "style-dictionary",
      "product": "style-dictionary",
      "cwe": "CWE-1321",
      "title": "Style Dictionary - Prototype Pollution in convertTokenData utility function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54639"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-11878",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenText",
      "product": "Access Manager",
      "cwe": "CWE-79",
      "title": "Reflected Cross-Site Scripting vulnerability in OpenText Access Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11878"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-53096",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53096"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-53090",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-253",
      "title": "bpf: Fix ld_{abs,ind} failure path analysis in subprogs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53090"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-53092",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-393",
      "title": "bpf: Fix linked reg delta tracking when src_reg == dst_reg",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53092"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-53012",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "nexthop: fix IPv6 route referencing IPv4 nexthop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53012"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-57287",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Job Configuration History Plugin",
      "cwe": "CWE-312",
      "title": "Jenkins Job Configuration History Plugin 1356.ve360da_6c523a_ and earlier does not redact the encrypted values of secrets when displaying historical job and agent configurations, allowing attackers with Extended Read permission to view encrypted secret values that would otherwise be redacted.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57287"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-53053",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/amd: Fix clone_alias() to use the original device's devid",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53053"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-53091",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-131",
      "title": "net: pull headers in qdisc_pkt_len_segs_init()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53091"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-53000",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-763",
      "title": "netfilter: nat: use kfree_rcu to release ops",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53000"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-53004",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53004"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-53009",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-415",
      "title": "ice: fix double-free of tx_buf skb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53009"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-53024",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.0303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "greybus: raw: fix use-after-free if write is called after disconnect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53024"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-53025",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "greybus: raw: fix use-after-free on cdev close",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53025"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-53031",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Validate node_id in arena_alloc_pages()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53031"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-53094",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix stale offload->prog pointer after constant blinding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53094"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-53130",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-191",
      "title": "fs/omfs: reject s_sys_blocksize smaller than OMFS_DIR_START",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53130"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-52948",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.0304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-190",
      "title": "i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52948"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-10531",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.03,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "AI Share & Summarize",
      "cwe": null,
      "title": "AI Share & Summarize < 2.0.4 - Contributor+ Stored XSS via title_style Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10531"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-50128",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mastodon",
      "product": "mastodon",
      "cwe": "CWE-354",
      "title": "Mastodon: Spoofing of attribution domains",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50128"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-52963",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.0289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: usb-audio: Bound MIDI endpoint descriptor scans",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52963"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-52970",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.0289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nft_ct: fix missing expect put in obj eval",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52970"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-52984",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.0289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: netem: fix queue limit check to include reordered packets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52984"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-53034",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "bpf, sockmap: Fix af_unix null-ptr-deref in proto update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53034"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-53056",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/msm/dpu: fix mismatch between power and frequency",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53056"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-53060",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "dm cache metadata: fix memory leak on metadata abort retry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53060"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-53063",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm cache: fix write hang in passthrough mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53063"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-57295",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins EC2 Fleet Plugin",
      "cwe": "CWE-352",
      "title": "A cross-site request forgery (CSRF) vulnerability in Jenkins EC2 Fleet Plugin 4.2.3.539.v8fedff2a_81c3 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing AWS credentials stored in Jenkins.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57295"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-57305",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Assembla Plugin",
      "cwe": "CWE-352",
      "title": "A cross-site request forgery (CSRF) vulnerability in Jenkins Assembla Plugin 1.4 and earlier allows attackers to connect to an attacker-specified URL using an attacker-specified username and password.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57305"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-11997",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seo_tools",
      "product": "Bulk SEO Image",
      "cwe": "CWE-352",
      "title": "Bulk SEO Image <= 1.1 - Cross-Site Request Forgery to Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11997"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-53057",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/riscv: Add IOTINVAL after updating DDT/PDT entries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53057"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-53109",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "powerpc/pgtable-frag: Fix bad page state in pte_frag_destroy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53109"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-52964",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52964"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-52990",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fsnotify: fix inode reference leak in fsnotify_recalc_mask()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52990"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-53051",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "PCI: tegra194: Fix CBB timeout caused by DBI access before core power-on",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53051"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-53011",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "net/sched: taprio: fix use-after-free in advance_sched() on schedule switch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53011"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-52915",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-129",
