{
  "day": "2026-06-26",
  "boundary": "UTC calendar day",
  "published_count": 353,
  "by_severity": {
    "CRITICAL": 47,
    "HIGH": 147,
    "MEDIUM": 152,
    "LOW": 7
  },
  "kev_count": 0,
  "exploit_reference_count": 39,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-50741",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.04456,
      "epss_percentile": 0.90651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revive",
      "product": "Adserver",
      "cwe": "CWE-94",
      "title": "Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwise valid plugin identifier as `type`, or using the `ox.setChannelTargeting` XML-RPC API method.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50741"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-48933",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.03711,
      "epss_percentile": 0.88864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodejs",
      "product": "node",
      "cwe": "CWE-190",
      "title": "A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48933"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-48618",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.03231,
      "epss_percentile": 0.87247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodejs",
      "product": "node",
      "cwe": "CWE-176",
      "title": "A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48618"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-53576",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02186,
      "epss_percentile": 0.80963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kestra-io",
      "product": "kestra",
      "cwe": "CWE-94",
      "title": "Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53576"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-57875",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0144,
      "epss_percentile": 0.7106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPCLPC2011/2211",
      "cwe": "CWE-476",
      "title": "GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability in packet parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57875"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-10823",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01346,
      "epss_percentile": 0.69175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "YMC Filter",
      "cwe": null,
      "title": "YMC Smart Filter < 3.11.3 - Unauthenticated Private/Draft Post Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10823"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-32833",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0134,
      "epss_percentile": 0.69048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shenzhen Cudy Technology Co., Ltd.",
      "product": "LT300 3.0",
      "cwe": "CWE-78",
      "title": "Cudy LT300 3.0 OS Command Injection via NTP Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32833"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-48778",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01314,
      "epss_percentile": 0.6842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "notepad-plus-plus",
      "product": "notepad-plus-plus",
      "cwe": "CWE-78",
      "title": "Notepad++: Arbitrary Code Execution via config.xml commandLineInterpreter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48778"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-57872",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01005,
      "epss_percentile": 0.60235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPCLPC2011/2211",
      "cwe": "CWE-22",
      "title": "GV-LPC2011/LPC2211 - unauthorized directory traversal vulnerability (get_fcont.cgi)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57872"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-40711",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00954,
      "epss_percentile": 0.58605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Container Storage Modules",
      "cwe": "CWE-78",
      "title": "Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40711"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-49869",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00892,
      "epss_percentile": 0.56637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kestra-io",
      "product": "kestra",
      "cwe": "CWE-78",
      "title": "Kestra: Unauthenticated Remote Code Execution via Authentication Bypass in `AuthenticationFilter`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49869"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-54753",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00813,
      "epss_percentile": 0.54158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nrwl",
      "product": "nx",
      "cwe": "CWE-749",
      "title": "Nx: `nx graph` dev server permissive CORS policy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54753"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-0685",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00726,
      "epss_percentile": 0.513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edgewall *Genshi*",
      "product": "Genshi",
      "cwe": null,
      "title": "Server side template inject (SSTI) in Edgewall Genshi Template Engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0685"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-48619",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00639,
      "epss_percentile": 0.47867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodejs",
      "product": "node",
      "cwe": "CWE-400",
      "title": "A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on the client. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48619"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-28701",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00632,
      "epss_percentile": 0.47577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Daktronics",
      "product": "VFC-DMP-5000",
      "cwe": "CWE-22",
      "title": "Daktronics Controller Firmware Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28701"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-5757",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00551,
      "epss_percentile": 0.43696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ollama AI",
      "product": "Ollama",
      "cwe": "CWE-125",
      "title": "There exists an unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5757"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-57878",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00531,
      "epss_percentile": 0.42634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPCLPC2011/2211",
      "cwe": "CWE-121",
      "title": "GV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (thttpd)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57878"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-57879",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0053,
      "epss_percentile": 0.42569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPCLPC2011/2211",
      "cwe": "CWE-121",
      "title": "GV-LPC2011/LPC2211 - unauthorized buffer overflow via AuthMode/AuthValue path (ssvr)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57879"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-57880",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0053,
      "epss_percentile": 0.42569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPCLPC2011/2211",
      "cwe": "CWE-121",
      "title": "GV-LPC2011/LPC2211 - unauthorized buffer overflow via RTSP Digest username (ssvr)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57880"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-30041",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00522,
      "epss_percentile": 0.42097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via supplying a crafted PSD file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30041"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-56032",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0051,
      "epss_percentile": 0.41384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BuddyBoss",
      "product": "Buddyboss Platform",
      "cwe": "CWE-502",
      "title": "WordPress Buddyboss Platform plugin <= 3.0.4 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56032"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-57518",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.39505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pagekit",
      "product": "pagekit",
      "cwe": "CWE-862",
