{
  "day": "2026-06-25",
  "boundary": "UTC calendar day",
  "published_count": 468,
  "by_severity": {
    "CRITICAL": 42,
    "HIGH": 219,
    "MEDIUM": 172,
    "LOW": 35
  },
  "kev_count": 2,
  "exploit_reference_count": 48,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-20230",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.83213,
      "epss_percentile": 0.99652,
      "kev": true,
      "kev_due_at": "2026-06-28",
      "vendor": "Cisco",
      "product": "Cisco Unified Communications Manager",
      "cwe": "CWE-918",
      "title": "Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20230"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-12569",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.30198,
      "epss_percentile": 0.98072,
      "kev": true,
      "kev_due_at": "2026-06-28",
      "vendor": "PTC",
      "product": "Windchill PDMLink",
      "cwe": "CWE-20",
      "title": "Remote Code Execution (RCE) vulnerability in Windchill PDMlink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12569"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2025-71334",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.03903,
      "epss_percentile": 0.89429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-73",
      "title": "Flowise - Arbitrary File Access via Missing Chat Flow ID Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71334"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-56766",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01984,
      "epss_percentile": 0.78968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vanhauser-thc",
      "product": "thc-hydra",
      "cwe": "CWE-121",
      "title": "Hydra - Stack Buffer Overflow in NTLM Authentication Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56766"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2025-71336",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01562,
      "epss_percentile": 0.73269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-78",
      "title": "Flowise - Unsandboxed Remote Code Execution via Custom MCP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71336"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2025-71324",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01379,
      "epss_percentile": 0.69911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-73",
      "title": "Flowise - Arbitrary File Read via chatId Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71324"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-50549",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01267,
      "epss_percentile": 0.67431,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cursor",
      "product": "cursor",
      "cwe": "CWE-59",
      "title": "Cursor Desktop sandbox escape via symlink and failed path canonicalization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50549"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-9717",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01191,
      "epss_percentile": 0.65461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Schneider Electric",
      "product": "PowerLogic™ P7",
      "cwe": "CWE-78",
      "title": "CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, impacting system integrity, confidentiality, and availability when a privileged authenticated user interacts with a vulnerable network-exposed service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9717"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-54836",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01048,
      "epss_percentile": 0.6154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YMC",
      "product": "YMC Filter",
      "cwe": "CWE-89",
      "title": "WordPress Filter & Grids plugin <= 3.11.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54836"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-50548",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00957,
      "epss_percentile": 0.58671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cursor",
      "product": "cursor",
      "cwe": "CWE-22",
      "title": "Cursor Desktop sandbox escape via agent-controlled working directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50548"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-9155",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00916,
      "epss_percentile": 0.57396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "InsightConnect Sed Plugin",
      "cwe": "CWE-78",
      "title": "OS Command Injection in Rapid7 InsightConnect Sed Plugin via expression parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9155"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2025-71338",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00864,
      "epss_percentile": 0.55798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-73",
      "title": "Flowise - Arbitrary File Write to Remote Code Execution via document-store API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71338"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-8658",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00833,
      "epss_percentile": 0.54813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "InsightConnect Tcpdump Plugin",
      "cwe": "CWE-78",
      "title": "OS Command Injection in Rapid7 InsightConnect Tcpdump Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8658"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-8659",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00833,
      "epss_percentile": 0.54813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "InsightConnect SQLmap Plugin",
      "cwe": "CWE-78",
      "title": "OS Command Injection in Rapid7 InsightConnect SQLmap Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8659"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-8664",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00833,
      "epss_percentile": 0.54814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "InsightConnect Finger Plugin",
      "cwe": "CWE-78",
      "title": "OS Command Injection in Rapid7 InsightConnect Finger Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8664"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2025-71333",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00801,
      "epss_percentile": 0.53791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-73",
      "title": "Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71333"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-53176",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00732,
      "epss_percentile": 0.5153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-191",
      "title": "IB/isert: Reject login PDUs shorter than ISER_HEADERS_LEN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53176"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-8592",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00675,
      "epss_percentile": 0.4941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "InsightConnect AWK Plugin",
      "cwe": "CWE-78",
      "title": "OS Command Injection in Rapid7 InsightConnect AWK Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8592"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-8660",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00675,
      "epss_percentile": 0.4941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "InsightConnect Ping Plugin",
      "cwe": "CWE-78",
      "title": "OS Command Injection in Rapid7 InsightConnect Ping Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8660"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-8665",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00675,
      "epss_percentile": 0.49409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "InsightConnect TR Plugin",
      "cwe": "CWE-78",
      "title": "OS Command Injection in Rapid7 InsightConnect Translate Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8665"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-8666",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00675,
      "epss_percentile": 0.4941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "InsightConnect Traceroute Plugin",
      "cwe": "CWE-78",
      "title": "OS Command Injection in Rapid7 InsightConnect Traceroute Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8666"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-46735",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00647,
      "epss_percentile": 0.48239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Display and Peripheral Manager",
      "cwe": "CWE-78",
      "title": "Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46735"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-54088",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0063,
      "epss_percentile": 0.47481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-78",
      "title": "File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54088"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2025-71327",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00582,
      "epss_percentile": 0.45249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-306",
      "title": "Flowise - Authentication Bypass via Unprotected Registration Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71327"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-12053",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00582,
      "epss_percentile": 0.45266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-532",
      "title": "Insertion of Sensitive Information into Log File in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12053"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-49506",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00579,
      "epss_percentile": 0.45116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Wyse Management Suite",
      "cwe": "CWE-22",
      "title": "Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49506"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-6679",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00576,
      "epss_percentile": 0.4497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-787",
      "title": "DTLS 1.3 ACK serialization heap buffer overflow via integer truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6679"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-45233",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00567,
      "epss_percentile": 0.44532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danpros",
      "product": "htmly",
      "cwe": "CWE-22",
      "title": "HTMLy CMS 3.1.1 Path Traversal via oldfile Parameter in Autosave",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45233"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-54823",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0056,
      "epss_percentile": 0.44165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MarketingFire",
      "product": "Widget Options",
      "cwe": "CWE-94",
      "title": "WordPress Widget Options plugin <= 4.2.3 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54823"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-43920",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00545,
      "epss_percentile": 0.43374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-306",
      "title": "FOSSBilling: Unauthenticated update patcher endpoint allows remote maintenance execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43920"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-9083",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00519,
      "epss_percentile": 0.41921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-22",
      "title": "Keycloak: keycloak: information disclosure through arbitrary filesystem path probing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9083"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-53224",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00517,
      "epss_percentile": 0.41839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "sctp: validate embedded INIT chunk and address list lengths in cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53224"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-53221",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00514,
      "epss_percentile": 0.41635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53221"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-53228",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00514,
      "epss_percentile": 0.41635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv6: sit: reload inner IPv6 header after GSO offloads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53228"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-53186",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00514,
      "epss_percentile": 0.41638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/srp: bound SRP_RSP sense copy by the received length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53186"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-53225",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00514,
      "epss_percentile": 0.41635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "sctp: fix uninit-value in __sctp_rcv_asconf_lookup()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53225"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-53215",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00502,
      "epss_percentile": 0.40911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: mvpp2: refill RX buffers before XDP or skb use",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53215"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-53216",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00502,
      "epss_percentile": 0.40912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: mvpp2: limit XDP frame size to the RX buffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53216"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-53199",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00501,
      "epss_percentile": 0.40834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53199"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-54092",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00484,
      "epss_percentile": 0.398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-400",
      "title": "File Browser: DoS Vulnerability on Public Login API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54092"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-53183",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.39465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mptcp: allow subflow rcv wnd to shrink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53183"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-53184",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.39466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "udp: clear skb->dev before running a sockmap verdict",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53184"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-50016",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00473,
      "epss_percentile": 0.39052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pnpm",
      "product": "pnpm",
      "cwe": "CWE-23",
      "title": "pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50016"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-54091",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00471,
      "epss_percentile": 0.38952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-863",
      "title": "File Browser: Incorrect access control in public directory shares via rule path rebasing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54091"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-54094",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0047,
      "epss_percentile": 0.38848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-22",
      "title": "File Browser: Symlink following lets scoped users read, overwrite, and share files outside their filebrowser scope",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54094"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-53247",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00467,
      "epss_percentile": 0.38655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "net: ethernet: mtk_eth_soc: Fix use-after-free in metadata dst teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53247"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-53151",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00457,
      "epss_percentile": 0.38061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "rxrpc: Fix the ACK parser to extract the SACK table for parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53151"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-41120",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00452,
      "epss_percentile": 0.37706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Wyse Management Suite",
      "cwe": "CWE-349",
      "title": "Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41120"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-56054",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00451,
      "epss_percentile": 0.3766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ahmad",
      "product": "JS Help Desk",
      "cwe": "CWE-22",
      "title": "WordPress JS Help Desk plugin <= 3.1.1 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56054"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-38637",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.37296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38637"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-38640",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.37297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted string.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38640"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-55667",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00443,
      "epss_percentile": 0.37052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-22",
      "title": "File Browser: Out-of-scope file deletion by a Create-only scoped user via symlink-following RemoveAll in upload failure-cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55667"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-53246",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00442,
      "epss_percentile": 0.36978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53246"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-53229",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53229"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-53235",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: add pskb_may_pull() to skb_gro_receive_list()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53235"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-56786",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00438,