      "title": "netfilter: ip6t_hbh: reject oversized option lists",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52915"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-52917",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "sctp: diag: reject stale associations in dump_one path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52917"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-53041",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "ocfs2: fix listxattr handling when the buffer is full",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53041"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-52978",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: psp: require admin permission for dev-set and key-rotate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52978"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-52994",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52994"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-52997",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.0272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "net/sched: sch_dualpi2: drain both C-queue and L-queue in dualpi2_change()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52997"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-53097",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "wifi: mt76: mt7996: fix use-after-free bugs in mt7996_mac_dump_work()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53097"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-53098",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "wifi: mt76: mt7915: fix use-after-free bugs in mt7915_mac_dump_work()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53098"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-52942",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.0266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "netfilter: nf_log: validate MAC header was set before dumping it",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52942"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-53044",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.0254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "soc/tegra: cbb: Fix incorrect ARRAY_SIZE in fabric lookup tables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53044"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-48028",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.0252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mastodon",
      "product": "mastodon",
      "cwe": "CWE-354",
      "title": "Mastodon: Removal of integrity-protected JSON entries from signed activities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48028"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-11968",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TortoiseGit team",
      "product": "TortoiseGit",
      "cwe": "CWE-88",
      "title": "Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') in TortoiseGit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11968"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-52913",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "batman-adv: v: stop OGMv2 on disabled interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52913"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-52916",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "batman-adv: frag: disallow unicast fragment in fragment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52916"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-52965",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-835",
      "title": "drm/ttm: Fix ttm_bo_swapout() infinite LRU walk on swapout failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52965"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-52977",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "futex: Prevent lockup in requeue-PI during signal/ timeout wakeup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52977"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-52985",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "netdevsim: zero initialize struct iphdr in dummy sk_buff",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52985"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-52995",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/rds: zero per-item info buffer before handing it to visitors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52995"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-53001",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: xtables: restrict several matches to inet family",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53001"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-53021",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-190",
      "title": "scsi: target: core: Fix integer overflow in UNMAP bounds check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53021"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-53022",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "platform/x86: dell-wmi-sysman: bound enumeration string aggregation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53022"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-53023",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/ntfs3: terminate the cached volume label after UTF-8 conversion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53023"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-53039",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-617",
      "title": "ocfs2: validate group add input before caching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53039"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-53048",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "gfs2: prevent NULL pointer dereference during unmount",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53048"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-53052",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ASoC: qcom: qdsp6: topology: check widget type before accessing data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53052"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-53061",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm cache: fix dirty mapping checking in passthrough mode switching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53061"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-53064",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "dm cache: fix null-deref with concurrent writes in passthrough mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53064"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-53093",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "wifi: brcmfmac: Fix error pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53093"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-53081",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-386",
      "title": "bpf: Enforce regsafe base id consistency for BPF_ADD_CONST scalars",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53081"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-53117",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "s390/cio: use generic driver_override infrastructure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53117"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-52988",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52988"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-53040",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "ocfs2: validate bg_bits during freefrag scan",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53040"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-13006",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QOS.CH Sarl",
      "product": "Logback-core",
      "cwe": "CWE-20",
      "title": "Incomplete protection against CVE-2025-11226",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13006"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-52980",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "sched/fair: Clear rel_deadline when initializing forked entities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52980"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-53013",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53013"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-53014",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/sched: act_mirred: fix wrong device for mac_header_xmit check in tcf_blockcast_redir",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53014"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-53015",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "erofs: unify lcn as u64 for 32-bit platforms",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53015"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-53027",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53027"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-53032",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "bpf: Fix NULL deref in map_kptr_match_type for scalar regs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53032"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-53038",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "ima_fs: Correctly create securityfs files for unsupported hash algos",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53038"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-53058",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "drm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier in atomic_enable()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53058"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-53105",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "wifi: mt76: mt7925: prevent NULL vif dereference in mt7925_mac_write_txwi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53105"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-53946",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-918",