      "title": "Pagekit CMS 1.0.18 Privilege Escalation via UserApiController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57518"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-54350",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00471,
      "epss_percentile": 0.3891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-89",
      "title": "Budibase: Anonymous NoSQL operator injection via published-app query templates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54350"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-57527",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00463,
      "epss_percentile": 0.38412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zaproxy",
      "product": "zap-extensions",
      "cwe": "CWE-502",
      "title": "ZAP ViewState Add-on Insecure Deserialization via JSFViewState.decode()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57527"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-0828",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00461,
      "epss_percentile": 0.38335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Safetica",
      "product": "Endpoint Client",
      "cwe": null,
      "title": "Kernel driver vulnerability in Safetica Endpoint Client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0828"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-45807",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00457,
      "epss_percentile": 0.38074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kestra-io",
      "product": "kestra",
      "cwe": "CWE-22",
      "title": "Kestra: Path traversal via URL-encoded \"%2E%2E\" in execution and namespace file endpoints allows arbitrary file read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45807"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-49984",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00457,
      "epss_percentile": 0.38074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kestra-io",
      "product": "kestra",
      "cwe": "CWE-22",
      "title": "Kestra: Path traversal in `LocalStorage` allows any authenticated user to read arbitrary server files via the execution file-download API (`\\..\\` bypasses the `..` guard)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49984"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-30040",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00454,
      "epss_percentile": 0.37825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary code in the context of the current process via supplying a crafted JPEG 2000 (JP2) file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30040"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-38639",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.37296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-20",
      "title": "An issue in the parse_month function (/time/strptime.rs) of relibc commit ab6a2e allows attackers to cause a Denial of Service (DoS) via parsing a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38639"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-38641",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.37297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-404",
      "title": "An issue in the DSO::mmap_and_copy function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via loading a crafted shared library.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38641"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-55677",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00431,
      "epss_percentile": 0.36089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "labstack",
      "product": "echo",
      "cwe": "CWE-22",
      "title": "Echo: Encoded slash (%2F) bypasses route-level protection and exposes static files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55677"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-53284",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00426,
      "epss_percentile": 0.3573,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "btrfs: only release the dirty pages io tree after successful writes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53284"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-48090",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00426,
      "epss_percentile": 0.35744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-416",
      "title": "Envoy HTTP: OAuth2 filter late async token completion after stream teardown (UAF / crash risk)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48090"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-47220",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00424,
      "epss_percentile": 0.3557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-476",
      "title": "Envoy: Segmentation fault when using %REQUESTED_SERVER_NAME% in log format",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47220"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-48615",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00421,
      "epss_percentile": 0.35311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodejs",
      "product": "node",
      "cwe": "CWE-359",
      "title": "A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48615"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-9639",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0042,
      "epss_percentile": 0.35251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-476",
      "title": "Authenticated Denial of Service via Malicious Backup Tarball in LXD",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9639"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-31928",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00415,
      "epss_percentile": 0.34793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Daktronics",
      "product": "VFC-DMP-5000",
      "cwe": "CWE-798",
      "title": "Daktronics Controller Firmware Use of Hard-coded Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31928"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-56057",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00414,
      "epss_percentile": 0.34684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Uncanny Owl",
      "product": "Uncanny Automator Pro",
      "cwe": "CWE-502",
      "title": "WordPress Uncanny Automator Pro plugin <= 7.3.0.6 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56057"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2025-11919",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.004,
      "epss_percentile": 0.3338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wolfram Research Inc.",
      "product": "Cloud",
      "cwe": null,
      "title": "Unprotected temporary directories in Wolfram Cloud may result in privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-11919"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-53309",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00399,
      "epss_percentile": 0.33268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-193",
      "title": "ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53309"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-54341",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00399,
      "epss_percentile": 0.33324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dragonflydb",
      "product": "dragonfly",
      "cwe": "CWE-125",
      "title": "Dragonfly: RESTORE operations may crash the server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54341"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-50739",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00393,
      "epss_percentile": 0.32653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revive",
      "product": "Adserver",
      "cwe": "CWE-284",
      "title": "A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation of linking campaigns and trackers through the `tracker-campaigns.php` script in Revive Adserver 6.0.7 and earlier. As a result, a low‑privileged user could link their trackers to campaigns owned by other managers on the same instance, leading to inconsistent ownership relationships.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50739"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-56876",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00391,
      "epss_percentile": 0.32397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "max-mapper",
      "product": "extract-zip",
      "cwe": "CWE-22",
      "title": "extract-zip unvalidated symlink path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56876"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-8380",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00387,
      "epss_percentile": 0.32041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Frontend File Manager Plugin",