      "epss_percentile": 0.36653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tomojitakasu",
      "product": "RTKLIB",
      "cwe": "CWE-787",
      "title": "RTKLIB 2.4.3 - Out-of-bounds Write in decode_type1033 via Crafted RTCM3 Message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56786"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-53198",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "ksmbd: fix use-after-free of a deferred file_lock on double SMB2_CANCEL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53198"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-56445",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00434,
      "epss_percentile": 0.36303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pydicom",
      "product": "pynetdicom Library",
      "cwe": "CWE-22",
      "title": "pydicom pynetdicom Library Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56445"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-54089",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00431,
      "epss_percentile": 0.36129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-287",
      "title": "File Browser: Authentication Bypass via Proxy Auth Header Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54089"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-50176",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00429,
      "epss_percentile": 0.35929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EVoke",
      "product": "EVoke CSMS",
      "cwe": "CWE-307",
      "title": "EVoke Systems EVoke CSMS Improper Restriction of Excessive Authentication Attempts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50176"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-53131",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00425,
      "epss_percentile": 0.35653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: require Ethernet MAC header before using eth_hdr()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53131"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-56091",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Shiro",
      "cwe": "CWE-289",
      "title": "Apache Shiro: Authentication bypass in Guice-Web integration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56091"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-9086",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00419,
      "epss_percentile": 0.3517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-79",
      "title": "Keycloak: keycloak: cross-site scripting (xss) via case-insensitive uri validation bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9086"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-40702",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00415,
      "epss_percentile": 0.34747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EVoke",
      "product": "EVoke CSMS",
      "cwe": "CWE-306",
      "title": "EVoke Systems EVoke CSMS Missing Authentication for Critical Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40702"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-55699",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00413,
      "epss_percentile": 0.34583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pnpm",
      "product": "pnpm",
      "cwe": "CWE-22",
      "title": "pnpm: reserved bin name deletes PNPM_HOME during global remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55699"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-55958",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00412,
      "epss_percentile": 0.34563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-787",
      "title": "Renesas TSIP TLS 1.3 transcript buffer out-of-bounds write in tsip_StoreMessage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55958"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-54097",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-639",
      "title": "File Browser: Cross-user unauthorized share-link deletion via unbounded prefix match in DeleteWithPathPrefix",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54097"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2025-71328",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00405,
      "epss_percentile": 0.33871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-620",
      "title": "Flowise - Unverified Password Change via Account Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71328"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-12844",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DROLSKY",
      "product": "List::SomeUtils::XS",
      "cwe": "CWE-122",
      "title": "List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12844"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-37452",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.3313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSIAPService.exe component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37452"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-37453",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.3313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSI_SERVICE_2 pipe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37453"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-46752",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00395,
      "epss_percentile": 0.3291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Kvrocks",
      "cwe": "CWE-122",
      "title": "Apache Kvrocks: Stack buffer overflow in Lua bit.tohex()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46752"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-53240",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0039,
      "epss_percentile": 0.32327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "xfrm: iptfs: fix use-after-free on first_skb in __input_process_payload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53240"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-40084",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00386,
      "epss_percentile": 0.31944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cacti",
      "product": "cacti",
      "cwe": "CWE-22",
      "title": "Cacti: Arbitrary File Read via Path Traversal in Report `format_file` Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40084"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-42387",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00386,
      "epss_percentile": 0.31894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "Recursor",
      "cwe": "CWE-20",
      "title": "Insufficient input validation in ZoneToCache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42387"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-42388",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00386,
      "epss_percentile": 0.31894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "Recursor",
      "cwe": "CWE-20",
      "title": "Missing input validation for catalog zones",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42388"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-54917",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00385,
      "epss_percentile": 0.31794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seaweedfs",
      "product": "seaweedfs",
      "cwe": "CWE-22",
      "title": "SeaweedFS: Path traversal in the S3 and Iceberg REST gateways allows cross-bucket access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54917"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-53217",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.3177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: mvpp2: sync RX data at the hardware packet offset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53217"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-56768",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00381,
      "epss_percentile": 0.31379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "haiwen",
      "product": "seahub",
      "cwe": "CWE-862",
      "title": "Seahub < 13.0.23 - Authentication Bypass in ShareLinkZipTaskView GET Method",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56768"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-56053",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EventPrime",
      "product": "EventPrime",
      "cwe": "CWE-502",
      "title": "WordPress EventPrime plugin <= 4.3.4.1 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56053"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-56122",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00377,
      "epss_percentile": 0.30957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rickknowles",
      "product": "Winstone Servlet Container",
      "cwe": "CWE-22",
      "title": "Winstone Servlet Engine 0.9.10 Path Traversal via HTTP Request Paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56122"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-50017",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00376,
      "epss_percentile": 0.30881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pnpm",
      "product": "pnpm",
      "cwe": "CWE-200",
      "title": "pnpm binds unscoped user-level npm auth credentials to a repository-selected registry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50017"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-5305",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.30477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Email Address Encoder",
      "cwe": null,
      "title": "Email Address Encoder (Free < 1.0.25, Premium < 0.3.12) - Unauthenticated Stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5305"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-53260",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.30086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53260"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-57435",
      "cvss_base": 1.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00368,
      "epss_percentile": 0.29979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sparklemotion",
      "product": "nokogiri",
      "cwe": "CWE-416",
      "title": "Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57435"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-50015",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pnpm",
      "product": "pnpm",
      "cwe": "CWE-22",
      "title": "pnpm: Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50015"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-57700",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00362,
      "epss_percentile": 0.29454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Daan.dev",
      "product": "OMGF Pro",
      "cwe": "CWE-434",
      "title": "WordPress OMGF Pro plugin <= 5.2.6 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57700"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-13311",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.2927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ljharb",
      "product": "shell-quote",
      "cwe": "CWE-407",
      "title": "shell-quote parse() is quadratic in token count, enabling denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13311"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-9800",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.28997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-1025",
      "title": "Keycloak-policy-enforcer: keycloak policy enforcer: authorization bypass via incorrect uri comparison",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9800"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-57434",
      "cvss_base": 1.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00358,
      "epss_percentile": 0.29018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sparklemotion",
      "product": "nokogiri",
      "cwe": "CWE-476",
      "title": "Nokogiri: Null Pointer Dereference calling methods on uninitialized wrapper classes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57434"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-10712",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00356,
      "epss_percentile": 0.28825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-79",
      "title": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10712"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-53248",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "net: airoha: Fix use-after-free in metadata dst teardown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53248"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-57520",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bitwarden",
      "product": "server",
      "cwe": "CWE-862",
      "title": "Bitwarden Server < 2026.5.0 Privilege Escalation via Bulk User Remove Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57520"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-57587",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00353,
      "epss_percentile": 0.28484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tenable",
      "product": "Nessus",
      "cwe": "CWE-89",
      "title": "SQL Injection in Nessus via Reverse DNS Lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57587"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-55700",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pnpm",
      "product": "pnpm",
      "cwe": "CWE-22",
      "title": "pnpm: stage download writes outside destination via manifest version traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55700"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-54226",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00349,
      "epss_percentile": 0.28046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Kvrocks",
      "cwe": "CWE-190",
      "title": "Apache Kvrocks: RESTORE IntSet Integer Overflow Leads to Remote DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54226"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-7531",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00347,
      "epss_percentile": 0.27832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-416",
      "title": "Use-after-free in PQC hybrid key-share handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7531"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-57588",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00346,
      "epss_percentile": 0.27754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tenable",
      "product": "Nessus",
      "cwe": "CWE-89",
      "title": "SQL Injection in Nessus via Malicious Scan Result File Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57588"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-54037",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danny-avila",
      "product": "LibreChat",
      "cwe": "CWE-770",
      "title": "LibreChat: Incomplete Fix for CVE-2025-7105 — /api/convos/duplicate Lacks Rate Limiting Applied to /api/convos/fork",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54037"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-13225",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "pretix",
      "cwe": "CWE-80",
      "title": "Stored XSS in ticket confirmation page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13225"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-53268",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "netfilter: conntrack_irc: fix possible out-of-bounds read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53268"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-53165",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "iomap: avoid potential null folio->mapping deref during error reporting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53165"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-53244",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "VFS: fix possible failure to unlock in nfsd4_create_file()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53244"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-42005",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00344,
      "epss_percentile": 0.27506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "Authoritative",
      "cwe": "CWE-400",
      "title": "Insufficient input validation of internal web server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42005"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-55477",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.2734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MHSanaei",
      "product": "3x-ui",
      "cwe": "CWE-73",
      "title": "Authenticated Arbitrary File Write via Database Import and Xray Log Path Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55477"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-57235",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00341,
      "epss_percentile": 0.27196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sparklemotion",
      "product": "nokogiri",
      "cwe": "CWE-125",
      "title": "Nokogiri: Possible Out-of-Bounds Read in `Nokogiri::XML::NodeSet#[]`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57235"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-57236",
      "cvss_base": 1.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00341,
      "epss_percentile": 0.27196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sparklemotion",
      "product": "nokogiri",
      "cwe": "CWE-416",
      "title": "Nokogiri: Possible Use-After-Free when `Nokogiri::XML::Document#encoding=` raises an exception",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57236"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-56049",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Post Snippets",
      "product": "Post Snippets",
      "cwe": "CWE-94",
      "title": "WordPress Post Snippets plugin <= 4.0.19 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56049"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-53180",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "timers/migration: Fix livelock in tmigr_handle_remote_up()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53180"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-56770",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.27022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "schwehr",
      "product": "libais",
      "cwe": "CWE-129",