      "title": "Ghost: Mobiledoc image-size fetch SSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53946"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-52944",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET_SPARSE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52944"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-53018",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: avoid reading already updated pages during GC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53018"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-53019",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "clk: spacemit: ccu_mix: fix inverted condition in ccu_mix_trigger_fc()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53019"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-53028",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "usb: typec: Fix error pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53028"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-53030",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "i3c: master: renesas: Fix memory leak in renesas_i3c_i3c_xfers()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53030"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-53042",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-824",
      "title": "fwctl: Fix class init ordering to avoid NULL pointer dereference on device removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53042"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-53095",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.0224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix abuse of kprobe_write_ctx via freplace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53095"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-53104",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "wifi: mt76: Fix memory leak destroying device",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53104"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-53111",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53111"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-53128",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drbd: Balance RCU calls in drbd_adm_dump_devices()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53128"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-56370",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-125",
      "title": "ImageMagick - Out-of-bounds Access in ConnectedComponentsImage via connected-components Artifact",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56370"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-42450",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcademySoftwareFoundation",
      "product": "OpenColorIO",
      "cwe": "CWE-120",
      "title": "OpenColorIO vulnerable to stack buffer overflow via unbounded `sscanf %s` in Spi3D (.spi3d) LUT parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42450"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-52927",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "netfilter: ebtables: fix OOB read in compat_mtw_from_user",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52927"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-52933",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-835",
      "title": "io_uring/poll: fix signed comparison in io_poll_get_ownership()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52933"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-52935",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "xfrm: espintcp: do not reuse an in-progress partial send",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52935"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-53077",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/rds: Restrict use of RDS/IB to the initial network namespace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53077"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-53078",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53078"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-53110",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/bpf: Zero-extend bpf prog return values and kfunc arguments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53110"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-53115",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "bus: fsl-mc: use generic driver_override infrastructure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53115"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-53119",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.0218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "platform/wmi: use generic driver_override infrastructure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53119"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-53120",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "PCI: use generic driver_override infrastructure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53120"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-53067",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00119,
      "epss_percentile": 0.02046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-415",
      "title": "PCI: endpoint: pci-ep-msi: Fix error unwind and prevent double alloc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53067"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-53085",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00119,
      "epss_percentile": 0.02057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "bpf: fix mm lifecycle in open-coded task_vma iterator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53085"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-53118",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00119,
      "epss_percentile": 0.02083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "vdpa: use generic driver_override infrastructure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53118"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-52941",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52941"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-53065",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "ASoC: sti: use managed regmap_field allocations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53065"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-47733",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.01985,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RocketChat",
      "product": "Rocket.Chat",
      "cwe": "CWE-79",
      "title": "Rocket.Chat: Missing URL protocol sanitization in ImageElement allows javascript: URLs in markdown images",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47733"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-52919",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-191",
      "title": "batman-adv: fix tp_meter counter underflow during shutdown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52919"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-53112",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prepare_bcn_tasklet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53112"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-53129",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "fs/mbcache: cancel shrink work before destroying the cache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53129"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-53068",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-190",
      "title": "drm/komeda: fix integer overflow in AFBC framebuffer size check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53068"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-53076",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "bpf: Fix OOB in pcpu_init_value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53076"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-52939",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52939"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-53123",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "md: wake raid456 reshape waiters before suspend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53123"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-52930",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipc/shm: serialize orphan cleanup with shm_nattch updates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52930"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-52921",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-835",