      "cwe": null,
      "title": "Frontend File Manager Plugin <= 23.6 - Author+ Arbitrary Post Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8380"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-36478",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsServerApp.exe, DnsServerApp.dll, TechnitiumLibrary.Net/Dns/DnsClient.cs components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36478"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-33646",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jdx",
      "product": "mise",
      "cwe": "CWE-94",
      "title": "mise: Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33646"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2025-55017",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00382,
      "epss_percentile": 0.31568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache IoTDB",
      "cwe": "CWE-22",
      "title": "Apache IoTDB: Path Traversal Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-55017"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2025-64152",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00382,
      "epss_percentile": 0.31569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache IoTDB",
      "cwe": "CWE-22",
      "title": "Apache IoTDB: Path Traversal Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64152"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-56055",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "InspiryThemes",
      "product": "RealHomes",
      "cwe": "CWE-502",
      "title": "WordPress RealHomes theme <= 4.5.3 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56055"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-56010",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00378,
      "epss_percentile": 0.31047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tyche Softwares.",
      "product": "Abandoned Cart Pro for WooCommerce",
      "cwe": "CWE-266",
      "title": "WordPress Abandoned Cart Pro for WooCommerce plugin <= 10.4.0 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56010"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-57881",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00376,
      "epss_percentile": 0.3088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPCLPC2011/2211",
      "cwe": "CWE-121",
      "title": "GV-LPC2011/LPC2211 - unauthorized stack-based buffer overflow vulnerability (vlsvr)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57881"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-48706",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-120",
      "title": "Envoy Heap Buffer Overflow in TcpStatsdSink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48706"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-55686",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00374,
      "epss_percentile": 0.30679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "podman-container-tools",
      "product": "podman",
      "cwe": "CWE-61",
      "title": "Podman: WORKDIR symlink traversal vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55686"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-54352",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.30534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-22",
      "title": "Budibase: Arbitrary file read by workspace-builder via PWA-zip symlink upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54352"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-56773",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "teableio",
      "product": "teable",
      "cwe": "CWE-862",
      "title": "Teable - Missing Authorization in v2 REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56773"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-9640",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.29822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "LXD",
      "cwe": "CWE-863",
      "title": "LXD Snapshot Import Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9640"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-48042",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-1124",
      "title": "Envoy: Stack overflow in destructor of highly nested JSON",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48042"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-54825",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00363,
      "epss_percentile": 0.29582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpDataTables",
      "product": "wpDataTables",
      "cwe": "CWE-89",
      "title": "WordPress wpDataTables plugin <= 7.4 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54825"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-56028",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0036,
      "epss_percentile": 0.29223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themewant",
      "product": "Easy Elements for Elementor &#8211; Addons &amp; Website Templates",
      "cwe": "CWE-266",
      "title": "WordPress Easy Elements for Elementor – Addons & Website Templates plugin <= 1.4.9 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56028"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-48800",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.2925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "notepad-plus-plus",
      "product": "notepad-plus-plus",
      "cwe": "CWE-78",
      "title": "Notepad++: Arbitrary Code Execution via shortcuts.xml UserCommand Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48800"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-57876",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00356,
      "epss_percentile": 0.28885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPCLPC2011/2211",
      "cwe": "CWE-787",
      "title": "GV-LPC2011/LPC2211 - unauthorized out-of-bounds writing vulnerability (onvif.cgi)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57876"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-55975",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28544,
      "kev": false,
      "kev_due_at": null,
      "vendor": "H.VIEW",
      "product": "HV-500S6 IP Camera",
      "cwe": "CWE-78",
      "title": "H.VIEW HV-500S6 IP Camera OS Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55975"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-56058",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00352,
      "epss_percentile": 0.28378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeCatcher",
      "product": "Quform",
      "cwe": "CWE-434",
      "title": "WordPress Quform plugin <= 2.23.0 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56058"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-56059",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00352,
      "epss_percentile": 0.28379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PhysCode",
      "product": "Travel Booking",
      "cwe": "CWE-434",
      "title": "WordPress Travel Booking theme <= 2.2.5 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56059"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-57315",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Creative Themes",
      "product": "Blocksy Companion Pro",
      "cwe": "CWE-94",
      "title": "WordPress Blocksy Companion Pro plugin <= 2.1.45 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57315"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2025-10268",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00349,
      "epss_percentile": 0.28107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Printcart Web to Print Product Designer for WooCommerce",
      "cwe": null,
      "title": "Printcart Web to Print Product Designer for WooCommerce <= 2.4.8 - Unauthenticated Folder Content Disclosure via Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-10268"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-57628",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.2795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP All Import",
      "product": "WP All Import",
      "cwe": "CWE-89",
      "title": "WordPress WP All Import plugin <= 4.0.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57628"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-57631",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.2795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ays Pro",
      "product": "Popup box",
      "cwe": "CWE-89",
      "title": "WordPress Popup box plugin <= 6.0.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57631"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-57316",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.2766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roxnor",