      "title": "libais 0.15 - Out-of-bounds Vector Access in VdmStream::AddLine via Invalid Sequential Message ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56770"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-52690",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00339,
      "epss_percentile": 0.2698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "Recursor",
      "cwe": "CWE-290",
      "title": "Spoofed answers can mark an authoritative non-EDNS capable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52690"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-10086",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00338,
      "epss_percentile": 0.26899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-79",
      "title": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10086"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-55439",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00337,
      "epss_percentile": 0.26768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "halo-dev",
      "product": "halo",
      "cwe": "CWE-22",
      "title": "Halo: Path Traversal in Backup Download Leads to Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55439"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-46601",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/image",
      "product": "golang.org/x/image/webp",
      "cwe": null,
      "title": "Panic on VP8 alpha channel size mismatch in x/image/webp in golang.org/x/image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46601"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-46602",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/image",
      "product": "golang.org/x/image/tiff",
      "cwe": null,
      "title": "Lack of limit on tile sizes in x/image/tiff in golang.org/x/image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46602"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-56787",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00335,
      "epss_percentile": 0.26576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tomojitakasu",
      "product": "RTKLIB",
      "cwe": "CWE-193",
      "title": "RTKLIB 2.4.3 - Off-by-One Out-of-Bounds Read in decode_ssr3 via RTCM3 SSR Message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56787"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-40083",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cacti",
      "product": "cacti",
      "cwe": "CWE-89",
      "title": "Cacti: SQL Injection in managers.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40083"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-57532",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.25963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "pretix",
      "cwe": "CWE-80",
      "title": "Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in the browser. This could allow one backend user to inject JavaScript into the browser context of another backend user. Due to requirements of the PDF rendering and editing libraries used, this is one of the few pages in our backend that do not have a strong Content-Security-Policy that would render this capability useless for most scenarios.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57532"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-56767",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.26017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getmaxun",
      "product": "maxun",
      "cwe": "CWE-862",
      "title": "Maxun < 0.0.42 - Cross-Tenant IDOR in Storage and Webhook API Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56767"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-57534",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0033,
      "epss_percentile": 0.25963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "pretix-pages",
      "cwe": "CWE-80",
      "title": "Stored XSS in pretix-pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57534"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-13314",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.0033,
      "epss_percentile": 0.25962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "pretix-digital",
      "cwe": "CWE-80",
      "title": "Stored XSS in pretix-digital",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13314"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-55180",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00326,
      "epss_percentile": 0.25584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pnpm",
      "product": "pnpm",
      "cwe": "CWE-200",
      "title": "pnpm: Repository config can expand victim environment secrets into registry requests before scripts run",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55180"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-12244",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "NSD",
      "cwe": "CWE-122",
      "title": "Heap overflow and crash with crafted SVCB RR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12244"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-13351",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.2534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject-rtos",
      "product": "Zephyr",
      "cwe": "CWE-772",
      "title": "net: Maliciously fragmented IPv6 packets can prevent receiving/processing future incoming packets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13351"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-46751",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00324,
      "epss_percentile": 0.25291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Kvrocks",
      "cwe": null,
      "title": "Apache Kvrocks: Does not remove the unsafe loadstring function from its Lua sandbox, allowing a user who can run EVAL scripts to load crafted, unvalidated bytecode that crashes the server process, resulting in a remote denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46751"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-54090",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-77",
      "title": "File Browser: Command Allowlist Bypass via Shell Metacharacter Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54090"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2025-71335",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.24944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-613",
      "title": "Flowise - Session Invalidation Failure After Password Change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71335"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-22879",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.2495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vtk",
      "product": "vtk",
      "cwe": "CWE-129",
      "title": "vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22879"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-57436",
      "cvss_base": 1.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00321,
      "epss_percentile": 0.2502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sparklemotion",
      "product": "nokogiri",
      "cwe": "CWE-416",
      "title": "Nokogiri: Possible Use-After-Free when setting `Document#root=` to an invalid node type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57436"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-57437",
      "cvss_base": 1.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00321,
      "epss_percentile": 0.2502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sparklemotion",
      "product": "nokogiri",
      "cwe": "CWE-416",
      "title": "Nokogiri: Possible Use-After-Free when directly using `NokogirI::XML::XPathContext` beyond document lifetime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57437"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-12245",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "NSD",
      "cwe": "CWE-416",
      "title": "Denial of DNS over TLS service by any DoT client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12245"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-40012",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.24696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "Recursor",
      "cwe": "CWE-524",
      "title": "Information about ECS zero scoped answers might leak to clients that use a specific ECS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40012"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-53175",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "inet: frags: fix use-after-free caused by the fqdir_pre_exit() flush",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53175"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-56123",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00308,
      "epss_percentile": 0.23502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "socat",
      "product": "socat",
      "cwe": "CWE-122",
      "title": "socat 1.8.0.0 - 1.8.1.1 Heap Buffer Overflow via SOCKS5 Reply Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56123"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-9153",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "InsightConnect Sed Plugin",
      "cwe": "CWE-22",
      "title": "Arbitrary File Read in Rapid7 InsightConnect Sed Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9153"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-6432",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silicon Labs",
      "product": "SiSDK",
      "cwe": "CWE-130",
      "title": "Improper bounds validation in EmberZNet SDK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6432"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-57535",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00308,
      "epss_percentile": 0.23478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "pretix",
      "cwe": "CWE-80",
      "title": "Content injected to PDF rendering contexts could, in many places, include HTML content including <img> tags. If the src attribute of these images pointed to an URL, the PDF rendering engine would download the image from that place and display it, thereby leaking information about the rendering server and possibly creating an SSRF vector in the local network.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57535"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-12937",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.2312,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themefic",
      "product": "Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin",
      "cwe": "CWE-89",
      "title": "Tourfic <= 2.22.7 - Unauthenticated SQL Injection via 'post_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12937"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2025-71340",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-502",
      "title": "picklescan - Remote Code Execution via idlelib.pyshell.ModifiedInterpreter.runcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71340"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-12246",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "NSD",
      "cwe": "CWE-20",
      "title": "Out of bounds stack write with crafted APL RR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12246"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-57429",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.22566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eLightUp",
      "product": "Slim SEO",
      "cwe": "CWE-862",
      "title": "WordPress Slim SEO plugin <= 4.6.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57429"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-54024",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00298,
      "epss_percentile": 0.22502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danny-avila",
      "product": "LibreChat",
      "cwe": "CWE-770",
      "title": "LibreChat: Incomplete Fix for CVE-2024-11171 — Conversation Import Multer Instance Missing File Size Limits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54024"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-40211",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00296,
      "epss_percentile": 0.22264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "DNSdist",
      "cwe": "CWE-770",
      "title": "Denial of service via crafted DoH3 queries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40211"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-48944",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getk2.org",
      "product": "K2 extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - getk2.org - Exposure of sensitive files via attachment copy in K2 extension for Joomla < 2.26",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48944"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-6094",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-125",
      "title": "Heap buffer overread in wc_PKCS7_DecodeEnvelopedData parsing crafted PKCS7 EnvelopedData",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6094"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-54841",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.2198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Appsbd",
      "product": "Vitepos",
      "cwe": "CWE-201",
      "title": "WordPress Vitepos plugin <= 3.4.2 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54841"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-41566",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00293,
      "epss_percentile": 0.21941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Kvrocks",
      "cwe": "CWE-280",
      "title": "Apache Kvrocks: Improper permission for the APPLYBATCH command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41566"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-55092",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aquasecurity",
      "product": "trivy",
      "cwe": "CWE-22",
      "title": "Trivy: Path traversal via a crafted vulnerability database or other downloaded artifacts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55092"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-40209",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "DNSdist",
      "cwe": "CWE-772",
      "title": "Denial of service via IXFR queries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40209"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-9099",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-639",
      "title": "Keycloak: group-admin escalation to realm-admin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9099"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-54573",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "outline",
      "product": "outline",
      "cwe": "CWE-863",
      "title": "Authorization Bypass in API Key/OAuth Scopes via Path Parsing Discrepancy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54573"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-54479",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EVoke",
      "product": "EVoke CSMS",
      "cwe": "CWE-613",
      "title": "EVoke Systems EVoke CSMS Insufficient Session Expiration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54479"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-9154",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.20016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "InsightConnect Sed Plugin",
      "cwe": "CWE-22",
      "title": "Arbitrary File Write in Rapid7 InsightConnect Sed Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9154"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-2238",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-862",
      "title": "Missing Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2238"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-54845",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PluginUs.Net",
      "product": "MDTF",
      "cwe": "CWE-98",
      "title": "WordPress MDTF plugin <= 1.3.8 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54845"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-12077",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wedevs",
      "product": "Dokan Pro",
      "cwe": "CWE-89",
      "title": "Dokan Pro <= 5.0.4 - Unauthenticated SQL Injection via 'latitude' and 'longitude' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12077"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-27366",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MainWP",
      "product": "MainWP Child",
      "cwe": "CWE-862",
      "title": "WordPress MainWP Child plugin <= 6.1.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27366"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-44622",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EVoke",
      "product": "EVoke CSMS",
      "cwe": "CWE-522",
      "title": "EVoke Systems EVoke CSMS Insufficiently Protected Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44622"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-54822",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SALESmanago",
      "product": "SALESmanago & Leadoo",
      "cwe": "CWE-89",
      "title": "WordPress SALESmanago & Leadoo plugin <= 3.11.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54822"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-54838",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rymera Web Co",
      "product": "WC Vendors Marketplace",
      "cwe": "CWE-89",
      "title": "WordPress WC Vendors Marketplace plugin <= 2.6.8 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54838"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-53147",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "thunderbolt: Validate XDomain request packet size before type cast",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53147"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-53254",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "Bluetooth: RFCOMM: validate skb length in MCC handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53254"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-9705",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00267,
      "epss_percentile": 0.1899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-613",
      "title": "Keycloak: keycloak: attacker can re-enable and take over disabled clients via registration access token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9705"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-56774",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kanboard",
      "product": "kanboard",
      "cwe": "CWE-639",
      "title": "Kanboard - Cross-User Deletion of Persistent Login Sessions via Unvalidated Session ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56774"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-55698",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.18522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pnpm",