      "title": "netfilter: ipset: stop hash:* range iteration at end",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52921"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-52925",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "vrf: Fix a potential NPD when removing a port from a VRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52925"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-52926",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "batman-adv: clear current gateway during teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52926"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-52928",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.0175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "af_unix: Reject SIOCATMARK on non-stream sockets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52928"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-52936",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: jitterentropy - replace long-held spinlock with mutex",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52936"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-53066",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "drm/sun4i: backend: fix error pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53066"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-53073",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53073"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-53074",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53074"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-53080",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "net/sched: cls_fw: fix NULL dereference of \"old\" filters before change()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53080"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-53082",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53082"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-53083",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Fix RCU stall in bpf_fd_array_map_clear()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53083"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-53084",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: return VMA snapshot from task_vma iterator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53084"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-53126",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53126"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-53107",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: libertas: don't kill URBs in interrupt context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53107"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-53121",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "amd-pstate: Fix memory leak in amd_pstate_epp_cpu_init()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53121"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-53089",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "bpf: Fix use-after-free in offloaded map/prog info fill",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53089"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-53116",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "s390/ap: use generic driver_override infrastructure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53116"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-52937",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52937"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-52940",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tun: zero the whole vnet header in tun_put_user()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52940"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-52949",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/ttm: Fix ttm_bo_shrink() infinite LRU walk on backup failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52949"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-53017",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "f2fs: fix data loss caused by incorrect use of nat_entry flag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53017"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-53114",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "perf/amd/ibs: Avoid calling perf_allow_kernel() from the IBS NMI handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53114"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-57306",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0011,
      "epss_percentile": 0.01492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Zowe zDevOps Plugin",
      "cwe": "CWE-352",
      "title": "A cross-site request forgery (CSRF) vulnerability in Jenkins Zowe zDevOps Plugin 1.1.3.50.ve350c9b_450b_1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57306"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-53099",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53099"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-53102",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "wifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53102"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-53113",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "wifi: ath11k: fix memory leaks in beacon template setup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53113"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-57289",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Bitbucket Push and Pull Request Plugin",
      "cwe": "CWE-295",
      "title": "Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditionally disables SSL/TLS certificate and hostname validation for connections sending Bearer token authenticated requests to the configured Bitbucket Server endpoint, allowing attackers able to intercept network traffic to capture the token.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57289"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-52991",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.01345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "sched/psi: fix race between file release and pressure write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52991"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-53766",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ChromeDevTools",
      "product": "chrome-devtools-mcp",
      "cwe": "CWE-22",
      "title": "chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing roots",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53766"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-53007",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "ice: fix potential NULL pointer deref in error path of ice_set_ringparam()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53007"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-53029",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "fs/ntfs3: prevent uninitialized lcn caused by zero len",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53029"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-9539",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "freedesktop.org",
      "product": "libslirp",
      "cwe": "CWE-125",
      "title": "libslirp TCP URG OOB Read Information Leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9539"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-54905",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00106,
      "epss_percentile": 0.01266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ruby-concurrency",
      "product": "concurrent-ruby",
      "cwe": "CWE-128",
      "title": "concurrent-ruby: `ReentrantReadWriteLock` read-count overflow grants a write lock without exclusivity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54905"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-13037",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00105,
      "epss_percentile": 0.01204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13037"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-9721",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chuhpl",
      "product": "Book a Room Event Calendar",
      "cwe": "CWE-352",
      "title": "Book a Room Event Calendar <= 1.9 - Cross-Site Request Forgery to Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9721"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-57292",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.01019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Gitee Plugin",
      "cwe": "CWE-352",
      "title": "A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57292"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-57298",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.01019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jenkins Project",
      "product": "Jenkins Contrast Continuous Application Security Plugin",
      "cwe": "CWE-352",
      "title": "A cross-site request forgery (CSRF) vulnerability in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers to have Jenkins connect to an attacker-specified URL using an attacker-specified username, API key, and service key.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57298"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-53050",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.001,