      "product": "GetGenie",
      "cwe": "CWE-497",
      "title": "WordPress GetGenie plugin <= 4.4.2 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57316"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-57318",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gemini Labs",
      "product": "Site Reviews",
      "cwe": "CWE-201",
      "title": "WordPress Site Reviews plugin <= 8.0.11 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57318"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-46604",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "golang.org/x/image",
      "product": "golang.org/x/image/tiff",
      "cwe": "CWE-787",
      "title": "Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46604"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-11625",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DAVIDO",
      "product": "Bytes::Random::Secure",
      "cwe": "CWE-335",
      "title": "Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11625"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-11702",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.2692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DAVIDO",
      "product": "Bytes::Random::Secure::Tiny",
      "cwe": "CWE-335",
      "title": "Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11702"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-56066",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.26599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ShortPixel",
      "product": "ShortPixel Adaptive Images",
      "cwe": "CWE-22",
      "title": "WordPress ShortPixel Adaptive Images plugin <= 3.11.4 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56066"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-54351",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00334,
      "epss_percentile": 0.26434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-915",
      "title": "Budibase: Mass Assignment in Webhook Trigger Allows Cross-Workspace Automation Execution via appId Override",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54351"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-33560",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00331,
      "epss_percentile": 0.2613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Daktronics",
      "product": "VFC-DMP-5000",
      "cwe": "CWE-434",
      "title": "Daktronics Controller Firmware Unrestricted Upload of File with Dangerous Type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33560"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-47221",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-476",
      "title": "Envoy: Null pointer deref in internal redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47221"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-9699",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.25487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-532",
      "title": "Mattermost Agents plugin logs unsanitized OpenAI API keys on authentication errors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9699"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-48930",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00324,
      "epss_percentile": 0.25336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodejs",
      "product": "node",
      "cwe": "CWE-284",
      "title": "A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48930"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-56030",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00321,
      "epss_percentile": 0.25016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "paytiumsupport",
      "product": "Paytium",
      "cwe": "CWE-266",
      "title": "WordPress Paytium plugin <= 5.0.2 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56030"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-56033",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00321,
      "epss_percentile": 0.25015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokan Multivendor Plugin",
      "product": "Dokan Pro",
      "cwe": "CWE-266",
      "title": "WordPress Dokan Pro plugin <= 5.0.4 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56033"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-57915",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.24997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Kerby",
      "cwe": "CWE-304",
      "title": "Apache Kerby: Kerberos Pre-Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57915"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-48044",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-409",
      "title": "Envoy Zstd Decompressor: Ratio Check at Wrong Loop Depth lead to memory explosion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48044"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-56027",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00319,
      "epss_percentile": 0.2476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pluggabl",
      "product": "Booster for WooCommerce",
      "cwe": "CWE-434",
      "title": "WordPress Booster for WooCommerce plugin <= 8.0.1 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56027"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-57874",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPCLPC2011/2211",
      "cwe": "CWE-120",
      "title": "GV-LPC2011/LPC2211 - unauthorized buffer overflow vulnerability (IEEE8021x_upload.cgi)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57874"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-50745",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00317,
      "epss_percentile": 0.24552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revive",
      "product": "Adserver",
      "cwe": "CWE-79",
      "title": "A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the output of the Smarty custom helper function url was neither properly encoded nor sanitised, allowing user‑supplied input to be reflected without escaping.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50745"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-50740",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00315,
      "epss_percentile": 0.24355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revive",
      "product": "Adserver",
      "cwe": "CWE-79",
      "title": "A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFrame invocation tag to perform reflected XSS attacks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50740"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-57231",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.23971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "podman-container-tools",
      "product": "podman",
      "cwe": "CWE-200",
      "title": "Podman: Malformed Image can trick podman run into leaking host environment variables into the container",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57231"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-53577",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00311,
      "epss_percentile": 0.23937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kestra-io",
      "product": "kestra",
      "cwe": "CWE-863",
      "title": "Kestra: Cross-Execution File Read via Preview Endpoint (IDOR)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53577"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2025-68063",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StylemixThemes",
      "product": "Splash - Sport Club WordPress Theme for Basketball, Football, Hockey",
      "cwe": "CWE-98",
      "title": "WordPress Splash - Sport Club WordPress theme for Basketball, Football, Hockey theme <= 4.4.3 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68063"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2025-68064",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Everthemess",
      "product": "Goya Core",
      "cwe": "CWE-98",
      "title": "WordPress Goya Core plugin < 1.0.9.4 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68064"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-56031",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Uncanny Owl",
      "product": "Uncanny Automator",
      "cwe": "CWE-502",
      "title": "WordPress Uncanny Automator plugin <= 7.3.1.2 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56031"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-54824",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ads WPQuads",
      "product": "Ads by WPQuads",
      "cwe": "CWE-497",