      "product": "pnpm",
      "cwe": "CWE-345",
      "title": "pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55698"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-54448",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.18505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aquasecurity",
      "product": "trivy",
      "cwe": "CWE-770",
      "title": "Trivy: Helm chart tar bomb causes OOM via unbounded io.ReadAll in parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54448"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-54821",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.18393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bootstrapped Ventures",
      "product": "Visual Link Preview",
      "cwe": "CWE-201",
      "title": "WordPress Visual Link Preview plugin <= 2.3.1 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54821"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-9716",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Schneider Electric",
      "product": "PowerLogic™ P7",
      "cwe": "CWE-476",
      "title": "CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable when malformed requests are received over exposed network interfaces.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9716"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-50014",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pnpm",
      "product": "pnpm",
      "cwe": "CWE-88",
      "title": "pnpm: Git Fetch Argument Injection via Lockfile resolution.commit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50014"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-10512",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.18288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-682",
      "title": "X25519 x86_64 assembly final reduction leaves non-canonical field element",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10512"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-37454",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the 3DES-ECB encryption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37454"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-57619",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.1813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elementor",
      "product": "Elementor Website Builder",
      "cwe": "CWE-862",
      "title": "WordPress Elementor Website Builder plugin <= 4.1.3 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57619"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-53196",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "USB: serial: io_ti: fix heap overflow in get_manuf_info()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53196"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-40210",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "DNSdist",
      "cwe": "CWE-126",
      "title": "Out-of-bounds read in SetMacAddrAction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40210"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-57522",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00261,
      "epss_percentile": 0.18086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bitwarden",
      "product": "server",
      "cwe": "CWE-74",
      "title": "Bitwarden Server < 2026.5.0 JSON Injection via Webhook Templates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57522"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-53253",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "Bluetooth: bnep: reject short frames before parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53253"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-56005",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Melapress",
      "product": "WP Activity Log",
      "cwe": "CWE-79",
      "title": "WordPress WP Activity Log plugin <= 5.6.3.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56005"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-13222",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "pretix-oppwa",
      "cwe": "CWE-841",
      "title": "Insufficient validation of payment status in pretix-oppwa",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13222"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-13223",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "pretix-computop",
      "cwe": "CWE-841",
      "title": "Insufficient validation of payment status in pretix-computop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13223"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-57536",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "pretix-mollie",
      "cwe": "CWE-841",
      "title": "Insufficient validation of payment status in pretix-mollie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57536"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-6681",
      "cvss_base": 1,
      "cvss_severity": "LOW",
      "epss_score": 0.00257,
      "epss_percentile": 0.17504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-120",
      "title": "PKCS#7 decode ignores caller output buffer size, writing past buffer bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6681"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-55413",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00256,
      "epss_percentile": 0.17364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ToolJet",
      "product": "ToolJet",
      "cwe": "CWE-94",
      "title": "ToolJet - Marketplace Plugin Poisoning Enables Instance-Wide Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55413"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-10833",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17433,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevteam",
      "product": "Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns",
      "cwe": "CWE-79",
      "title": "Gutenberg Essential Blocks - Page Builder for Gutenberg Blocks & Patterns <= 6.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'configurablePrefix' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10833"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-53232",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.1711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: phy: clean the sfp upstream if phy probing fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53232"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-57521",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bitwarden",
      "product": "server",
      "cwe": "CWE-862",
      "title": "Bitwarden Server < 2026.5.0 Broken Access Control via PreviewInvoiceController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57521"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-54036",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danny-avila",
      "product": "LibreChat",
      "cwe": "CWE-306",
      "title": "LibreChat: 2FA Re-enrollment Allows Full Account 2FA Takeover Without OTP Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54036"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-4526",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silicon Labs",
      "product": "EmberZNet",
      "cwe": "CWE-125",
      "title": "Global ZCL command parser missing minimum-length validation in EmberZNet v9.0.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4526"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-47145",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silicon Labs",
      "product": "EmberZNet",
      "cwe": "CWE-617",
      "title": "Color Control hue/saturation assertion abort in EmberZNet v9.0.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47145"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-47146",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silicon Labs",
      "product": "EmberZNet",
      "cwe": "CWE-617",
      "title": "Color Control color-temperature assertion abort in EmberZNet v9.0.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47146"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-47148",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silicon Labs",
      "product": "EmberZNet",
      "cwe": "CWE-125",
      "title": "Groups GetGroupMembership count/list-length mismatch in EmberZNet v9.0.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47148"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-47149",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silicon Labs",
      "product": "EmberZNet",
      "cwe": "CWE-125",
      "title": "Door Lock GetUserType invalid table index in EmberZNet v9.0.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47149"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-47152",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silicon Labs",
      "product": "EmberZNet",
      "cwe": "CWE-369",
      "title": "Level Control Move divide-by-zero in EmberZNet v9.0.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47152"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-47153",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silicon Labs",
      "product": "EmberZNet",
      "cwe": "CWE-369",
      "title": "Level Control Step With On/Off divide-by-zero in EmberZNet v9.0.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47153"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-47154",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silicon Labs",
      "product": "EmberZNet",
      "cwe": "CWE-125",
      "title": "Simple Metering GetProfileResponse interval-bounds bug in EmberZNet v9.0.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47154"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-56789",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tomojitakasu",
      "product": "RTKLIB",
      "cwe": "CWE-122",
      "title": "RTKLIB 2.4.3 - Heap Buffer Overflow and Stack Read via Oversized RINEX Epoch Satellite Count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56789"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-53256",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53256"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-57533",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00248,
      "epss_percentile": 0.16437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "pretix",
      "cwe": "CWE-80",
      "title": "Malicious HTML content could be injected into the page pretix shows when redirection to an untrusted page occurs. Since this page has a Content-Security-Policy, this can mainly be used for phishing purposes.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57533"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-54033",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danny-avila",
      "product": "LibreChat",
      "cwe": "CWE-918",
      "title": "LibreChat: SSRF via User-Provided Custom Endpoint baseURL — no private IP validation on user-configured API base URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54033"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-9718",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Schneider Electric",
      "product": "PowerLogic™ P7",
      "cwe": "CWE-617",
      "title": "CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a specially crafted request is sent to a vulnerable network-exposed service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9718"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-12993",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apicurio Registry 3",
      "cwe": "CWE-776",
      "title": "Apicurio/apicurio-registry: apicurio-registry: xml entity-expansion denial of service via internal dtd subset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12993"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-9222",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00242,
      "epss_percentile": 0.15674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shenzhen i365-Tech Co. Ltd.",
      "product": "Setracker2 Parental Control App (Android) package com.tgelec.setracker",
      "cwe": "CWE-836",
      "title": "Setracker2 Children's Smartwatch Ecosystem Use of password hash instead of password for authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9222"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-53146",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "thunderbolt: Limit XDomain response copy to actual frame size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53146"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-9650",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Schneider Electric",
      "product": "EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller",
      "cwe": "CWE-522",
      "title": "CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device if they have physical access to the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9650"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-49319",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.1537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Alps Electric Co., Ltd.",
      "product": "Remote Keyless Entry System (RKES) R53R0",
      "cwe": "CWE-294",
      "title": "Alps Electric Co., Ltd. R53R0 Remote Keyless Entry System (RKES) Replay Attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49319"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-54828",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StylemixThemes",
      "product": "Motors",
      "cwe": "CWE-862",
      "title": "WordPress Motors plugin <= 1.4.109 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54828"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-54830",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Etoile Web Design Incorporated",
      "product": "Five Star Restaurant Reservations",
      "cwe": "CWE-862",
      "title": "WordPress Five Star Restaurant Reservations plugin <= 2.7.19 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54830"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-54844",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CheckView",
      "product": "CheckView Automated Testing",
      "cwe": "CWE-862",
      "title": "WordPress CheckView Automated Testing plugin <= 2.1.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54844"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-56013",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "myCred",
      "product": "License Manager for WooCommerce",
      "cwe": "CWE-639",
      "title": "WordPress License Manager for WooCommerce plugin <= 3.0.15 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56013"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-2508",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GravityMore",
      "product": "Gravity Bookings",
      "cwe": "CWE-89",
      "title": "Gravity Forms Booking <= 2.7.1 - Authenticated (Subscriber+) Time-Based SQL Injection via 'staff_id'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2508"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-12975",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00233,
      "epss_percentile": 0.14507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apicurio Registry 3",
      "cwe": "CWE-611",
      "title": "Apicurio/apicurio-registry: apicurio-registry: unhardened saxparser in content-type detection leads to blind xxe / ssrf / billion-laughs dos",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12975"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-53275",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "ipv6: mcast: Fix use-after-free when processing MLD queries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53275"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-9220",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shenzhen i365-Tech Co. Ltd.",
      "product": "Setracker2 Parental Control App (Android) package com.tgelec.setracker",
      "cwe": "CWE-321",
      "title": "Setracker2 Children's Smartwatch Ecosystem Use of hard-coded cryptographic key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9220"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-12473",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open Health Imaging Foundation (OHIF)",
      "product": "DICOM Web Viewer Framework",
      "cwe": "CWE-918",
      "title": "OHIF Viewers DICOM Server-Side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12473"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-46608",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nicolargo",
      "product": "glances",
      "cwe": "CWE-183",
      "title": "Glances: XML-RPC Multi-Origin CORS Configuration Silently Falls Back to Wildcard (Incomplete Fix for CVE-2026-33533)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46608"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-47147",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silicon Labs",
      "product": "EmberZNet",
      "cwe": "CWE-125",
      "title": "OTA server raw parser missing per-field bounds validation in EmberZNet v9.0.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47147"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-56014",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Averta",
      "product": "Master Slider",
      "cwe": "CWE-79",
      "title": "WordPress Master Slider plugin <= 3.11.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56014"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-56042",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Algolplus",
      "product": "Advanced Order Export For WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Advanced Order Export For WooCommerce plugin <= 4.0.9 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56042"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-56051",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TablePress",
      "product": "TablePress",
      "cwe": "CWE-79",
      "title": "WordPress TablePress plugin <= 3.3.1 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56051"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-56071",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPMU DEV",
      "product": "Forminator",
      "cwe": "CWE-79",
      "title": "WordPress Forminator plugin <= 1.53.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56071"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-54843",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00229,
      "epss_percentile": 0.14016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PluginUs.Net",
      "product": "MDTF",
      "cwe": "CWE-89",