      "epss_percentile": 0.00961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "quota: Fix race of dquot_scan_active() with quota deactivation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53050"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-52938",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "bpf: Fix NULL pointer dereference in bpf_sk_storage_clone and diag paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52938"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-53079",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "net_sched: fix skb memory leak in deferred qdisc drops",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53079"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-53106",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.0101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "bpf: Do not allow deleting local storage in NMI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53106"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-53124",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.01009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ublk: reset per-IO canceled flag on each fetch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53124"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-53127",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.01007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "block: fix zones_cond memory leak on zone revalidation error paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53127"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-53054",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00098,
      "epss_percentile": 0.00894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "drm/msm: Fix VM_BIND UNMAP locking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53054"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-53062",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00097,
      "epss_percentile": 0.00849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "dm cache policy smq: fix missing locks in invalidating cache blocks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53062"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-7539",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00096,
      "epss_percentile": 0.00827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc.",
      "product": "HP Dock Accessory",
      "cwe": "CWE-379",
      "title": "HP Dock Accessory WMI Provider Installer Security Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7539"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-53765",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ChromeDevTools",
      "product": "chrome-devtools-mcp",
      "cwe": "CWE-59",
      "title": "chrome-devtools-mcp: daemon.pid write follows symlinks in /tmp fallback runtime directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53765"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-53035",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "bpf, sockmap: Fix af_unix iter deadlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53035"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-53037",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "HID: usbhid: fix deadlock in hid_post_reset()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53037"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-53101",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "wifi: mt76: mt7921: fix potential deadlock in mt7921_roc_abort_sync",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53101"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-53100",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.0068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "wifi: mt76: fix deadlock in remain-on-channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53100"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-53103",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.00681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "wifi: mt76: mt7925: fix potential deadlock in mt7925_roc_abort_sync",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53103"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-52959",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00093,
      "epss_percentile": 0.00619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "virt: sev-guest: Do not use host-controlled page order in cleanup path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52959"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-53020",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00093,
      "epss_percentile": 0.00646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "um: Fix potential race condition in TLB sync",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53020"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-52979",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "net: psp: check for device unregister when creating assoc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52979"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-53122",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "btrfs: fix deadlock between reflink and transaction commit when using flushoncommit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53122"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-56269",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-798",
      "title": "Flowise - Weak Default Token Hash Secret in JWT Token Encryption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56269"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-53125",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00092,
      "epss_percentile": 0.00594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "md: fix array_state=clear sysfs deadlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53125"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-13208",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0009,
      "epss_percentile": 0.00515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Virtualization 4",
      "cwe": "CWE-287",
      "title": "Kubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi identity from unauthenticated grpc request body",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13208"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-53008",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00077,
      "epss_percentile": 0.00132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "ice: fix race condition in TX timestamp ring cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53008"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-53108",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00077,
      "epss_percentile": 0.00137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "powerpc/64s: Fix unmap race with PMD migration entries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53108"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-56272",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00073,
      "epss_percentile": 0.00077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-916",
      "title": "Flowise - Insufficient Password Salt Rounds in Bcrypt Hashing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56272"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-60466",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-60466. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-60467",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-60467. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-60468",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-60468. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-60471",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-60471. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-60473",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-60473. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-60474",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-60474. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-71332",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-71332 (Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10642",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10642 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-11998",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-11998 (Google AngularJS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49979",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49979 (appsmithorg appsmith). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50189",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50189 (appsmithorg appsmith). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-53765",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-53765 (ChromeDevTools chrome-devtools-mcp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-53766",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-53766 (ChromeDevTools chrome-devtools-mcp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54297",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54297 (lostisland faraday). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54904",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54904 (ruby-concurrency concurrent-ruby). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55454",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55454 (appsmithorg appsmith). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56270",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56270 (Flowise). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-11645",
      "detail": "DUE DATE PASSED — CVE-2026-11645 (Google Chrome). CISA remediation deadline was June 23, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-20245",
      "detail": "DUE DATE PASSED — CVE-2026-20245 (Cisco Catalyst SD-WAN Controller). CISA remediation deadline was June 23, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-7473",
      "detail": "DUE DATE PASSED — CVE-2026-7473 (Arista Networks EOS). CISA remediation deadline was June 23, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