      "title": "WordPress Ads by WPQuads plugin <= 3.0.3 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54824"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-50137",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-862",
      "title": "Budibase: POST /api/attachments/:datasourceId/url is unauthenticated and lets anonymous callers mint S3 PUT pre-signed URLs using stored datasource IAM credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50137"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-47204",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-476",
      "title": "Envoy: grpc_stats filter segfault on Connect protocol requests to direct_response routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47204"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-49486",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow FTP provider",
      "cwe": "CWE-319",
      "title": "Apache Airflow FTP provider: FTP Provider does not protect FTPS data channel (missing PROT_P)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49486"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-54834",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.21979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fpuenteonline",
      "product": "Object Cache 4 everyone",
      "cwe": "CWE-201",
      "title": "WordPress Object Cache 4 everyone plugin <= 2.3.2 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54834"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-56060",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.21979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tychesoftwares",
      "product": "Print Invoice & Delivery Notes for WooCommerce",
      "cwe": "CWE-497",
      "title": "WordPress Print Invoice & Delivery Notes for WooCommerce plugin <= 7.1.1 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56060"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-57914",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.21969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Kerby",
      "cwe": "CWE-400",
      "title": "Apache Kerby: StackOverflow on parsing deeply nested ASN1 structures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57914"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-47207",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-416",
      "title": "Envoy crashes if multiple unexpected ext_proc responses are packed into one gRPC message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47207"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-56069",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Site Building with Toolset",
      "product": "Toolset Forms",
      "cwe": "CWE-639",
      "title": "WordPress Toolset Forms plugin <= 2.6.24 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56069"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-57632",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Omnisend",
      "product": "Email Marketing for WooCommerce by Omnisend",
      "cwe": "CWE-862",
      "title": "WordPress Email Marketing for WooCommerce by Omnisend plugin <= 1.19.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57632"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-45405",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dokku",
      "product": "dokku",
      "cwe": "CWE-59",
      "title": "Dokku: Arbitrary File Write via Tar Symlink Traversal in git:from-archive and certs:add",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45405"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-54826",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21389,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PSM Plugins",
      "product": "SupportCandy",
      "cwe": "CWE-639",
      "title": "WordPress SupportCandy plugin <= 3.4.6 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54826"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-54846",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "akosglys",
      "product": "Syncee Premium Dropshipping &amp; Wholesale",
      "cwe": "CWE-862",
      "title": "WordPress Syncee Premium Dropshipping & Wholesale plugin <= 1.0.27 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54846"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-44736",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.21181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-200",
      "title": "OpenProject: Relations API Filter Bypasses Visibility Scope, Leaking Cross-Project Work Package Subjects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44736"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-56029",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.21125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "corvuspay",
      "product": "CorvusPay WooCommerce Payment Gateway",
      "cwe": "CWE-288",
      "title": "WordPress CorvusPay WooCommerce Payment Gateway plugin <= 2.7.4 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56029"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-57321",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.2109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "icc0rz",
      "product": "H5P",
      "cwe": "CWE-22",
      "title": "WordPress H5P plugin <= 1.17.7 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57321"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-54820",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetBooking",
      "cwe": "CWE-89",
      "title": "WordPress JetBooking plugin <= 4.0.4.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54820"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-54827",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "contempoinc",
      "product": "Real Estate 7",
      "cwe": "CWE-89",
      "title": "WordPress Real Estate 7 theme <= 3.5.9 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54827"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-54831",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paolo",
      "product": "GeoDirectory",
      "cwe": "CWE-89",
      "title": "WordPress GeoDirectory plugin <= 2.8.162 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54831"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-56034",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20874,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Online Web Tutor",
      "product": "Library Management System",
      "cwe": "CWE-89",
      "title": "WordPress Library Management System plugin <= 3.5.7 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56034"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-47206",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00283,
      "epss_percentile": 0.20913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dragonflydb",
      "product": "dragonfly",
      "cwe": "CWE-116",
      "title": "Dragonfly: RESP Protocol Injection via Lua redis.error_reply() in EvalSerializer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47206"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-50742",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revive",
      "product": "Adserver",
      "cwe": "CWE-79",
      "title": "A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed without proper escaping when inconsistencies were detected. Whether the XSS payload is executed when an administrator uses the affected maintenance tools is not entirely under the attacker's control.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50742"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-29509",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wummel",
      "product": "patool",
      "cwe": "CWE-22",
      "title": "Patool < 4.0.5 Path Traversal via safe_extract() Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29509"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-57877",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPCLPC2011/2211",
      "cwe": "CWE-134",
      "title": "GV-LPC2011/LPC2211 - unauthorized format string vulnerability (vlsvr)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57877"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-45406",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dokku",
      "product": "dokku",
      "cwe": "CWE-95",
      "title": "Dokku: Host RCE via Maliciously Named OpenResty Include Files Injected Through eval",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45406"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-56008",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeFusion",
      "product": "Fusion Builder",
      "cwe": "CWE-266",