      "title": "WordPress MDTF plugin <= 1.3.7 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54843"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-54849",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00229,
      "epss_percentile": 0.14016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Premmerce",
      "product": "Premmerce Wishlist for WooCommerce",
      "cwe": "CWE-89",
      "title": "WordPress Premmerce Wishlist for WooCommerce plugin <= 1.1.11 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54849"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-13283",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.13959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13283"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-40082",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cacti",
      "product": "cacti",
      "cwe": "CWE-384",
      "title": "Cacti: Session Fixation via missing session_regenerate_id() after login",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40082"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-12340",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-125",
      "title": "Out-of-bounds heap read in SM2/SM3 certificate Subject Key Identifier computation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12340"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-56130",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00225,
      "epss_percentile": 0.13388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Shiro",
      "cwe": "CWE-294",
      "title": "Apache Shiro: Remember-me cookie isn't checked for expiry on the server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56130"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-1606",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-94",
      "title": "Improper Control of Generation of Code ('Code Injection') in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1606"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-11310",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.12759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-295",
      "title": "X.509 trust-chain bypass in wolfSSL_X509_verify_cert() via untrusted intermediate anchoring",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11310"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-11999",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.12759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-295",
      "title": "X.509 trust-chain bypass via path-depth exhaustion in wolfSSL_X509_verify_cert()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11999"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-55960",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.12759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-295",
      "title": "Un-negotiated Raw Public Key (RFC 7250) accepted in place of X.509, bypassing chain validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55960"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-47150",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00217,
      "epss_percentile": 0.12417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silicon Labs",
      "product": "EmberZNet",
      "cwe": "CWE-787",
      "title": "IAS Zone enroll invalid table index and write in EmberZNet 9.0.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47150"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-47151",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00217,
      "epss_percentile": 0.12416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silicon Labs",
      "product": "EmberZNet",
      "cwe": "CWE-787",
      "title": "Door Lock ClearWeekdaySchedule invalid table index and write in EmberZNet v9.0.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47151"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-12079",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wedevs",
      "product": "Dokan Pro",
      "cwe": "CWE-89",
      "title": "Dokan Pro <= 5.0.4 - Authenticated (Subscriber+) SQL Injection via 'orderby' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12079"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-54027",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danny-avila",
      "product": "LibreChat",
      "cwe": "CWE-862",
      "title": "LibreChat: Image Upload Route Bypasses Agent Permission Check — Incomplete Fix for File Upload Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54027"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-56769",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hcengineering",
      "product": "platform",
      "cwe": "CWE-918",
      "title": "Huly Platform - Server-Side Request Forgery via /import Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56769"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-8662",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "InsightConnect Compression Plugin",
      "cwe": "CWE-22",
      "title": "Path Traversal in Rapid7 InsightConnect Compression Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8662"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-12755",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00216,
      "epss_percentile": 0.12263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-1284",
      "title": "Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows an authenticated user with the UserGroupsView permission to coerce server-side authentication to an attacker-controlled host, exposing PAM provider credentials as a NTLMv2 challenge-response, via a crafted DomainName parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12755"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-37149",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerability in the scost parameter in /grocery/search_products.php. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37149"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-56790",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "canboat",
      "product": "canboat",
      "cwe": "CWE-193",
      "title": "CANBoat - Off-by-One Global Buffer Overflow in searchForPgn()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56790"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-11703",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-287",
      "title": "Missing SNI/ALPN binding on stateful (session-ID) TLS session resumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11703"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-6092",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.1136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-757",
      "title": "Encrypt-then-MAC could fall back to MAC-then-Encrypt when HAVE_ENCRYPT_THEN_MAC is configured",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6092"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-9702",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00208,
      "epss_percentile": 0.11291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "InPost PL",
      "cwe": null,
      "title": "InPost PL < 1.9.1 - Unauthenticated WooCommerce Order Parcel-Locker Hijacking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9702"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-53178",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-191",
      "title": "staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53178"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-53264",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "net/sched: act_api: use RCU with deferred freeing for action lifecycle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53264"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-42390",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "Recursor",
      "cwe": "CWE-20",
      "title": "ZONEMD validation can be bypassed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42390"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-40208",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00205,
      "epss_percentile": 0.10788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "DNSdist",
      "cwe": "CWE-705",
      "title": "Denial of service via DoH3 queries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40208"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-56771",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "samuelclay",
      "product": "NewsBlur",
      "cwe": "CWE-918",
      "title": "NewsBlur < 14.5.0 - Server-Side Request Forgery via add_url Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56771"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-56772",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "samuelclay",
      "product": "NewsBlur",
      "cwe": "CWE-639",
      "title": "NewsBlur < 14.5.0 - Insecure Direct Object Reference in Social Interactions Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56772"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-9219",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shenzhen i365-Tech Co. Ltd.",
      "product": "Setracker2 Parental Control App (Android) package com.tgelec.setracker",
      "cwe": "CWE-340",
      "title": "Setracker2 Children's Smartwatch Ecosystem Generation of Predictable Numbers or Identifiers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9219"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-56023",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Knit Pay",
      "product": "UPI QR Code Payment Gateway for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress UPI QR Code Payment Gateway for WooCommerce plugin <= 1.6.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56023"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-0934",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00201,
      "epss_percentile": 0.10319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0934"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-48945",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getk2.org",
      "product": "K2 extension for Joomla",
      "cwe": "CWE-434",
      "title": "Joomla Extension - getk2.org - Privileged RCE vulnerability in K2 extension for Joomla < 2.26",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48945"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-5952",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5952"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-54842",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00195,
      "epss_percentile": 0.09566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Royal Plugins",
      "product": "Royal MCP",
      "cwe": "CWE-862",
      "title": "WordPress Royal MCP plugin <= 1.4.25 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54842"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-54829",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00195,
      "epss_percentile": 0.09551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jacob N. Breetvelt",
      "product": "WP Photo Album Plus",
      "cwe": "CWE-89",
      "title": "WordPress WP Photo Album Plus plugin <= 9.1.13.005 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54829"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-55412",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00193,
      "epss_percentile": 0.09293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ToolJet",
      "product": "ToolJet",
      "cwe": "CWE-918",
      "title": "ToolJet Cloud - SSRF to Azure Cloud Infrastructure Compromise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55412"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-54093",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-22",
      "title": "File Browser: Path traversal in download-as-zip/tar via Windows-style backslash separators in stored filenames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54093"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-5796",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5796"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-40080",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cacti",
      "product": "cacti",
      "cwe": "CWE-601",
      "title": "Cacti: Open Redirect via HTTP_REFERER substring check in auth_login_redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40080"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-28898",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "swift-nio-http2",
      "cwe": "CWE-116",
      "title": "swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them into the translated HTTP/1.1 message. swift-nio-http2 1.44.1 adds validation of all pseudo-header values (:path, :authority, :scheme, :method, and :status) at both the HPACK header validation layer and the HTTP/2-to-HTTP/1.1 translation layer. Requests or responses containing CR, LF, or NUL bytes in any pseudo-header value are now rejected with a connection error. This issue is fixed in swift-nio-http2 1.44.1.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28898"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-56050",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeisle",
      "product": "PPOM for WooCommerce",
      "cwe": "CWE-284",
      "title": "WordPress PPOM for WooCommerce plugin <= 33.0.18 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56050"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-6678",
      "cvss_base": 1,
      "cvss_severity": "LOW",
      "epss_score": 0.0019,
      "epss_percentile": 0.09004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-191",
      "title": "Integer underflow in wc_PKCS7_DecryptOri handling crafted Other Recipient Info",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6678"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-11379",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11379"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-12992",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00187,
      "epss_percentile": 0.08651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Apicurio Registry 3",
      "cwe": "CWE-918",
      "title": "Apicurio/apicurio-registry: apicurio-registry: ssrf via wsdl4j import dereference in wsdl full validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12992"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2025-60464",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-416",
      "title": "A use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 TS file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60464"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-54848",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.08119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saad Iqbal",
      "product": "APIExperts Square for WooCommerce",
      "cwe": "CWE-201",
      "title": "WordPress APIExperts Square for WooCommerce plugin <= 4.7.3 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54848"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-48943",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getk2.org",
      "product": "K2 extension for Joomla",
      "cwe": "CWE-915",
      "title": "Joomla Extension - getk2.org - Authenticated user property mass-assignment in K2 extension for Joomla < 2.26",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48943"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-54029",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danny-avila",
      "product": "LibreChat",
      "cwe": "CWE-862",
      "title": "LibreChat: IDOR in Message Deletion — Incomplete Fix for CVE-2024-41703 Leaves deleteMessages() Without User Filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54029"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-3176",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00182,
      "epss_percentile": 0.08119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-862",
      "title": "Missing Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3176"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-11800",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.0797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.6",
      "cwe": "CWE-347",
      "title": "Org.keycloak:keycloak-services: keycloak: authentication bypass via jwt algorithm confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11800"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-6450",
      "cvss_base": 1,
      "cvss_severity": "LOW",
      "epss_score": 0.0018,
      "epss_percentile": 0.07829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-295",
      "title": "CRL critical extension bypass in ParseCRL_Extensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6450"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-13281",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00177,
      "epss_percentile": 0.07582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13281"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-54040",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00177,
      "epss_percentile": 0.07589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danny-avila",
      "product": "LibreChat",
      "cwe": "CWE-306",
      "title": "LibreChat: 2FA Backup Code Regeneration Without OTP Verification Allows 2FA Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54040"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-13083",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Pen Drive Powered by Red Hat Lightspeed",
      "cwe": "CWE-79",
      "title": "Pen-drive: pen-drive: stored xss via unescaped cluster data in html report",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13083"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-54096",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-863",
      "title": "File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54096"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-56006",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "H5P",
      "product": "H5P",
      "cwe": "CWE-79",
      "title": "WordPress H5P plugin <= 1.17.6 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56006"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-42389",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "Recursor",
      "cwe": "CWE-20",
      "title": "Reject more queries with invalid header values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42389"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-6325",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00175,
      "epss_percentile": 0.07346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in SetSuitesHashSigAlgo on oversized signature algorithms list",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6325"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-55697",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.07169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pnpm",