      "title": "WordPress Fusion Builder plugin <= 3.15.4 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56008"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-54837",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Syed Balkhi",
      "product": "Intranet &amp; Private Site &#8211; All-In-One Intranet",
      "cwe": "CWE-862",
      "title": "WordPress Intranet & Private Site – All-In-One Intranet plugin <= 1.8.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54837"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-54839",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kingaddons",
      "product": "Trinity Backup &#8211; Backup, Migrate, Restore, Clone &amp; Schedule Backups",
      "cwe": "CWE-639",
      "title": "WordPress Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups plugin <= 2.0.9 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54839"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-54847",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Design",
      "product": "Stylish Cost Calculator",
      "cwe": "CWE-862",
      "title": "WordPress Stylish Cost Calculator plugin <= 8.3.9 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54847"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-13372",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Remote Desktop Manager",
      "cwe": "CWE-706",
      "title": "Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026.2.5 through 2026.2.11 allows an authenticated attacker with write access to a shared workspace to execute a PowerShell script in another user's context via a display name collision with an existing VPN script link.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13372"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-54636",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00274,
      "epss_percentile": 0.19873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dokku",
      "product": "dokku",
      "cwe": "CWE-78",
      "title": "Dokku: OS Command Injection via app.json managed Cron",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54636"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-47205",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.1988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-416",
      "title": "Envoy: ext_authz Use-After-Free during Stream Teardown with Per-Route Overrides",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47205"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-49991",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "rustfs",
      "cwe": "CWE-22",
      "title": "RustFS Snowball Auto-Extract: Path Traversal allows cross-bucket object injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49991"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-13226",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.19775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "trainingbusinesspros",
      "product": "Groundhogg — CRM, Newsletters, and Marketing Automation",
      "cwe": "CWE-89",
      "title": "Groundhogg <= 4.5.4 - Authenticated (Custom+) SQL Injection via 'after' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13226"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-46386",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00272,
      "epss_percentile": 0.19695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-502",
      "title": "OpenProject: Pre-authentication RCE in openproject/openproject Docker image via default `SECRET_KEY_BASE=OVERWRITE_ME` and `cookies_serializer = :marshal`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46386"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-57658",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0027,
      "epss_percentile": 0.19225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Templatespare",
      "product": "TemplateSpare",
      "cwe": "CWE-434",
      "title": "WordPress TemplateSpare plugin <= 4.2.0 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57658"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-56064",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themefic",
      "product": "Tourfic",
      "cwe": "CWE-89",
      "title": "WordPress Tourfic plugin <= 2.22.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56064"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-44735",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-863",
      "title": "OpenProject: Shares API Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44735"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-56035",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cory Marsh",
      "product": "BitFire Security",
      "cwe": "CWE-1284",
      "title": "WordPress BitFire Security plugin <= 5.0.3 - Multiple Vulnerabilities vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56035"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-57920",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Peplink",
      "product": "InControl",
      "cwe": "CWE-551",
      "title": "Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57920"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-52782",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00258,
      "epss_percentile": 0.17619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-639",
      "title": "OpenProject: IDOR through /projects/<A>/settings/project_storages/<A_ps_id> via PATCH parameter \"storages_project_storage[project_folder_id]\" leads to Access to Unauthorized Resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52782"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-48770",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "notepad-plus-plus",
      "product": "notepad-plus-plus",
      "cwe": "CWE-125",
      "title": "Notepad++ WM_COPYDATA COPYDATA_FULL_CMDLINE local DoS crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48770"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-48934",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodejs",
      "product": "node",
      "cwe": "CWE-295",
      "title": "A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48934"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-47193",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-200",
      "title": "OpenProject: Journal diff endpoint bypasses object, journal, and field visibility checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47193"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-57647",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bPlugins",
      "product": "Panorama Viewer – 360 Degree Image + Video Viewer",
      "cwe": "CWE-98",
      "title": "WordPress Panorama Viewer – 360 Degree Image + Video Viewer plugin <= 1.6.1 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57647"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-1869",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpeverest",
      "product": "User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder",
      "cwe": "CWE-862",
      "title": "User Registration & Membership <= 5.2.0 - Missing Authorization to Unauthenticated Payment Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1869"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-57622",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arraytics",
      "product": "WPCafe",
      "cwe": "CWE-862",
      "title": "WordPress WPCafe plugin <= 3.0.14 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57622"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-50765",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.16451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the restriction type label (display_text field).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50765"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2025-32394",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Significant-Gravitas",
      "product": "AutoGPT",
      "cwe": "CWE-405",
      "title": "AutoGPT: There is a DoS vulnerability in AITextSummarizerBlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32394"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2025-32423",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.1624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Significant-Gravitas",
      "product": "AutoGPT",
      "cwe": "CWE-770",
      "title": "AutoGPT: There is a DoS vulnerability in ExtractTextInformationBlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32423"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-57912",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson & Johnson",
      "product": "Campus Recruiting",
      "cwe": "CWE-602",