      "product": "pnpm",
      "cwe": "CWE-78",
      "title": "pnpm: Repository-controlled configDependencies can select a pacquet native install engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55697"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-50021",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.07132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pnpm",
      "product": "pnpm",
      "cwe": "CWE-354",
      "title": "pnpm: Integrity Check Bypass via Missing Lockfile Integrity Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50021"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-5309",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-639",
      "title": "Authorization Bypass Through User-Controlled Key in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5309"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2025-60465",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-416",
      "title": "A use-after-free in the gf_filter_pid_inst_swap function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60465"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-7511",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-347",
      "title": "PKCS7_verify signer confusion allows forged signatures to be accepted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7511"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-56779",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-918",
      "title": "MaxKB < 2.10.0 - Server-Side Request Forgery via downloadCallbackUrl and download_url Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56779"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-13350",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0017,
      "epss_percentile": 0.06769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "Venueless",
      "cwe": "CWE-639",
      "title": "Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't be allowed to create.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13350"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-48946",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getk2.org",
      "product": "K2 extension for Joomla",
      "cwe": "CWE-434",
      "title": "Joomla Extension - getk2.org - Privileged RCE vulnerability in K2 extension for Joomla < 2.26",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48946"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2020-37256",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grav",
      "product": "Grav",
      "cwe": "CWE-79",
      "title": "Grav - Cross-Site Scripting in Admin Plugin Page Editor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2020-37256"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-48940",
      "cvss_base": 3.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00167,
      "epss_percentile": 0.06453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getk2.org",
      "product": "K2 extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - getk2.org - Stored-XSS in K2 extension for Joomla < 2.26",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48940"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-9799",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-639",
      "title": "Keycloak: keycloak: unauthorized access to resources via uma permission ticket bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9799"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-57234",
      "cvss_base": 2.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00166,
      "epss_percentile": 0.06369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sparklemotion",
      "product": "nokogiri",
      "cwe": "CWE-178",
      "title": "Nokogiri: XML::Schema on JRuby allows network requests when NONET is set, bypassing CVE-2020-26247",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57234"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-10824",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Masteriyo LMS",
      "cwe": null,
      "title": "Masteriyo LMS < 2.2.1 - Unauthenticated Course Progress Disclosure and Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10824"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-55487",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pnpm",
      "product": "pnpm",
      "cwe": "CWE-346",
      "title": "pnpm: manifest identity spoof satisfies allowBuilds and runs attacker lifecycle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55487"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-13282",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13282"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-54025",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danny-avila",
      "product": "LibreChat",
      "cwe": "CWE-79",
      "title": "LibreChat: Stored XSS via unescaped image alt text in markdown artifact preview",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54025"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-9221",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00161,
      "epss_percentile": 0.05748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shenzhen i365-Tech Co. Ltd.",
      "product": "Setracker2 Parental Control App (Android) package com.tgelec.setracker",
      "cwe": "CWE-327",
      "title": "Setracker2 Children's Smartwatch Ecosystem Use of a Broken or Risky Cryptographic Algorithm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9221"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-10097",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00161,
      "epss_percentile": 0.05753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-697",
      "title": "ML-KEM-1024 x64 AVX2 incomplete cipher text comparison enables IND-CCA2 break and static private-key recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10097"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-48995",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pnpm",
      "product": "pnpm",
      "cwe": "CWE-353",
      "title": "pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48995"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-12635",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00161,
      "epss_percentile": 0.05853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-350",
      "title": "Reliance on Reverse DNS Resolution for a Security-Critical Action in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12635"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-6329",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-347",
      "title": "PKCS#12 MAC verification uses attacker-controlled comparison length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6329"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-2815",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silicon Labs",
      "product": "SiSDK",
      "cwe": "CWE-339",
      "title": "Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2815"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-40941",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cacti",
      "product": "cacti",
      "cwe": "CWE-347",
      "title": "Cacti: Package Import Signature Validation Bypass Allows Self-Signed Packages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40941"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-48941",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getk2.org",
      "product": "K2 extension for Joomla",
      "cwe": "CWE-862",
      "title": "Joomla Extension - getk2.org - Unauthenticated folder delete in K2 extension for Joomla < 2.26",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48941"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-12490",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.05305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "NSD",
      "cwe": "CWE-284",
      "title": "Bypass of client certificate verification with transfer over TLS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12490"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-42004",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00156,
      "epss_percentile": 0.05265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "DNSdist",
      "cwe": "CWE-115",
      "title": "EDNS options smuggling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42004"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-50573",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.05158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pnpm",
      "product": "pnpm",
      "cwe": "CWE-345",
      "title": "pnpm: Unsafe default behavior breaks integrity check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50573"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-7532",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-295",
      "title": "iPAddress name constraints not enforced when WOLFSSL_IP_ALT_NAME is undefined",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7532"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-45188",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00155,
      "epss_percentile": 0.05205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Kvrocks",
      "cwe": "CWE-23",
      "title": "Apache Kvrocks: Replication Fullsync Path Traversal via Unvalidated Filename Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45188"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-40011",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00153,
      "epss_percentile": 0.04955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "DNSdist",
      "cwe": "CWE-116",
      "title": "Prometheus denial of service via crafted DNS queries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40011"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-6291",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.0493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-208",
      "title": "Bleichenbacher padding oracle in PKCS#7 KTRI RSA PKCS#1 v1.5 decryption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6291"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-55895",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.0493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-78",
      "title": "Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55895"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-53212",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "netfilter: nft_tunnel: fix use-after-free on object destroy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53212"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-53202",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-674",
      "title": "accel/ivpu: Fix signed integer truncation in IPC receive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53202"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-13318",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Virtualization 4",
      "cwe": "CWE-918",
      "title": "Virt-api-rhel9: kubevirt: kubevirt: ssrf in virt-api port-forward via unvalidated guest-agent-reported ip",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13318"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-48942",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getk2.org",
      "product": "K2 extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - getk2.org - Stored-XSS in K2 extension for Joomla < 2.26",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48942"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-53194",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "USB: serial: kl5kusb105: fix bulk-out buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53194"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-49839",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.0458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jqlang",
      "product": "jq",
      "cwe": "CWE-787",
      "title": "jq --rawfile invalid-state reuse after String too long causes heap-buffer-overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49839"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-6331",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00148,
      "epss_percentile": 0.04506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-347",
      "title": "HMAC zero-length tag forgery in EVP_DigestVerifyFinal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6331"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-47770",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jqlang",
      "product": "jq",
      "cwe": "CWE-674",
      "title": "jq: stack overflow in deep structural equality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47770"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-55961",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-347",
      "title": "wolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 with no signer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55961"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-57456",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-94",
      "title": "Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57456"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-56788",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tomojitakasu",
      "product": "RTKLIB",
      "cwe": "CWE-125",
      "title": "RTKLIB 2.4.3 - Out-of-bounds Read via Negative Array Index in getcodepri",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56788"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-53137",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00143,
      "epss_percentile": 0.04152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53137"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-53143",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00143,
      "epss_percentile": 0.04061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53143"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-53195",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00143,
      "epss_percentile": 0.04059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53195"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-53203",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00143,
      "epss_percentile": 0.0406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "accel/ivpu: Add buffer overflow check in MS get_info_ioctl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53203"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-55962",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-287",
      "title": "TLS 1.3 post-handshake authentication: server accepts Finished without client Certificate/CertificateVerify",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55962"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-46606",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.04041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nicolargo",
      "product": "glances",
      "cwe": "CWE-78",
      "title": "Glances: Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46606"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-53193",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00141,
      "epss_percentile": 0.03922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "ALSA: timer: Forcibly close timer instances at closing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53193"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-57453",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.03871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-77",
      "title": "Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57453"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-53132",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "vsock/virtio: fix potential unbounded skb queue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53132"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-53925",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.03589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nicolargo",
      "product": "glances",
      "cwe": "CWE-22",
      "title": "Glances: Arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53925"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-53148",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "thunderbolt: Clamp XDomain response data copy to allocation size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53148"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-6330",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-327",
      "title": "ML-KEM ARM64 NEON ciphertext comparison only compares half of the input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6330"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-12897",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Horner Automation",
      "product": "Cscape",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in Horner Automation Cscape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12897"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-53234",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.0317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "net: ibm: emac: Fix use-after-free during device removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53234"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-53227",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "net: openvswitch: fix possible kfree_skb of ERR_PTR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53227"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-53252",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "Bluetooth: fix memory leak in error path of hci_alloc_dev()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53252"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-8330",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.0307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-532",
      "title": "Insertion of Sensitive Information into Log File in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8330"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-54030",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00129,
      "epss_percentile": 0.03039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danny-avila",
      "product": "LibreChat",
      "cwe": "CWE-346",
      "title": "LibreChat: Missing Resource Parameter Validation in MCP OAuth Flow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54030"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-46607",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nicolargo",
      "product": "glances",
      "cwe": "CWE-502",
      "title": "Glances: Insecure Pickle Deserialization in Version Cache Leads to Arbitrary Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46607"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-53133",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-681",