      "title": "Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes entered about students by interviewers.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57912"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-57913",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson & Johnson",
      "product": "Audit Tracking Management System",
      "cwe": "CWE-602",
      "title": "Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transcripts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57913"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-8661",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.16017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "InsightConnect Markdown Plugin",
      "cwe": "CWE-79",
      "title": "Server-Side Cross-Site Scripting and SSRF in Rapid7 InsightConnect Markdown to PDF Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8661"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-54832",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jegstudio",
      "product": "Gutenverse Companion",
      "cwe": "CWE-862",
      "title": "WordPress Gutenverse Companion plugin <= 2.5.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54832"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-54835",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rustaurius",
      "product": "Five Star Restaurant Menu",
      "cwe": "CWE-862",
      "title": "WordPress Five Star Restaurant Menu plugin <= 2.5.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54835"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-56025",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paymob",
      "product": "Paymob for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Paymob for WooCommerce plugin <= 4.1.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56025"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-56061",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Swings",
      "product": "Subscriptions for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Subscriptions for WooCommerce plugin <= 1.9.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56061"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-56044",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adenion",
      "product": "Blog2Social",
      "cwe": "CWE-79",
      "title": "WordPress Blog2Social plugin <= 8.9.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56044"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-2053",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00236,
      "epss_percentile": 0.14913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 API Manager",
      "cwe": "CWE-918",
      "title": "Unauthenticated Server-Side Request Forgery via WS-Addressing in WSO2 API Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2053"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-12411",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00236,
      "epss_percentile": 0.14811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "lxd",
      "cwe": "CWE-639",
      "title": "Broken Access Control in Canonical LXD DevLXD API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12411"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-54833",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dev Kabir",
      "product": "Enable CORS",
      "cwe": "CWE-321",
      "title": "WordPress Enable CORS plugin <= 2.0.3 - Backdoor vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54833"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2025-63078",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jetmonsters",
      "product": "Restaurant Menu by MotoPress",
      "cwe": "CWE-862",
      "title": "WordPress Restaurant Menu by MotoPress plugin <= 2.4.11 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-63078"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-50744",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revive",
      "product": "Adserver",
      "cwe": "CWE-284",
      "title": "A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID cookie in the HTTP headers, and although the method correctly returned an error, the associated session was not invalidated. As a result, the leaked session ID could be used to perform subsequent API calls without restrictions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50744"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-57640",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stylemix",
      "product": "MasterStudy LMS",
      "cwe": "CWE-862",
      "title": "WordPress MasterStudy LMS plugin <= 3.7.30 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57640"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-57873",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-LPCLPC2011/2211",
      "cwe": "CWE-476",
      "title": "GV-LPC2011/LPC2211 - unauthorized null pointer dereference vulnerability (IEEE8021x_upload.cgi)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57873"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-56048",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tychesoftwares",
      "product": "Payment Gateway Based Fees and Discounts for WooCommerce",
      "cwe": "CWE-639",
      "title": "WordPress Payment Gateway Based Fees and Discounts for WooCommerce plugin <= 3.0.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56048"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-57324",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VillaTheme",
      "product": "GIFT4U",
      "cwe": "CWE-862",
      "title": "WordPress GIFT4U plugin <= 1.0.10 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57324"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-11779",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PayloadCMS",
      "product": "PayloadCMS",
      "cwe": "CWE-307",
      "title": "PayloadCMS 3.84.1 - Authenticated account lockout bypass through default unlock access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11779"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-45408",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.14522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dokku",
      "product": "dokku",
      "cwe": "CWE-78",
      "title": "Dokku: OS Command Injection via App Name in Git Pre-Receive Hook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45408"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-52701",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themegrill",
      "product": "User Registration",
      "cwe": "CWE-862",
      "title": "WordPress User Registration plugin <= 5.2.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52701"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2025-64637",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.14483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Opal_WP",
      "product": "Auros Core",
      "cwe": "CWE-80",
      "title": "WordPress Auros Core plugin <= 5.3.1 - Content Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64637"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-57633",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.14483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WCBoost",
      "product": "WCBoost &#8211; Products Compare",
      "cwe": "CWE-497",
      "title": "WordPress WCBoost &#8211; Products Compare plugin <= 1.1.0 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57633"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-52780",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00231,
      "epss_percentile": 0.14182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-20",
      "title": "OpenProject: Cache store poisoning leads to Remote Code Execution (RCE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52780"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-48497",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-480",
      "title": "Envoy: Abnormal process termination in DNS UDP filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48497"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-44734",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-862",
      "title": "OpenProject: Improper Access Control on OpenProject through the POST request to /projects/[PROJECT_NAME]/cost_reports/[REPORT_ID]/rename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44734"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-56041",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dFactory",
      "product": "Responsive Lightbox",
      "cwe": "CWE-79",
      "title": "WordPress Responsive Lightbox plugin <= 2.7.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56041"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-56043",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CusRev",