      "title": "RDMA/umem: Fix truncation for block sizes >= 4G",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53133"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-53136",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "drm/amd/display: Clamp VBIOS HDMI retimer register count to array size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53136"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-53182",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: nl80211: reject oversized EMA RNR lists",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53182"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-53189",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.0302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/huge_memory: update file PMD counter before folio_put()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53189"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-53191",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "io_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53191"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-53209",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53209"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-53233",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-415",
      "title": "netdev: fix double-free in netdev_nl_bind_rx_doit()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53233"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-53242",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53242"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-53159",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.03024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "misc: fastrpc: fix DMA address corruption due to find_vma misuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53159"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-53170",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "accel/ethosu: reject DMA commands with uninitialized length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53170"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-53171",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel/ethosu: fix arithmetic issues in dma_length()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53171"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-12921",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AzeoTech",
      "product": "DAQFactory",
      "cwe": "CWE-416",
      "title": "Use after free in AzeoTech DAQFactory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12921"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-53201",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Revert \"drm/xe: Skip exec queue schedule toggle if queue is idle during suspend\"",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53201"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-53188",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "RDMA/core: Validate the passed in fops for ib_get_ucaps()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53188"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-53162",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.0281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "memcg: use round-robin victim selection in refill_stock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53162"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-53157",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "net: phonet: free phonet_device after RCU grace period",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53157"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-53160",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "misc: fastrpc: fix use-after-free race in fastrpc_map_create",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53160"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-53161",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53161"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-53239",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "xfrm: policy: fix use-after-free on inexact bin in xfrm_policy_bysel_ctx()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53239"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-53138",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "drm/amd/display: Bound VBIOS record-chain walk loops",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53138"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-53149",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "thunderbolt: Bound root directory content to block size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53149"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-53223",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: guard timestamp cmsgs to real error queue skbs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53223"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-55411",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ToolJet",
      "product": "ToolJet",
      "cwe": "CWE-639",
      "title": "ToolJet: Cross-tenant credential decryption (IDOR) in POST /api/data-sources/decrypt — any authenticated user can decrypt any organization's data-source secrets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55411"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-53230",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "net/mlx5: Fix slab-out-of-bounds in mlx5_query_nic_vport_mac_list",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53230"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-53156",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.0263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "nvmem: core: fix use-after-free bugs in error paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53156"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-53192",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "ALSA: timer: Fix UAF at snd_timer_user_params()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53192"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-53179",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "staging: rtl8723bs: fix buffer over-read in rtw_update_protection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53179"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-53205",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "accel/ivpu: Add bounds checks for firmware log indices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53205"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-53167",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53167"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-53187",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.0254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "RDMA/core: Validate cpu_id against nr_cpu_ids in DMAH alloc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53187"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-10592",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-295",
      "title": "Wildcard DNS SAN bypasses CA name-constraint checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10592"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-6731",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-295",
      "title": "X.509 name constraint bypass via Subject CN treated as a DNS name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6731"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-55693",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-787",
      "title": "Vim: Out-of-bounds Write in Spell File Word Count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55693"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-4522",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HYPR",
      "product": "Passwordless",
      "cwe": "CWE-306",
      "title": "Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Interception. This issue affects HYPR Passwordless: before 11.1.1.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4522"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-53134",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "netfilter: nft_fib: fix stale stack leak via the OIFNAME register",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53134"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-53135",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53135"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-53139",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/v3d: Skip CSD when it has zeroed workgroups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53139"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-53150",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-191",
      "title": "thunderbolt: Reject zero-length property entries in validator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53150"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-53158",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "misc: fastrpc: Fix NULL pointer dereference in rpmsg callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53158"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-53163",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "locking/rtmutex: Skip remove_waiter() when waiter is not enqueued",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53163"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-53168",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fuse: reject fuse_notify() pagecache ops on directories",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53168"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-53177",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "bnxt_en: Fix NULL pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53177"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-53181",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "vsock/vmci: fix sk_ack_backlog leak on failed handshake",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53181"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-53208",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53208"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-53213",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.0245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "drm/vc4: fix krealloc() memory leak",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53213"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-53218",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.0245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "netfilter: nft_exthdr: fix register tracking for F_PRESENT flag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53218"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-53219",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: x_tables: avoid leaking percpu counter pointers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53219"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-53236",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tcp: restrict SO_ATTACH_FILTER to priv users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53236"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-53238",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netlabel: validate unlabeled address and mask attribute lengths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53238"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-53245",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53245"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-53249",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53249"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-54250",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "k3s-io",
      "product": "k3s",
      "cwe": "CWE-22",
      "title": "K3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot Decompression",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54250"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-53140",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53140"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-53142",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "drm/xe/display: fix oops in suspend/shutdown without display",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53142"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-53144",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "drm/amdkfd: fix NULL dereference in get_queue_ids()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53144"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-53152",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "mmc: dw_mmc-rockchip: Add missing private data for very old controllers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53152"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-53154",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-772",
      "title": "mm/hugetlb: restore reservation on error in hugetlb folio copy paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53154"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-53190",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53190"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-53210",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "tee: shm: fix shm leak in register_shm_helper()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53210"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-53214",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "ipv6: Fix a potential NPD in cleanup_prefix_route()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53214"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-53220",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "netfilter: revalidate bridge ports",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53220"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-53237",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.0237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "gpio: mvebu: fix NULL pointer dereference in suspend/resume",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53237"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-53241",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ALSA: seq: dummy: fix UMP event stack overread",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53241"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-53251",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-772",
      "title": "Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53251"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-53266",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: bridge: make ebt_snat ARP rewrite writable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53266"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-53270",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipvs: clear the svc scheduler ptr early on edit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53270"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-10098",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-295",
      "title": "OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10098"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-6091",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-295",
      "title": "Partial-chain verification accepts untrusted intermediate as trust anchor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6091"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-53141",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/v3d: Fix global performance monitor reference counting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53141"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-53164",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "iommu/dma: Do not try to iommu_map a 0 length region in swiotlb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53164"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-53211",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "netfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR register",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53211"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-53274",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53274"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-53200",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: arm64: nv: Fix handling of XN[0] when !FEAT_XNX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53200"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-53172",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "accel/ethosu: fix IFM region index out-of-bounds in command stream parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53172"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-53173",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "accel/ethosu: fix OOB write in ethosu_gem_cmdstream_copy_and_validate()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53173"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-53174",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ovl: keep err zero after successful ovl_cache_get()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53174"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-53265",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.0219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "dm cache policy smq: check allocation under invalidate lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53265"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-53267",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-674",
      "title": "netfilter: nft_ct: bail out on template ct in get eval",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53267"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2021-47986",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "parse-community",
      "product": "parse-server",
      "cwe": "CWE-494",
      "title": "Parse Server - Unreviewed Code Execution via Malicious Version Tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-47986"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2021-47987",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "parse-community",
      "product": "parse-server",
      "cwe": "CWE-494",
      "title": "Parse Server - Arbitrary Code Execution via Malicious Version Tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-47987"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-55892",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-787",
      "title": "Vim: Out-of-bounds Write in Spell File Prefix Dump",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55892"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-46611",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nicolargo",
      "product": "glances",
      "cwe": "CWE-346",
      "title": "Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46611"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-2299",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost Google Drive Plugin",
      "cwe": "CWE-862",
      "title": "Improper Access Control in Mattermost Google Drive Plugin File Creation Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2299"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-53262",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00119,
      "epss_percentile": 0.02077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53262"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-53226",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "gpio: rockchip: fix generic IRQ chip leak on remove",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53226"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-55964",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.02012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-295",
      "title": "Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temporary CA exemption)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55964"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-57452",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.01999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-125",
      "title": "Vim: Out-of-bounds Read with libsodium-encrypted Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57452"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-57455",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.02044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-787",
      "title": "Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length `soundfold()` argument",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57455"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-53272",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "erofs: fix use-after-free on sbi->sync_decompress",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53272"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-53273",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "tee: optee: prevent use-after-free when the client exits before the supplicant",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53273"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-53255",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "Bluetooth: MGMT: validate advertising TLV before type checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53255"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-57454",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-125",
      "title": "Vim: Out-of-bounds Read with Text Properties",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57454"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-57589",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenBSD",
      "cwe": "CWE-416",
      "title": "sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-after-free after tsleep in sys_semget().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57589"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-57451",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-125",
      "title": "Vim: Out-of-bounds Read in Text Property Count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57451"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-53259",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "ipv6: anycast: insert aca into global hash under idev->lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53259"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-33612",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "Recursor",
      "cwe": "CWE-349",
      "title": "ZoneToCache can poison the cache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33612"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-53263",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-193",
      "title": "6lowpan: fix off-by-one in multicast context address compression",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53263"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-53261",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "devlink: Release nested relation on devlink free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53261"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-53269",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.0175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: synproxy: add mutex to guard hook reference counting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53269"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-53271",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.0173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53271"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-55967",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00114,
      "epss_percentile": 0.01756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-323",
      "title": "AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enabling counter wrap and keystream reuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55967"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-56129",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dynabook Inc.",
      "product": "Generic IO & Memory Access driver",
      "cwe": "CWE-782",
      "title": "Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A logged-in user with no administrative privilege may access physical memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56129"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-53276",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "Bluetooth: ISO: Fix a use-after-free of the hci_conn pointer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53276"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-53258",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "wifi: fix leak if split 6 GHz scanning fails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53258"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-8720",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-354",
      "title": "HMAC-BLAKE2 final discards message when key length exceeds block size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8720"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-9651",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Schneider Electric",
      "product": "EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller",
      "cwe": "CWE-732",
      "title": "CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential account compromise when an attacker with privileged local access reads improperly protected system files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9651"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-53277",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.0129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-662",
      "title": "KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT emulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53277"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-53155",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.0134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/huge_memory: use correct flags for device private PMD entry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53155"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-53169",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-617",
      "title": "accel/ethosu: reject NPU_OP_RESIZE commands from userspace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53169"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-53204",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "firmware: stratix10-rsu: Fix NULL deref on rsu_send_msg() timeout in probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53204"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-53206",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "accel/ivpu: Add bounds check for firmware runtime memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53206"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-53222",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "ptp: ocp: fix resource freeing order",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53222"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-53243",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "rseq: Fix using an uninitialized stack variable in rseq_exit_user_update()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53243"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-13218",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Virtualization 4",
      "cwe": "CWE-61",
      "title": "Kubevirt: kubevirt: symlink following in writetocachedfile allows host file overwrite from virt-launcher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13218"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-53250",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00104,
      "epss_percentile": 0.01188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-367",
      "title": "xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53250"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-54679",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jqlang",
      "product": "jq",
      "cwe": "CWE-190",
      "title": "jq: potential integer overflow in jvp_string_append",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54679"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-46733",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00101,
      "epss_percentile": 0.01046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Display and Peripheral Manager",
      "cwe": "CWE-284",
      "title": "Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46733"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-4930",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00101,
      "epss_percentile": 0.01028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "silabs.com",
      "product": "Simplicity SDK",
      "cwe": "CWE-331",
      "title": "DPA Countermeasures weakening on Series 3 devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4930"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-53257",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: cfg80211: enforce HE/EHT cap/oper consistency",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53257"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-53145",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00099,
      "epss_percentile": 0.00925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-367",
      "title": "drm/gem: Try to fix change_handle ioctl, attempt 4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53145"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-53153",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00099,
      "epss_percentile": 0.00925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-820",
      "title": "mm/list_lru: drain before clearing xarray entry on reparent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53153"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-53185",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00095,
      "epss_percentile": 0.00783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "zram: fix use-after-free in zram_bvec_write_partial()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53185"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-53207",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53207"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-57438",
      "cvss_base": 2.2,
      "cvss_severity": "LOW",
      "epss_score": 0.00094,
      "epss_percentile": 0.00678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sparklemotion",
      "product": "nokogiri",
      "cwe": "CWE-416",
      "title": "Nokogiri: Possible Use-After-Free in XInclude Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57438"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-53197",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "xfrm: iptfs: fix ABBA deadlock in iptfs_destroy_state()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53197"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-53231",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00083,
      "epss_percentile": 0.00291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "net: phy: don't try to setup PHY-driven SFP cages when using genphy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53231"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-46732",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00075,
      "epss_percentile": 0.00097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Display and Peripheral Manager",
      "cwe": "CWE-362",
      "title": "Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46732"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-6412",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00074,
      "epss_percentile": 0.0008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfSSL",
      "product": "wolfSSL",
      "cwe": "CWE-327",
      "title": "Continued acceptance of SHA-1/MD5 digests in certificate processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6412"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-46734",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00064,
      "epss_percentile": 0.00016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Display and Peripheral Manager",
      "cwe": "CWE-295",
      "title": "Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Protection mechanism bypass.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46734"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-60464",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-60464. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-60465",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-60465. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-71324",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-71324 (Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-71327",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-71327 (Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-71328",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-71328 (Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-71333",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-71333 (Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-71334",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-71334 (Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-71335",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-71335 (Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-71336",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-71336 (Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-71338",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-71338 (Flowise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13351",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13351 (zephyrproject-rtos Zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-40080",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-40080 (cacti). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-40082",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-40082 (cacti). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-40083",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-40083 (cacti). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-40084",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-40084 (cacti). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47770",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47770 (jqlang jq). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48995",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48995 (pnpm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49839",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49839 (jqlang jq). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50014",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50014 (pnpm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50015",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50015 (pnpm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50016",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50016 (pnpm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50017",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50017 (pnpm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50021",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50021 (pnpm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50573",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50573 (pnpm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54024",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54024 (danny-avila LibreChat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54025",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54025 (danny-avila LibreChat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54027",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54027 (danny-avila LibreChat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54029",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54029 (danny-avila LibreChat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54030",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54030 (danny-avila LibreChat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54033",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54033 (danny-avila LibreChat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54036",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54036 (danny-avila LibreChat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54037",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54037 (danny-avila LibreChat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54040",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54040 (danny-avila LibreChat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54917",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54917 (seaweedfs). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55180",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55180 (pnpm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55487",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55487 (pnpm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55697",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55697 (pnpm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55698",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55698 (pnpm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55699",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55699 (pnpm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55700",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55700 (pnpm). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