      "product": "Customer Reviews for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Customer Reviews for WooCommerce plugin <= 5.110.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56043"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-57312",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpeverest",
      "product": "Everest Forms",
      "cwe": "CWE-79",
      "title": "WordPress Everest Forms plugin <= 3.4.8 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57312"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-57314",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.1411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SureCart",
      "product": "SureCart",
      "cwe": "CWE-79",
      "title": "WordPress SureCart plugin <= 4.3.2 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57314"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-57317",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.1411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NSquared",
      "product": "Simply Schedule Appointments",
      "cwe": "CWE-79",
      "title": "WordPress Simply Schedule Appointments plugin <= 1.6.12.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57317"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-57319",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.1411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RealMag777",
      "product": "FOX",
      "cwe": "CWE-79",
      "title": "WordPress FOX plugin <= 1.4.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57319"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-56036",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00229,
      "epss_percentile": 0.14016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codemstory",
      "product": "워드프레스 결제 심플페이",
      "cwe": "CWE-89",
      "title": "WordPress 워드프레스 결제 심플페이 plugin <= 5.5.6 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56036"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-56062",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00229,
      "epss_percentile": 0.14017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oooorgle",
      "product": "Quotes llama",
      "cwe": "CWE-89",
      "title": "WordPress Quotes llama plugin <= 3.1.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56062"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-56067",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00229,
      "epss_percentile": 0.14015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetSmartFilters",
      "cwe": "CWE-89",
      "title": "WordPress JetSmartFilters plugin <= 3.8.3 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56067"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-56068",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00229,
      "epss_percentile": 0.14017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetEngine",
      "cwe": "CWE-89",
      "title": "WordPress JetEngine plugin <= 3.8.10.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56068"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-56070",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00229,
      "epss_percentile": 0.14015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeHunk",
      "product": "Advance Product Search",
      "cwe": "CWE-89",
      "title": "WordPress Advance Product Search plugin <= 1.4.4 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56070"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-57313",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.1401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SureCart",
      "product": "SureCart",
      "cwe": "CWE-79",
      "title": "WordPress SureCart plugin <= 4.2.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57313"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-57940",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00229,
      "epss_percentile": 0.13973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danpros",
      "product": "HTMLy",
      "cwe": "CWE-918",
      "title": "HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The function get_feed() in system/admin/admin.php passes user-supplied $feed_url directly to file_get_contents() without any validation. An authenticated attacker with administrative privileges can exploit this by entering a crafted URL (e.g., http://dnslog.example.com, file:///etc/passwd, or http://169.254.169.254 in cloud contexts) via Tools -> Import RSS. The server will then make a request to the attacker-controlled target.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57940"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-56414",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "H.VIEW",
      "product": "HV-500S6 IP Camera",
      "cwe": "CWE-434",
      "title": "H.VIEW HV-500S6 IP Camera Unrestricted Upload of File with Dangerous Type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56414"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-56038",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frisbii",
      "product": "Frisbii Pay",
      "cwe": "CWE-862",
      "title": "WordPress Frisbii Pay plugin <= 1.8.2 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56038"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-56663",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Significant-Gravitas",
      "product": "AutoGPT",
      "cwe": "CWE-918",
      "title": "AutoGPT: SSRF-to-RCE Chain in `SendWebRequestBlock` via IP validation bypass and internal `pg-meta` access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56663"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-50766",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with edit_items permission to inject arbitrary web scripts via the item public notes field (items.itemnotes).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50766"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-50767",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the item type check-in message field (checkinmsg).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50767"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-52785",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00221,
      "epss_percentile": 0.12981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-89",
      "title": "OpenProject: SQL injection in timestamps functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52785"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-57323",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.1293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bPlugins",
      "product": "Flash & HTML5 Video",
      "cwe": "CWE-862",
      "title": "WordPress Flash & HTML5 Video plugin <= 2.11.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57323"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2025-66123",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.1293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "About Envato",
      "product": "BookPro",
      "cwe": "CWE-639",
      "title": "WordPress BookPro plugin <= 1.1.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66123"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-57630",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.1293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Creative Themes",
      "product": "Blocksy Companion Pro",
      "cwe": "CWE-639",
      "title": "WordPress Blocksy Companion Pro plugin <= 2.1.46 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57630"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-48743",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00217,
      "epss_percentile": 0.12488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-444",
      "title": "Envoy: HTTP/3 to HTTP/1 request smuggling via headers-only request with nonzero Content-Length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48743"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-47214",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00217,
      "epss_percentile": 0.12443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docling-project",
      "product": "docling",
      "cwe": "CWE-73",
      "title": "Docling: Unsafe URI and Path Handling in HTML Backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47214"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-57661",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "WPComplete",
      "cwe": "CWE-862",
      "title": "WordPress WPComplete plugin <= 2.9.5.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57661"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-48928",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodejs",
      "product": "node",
      "cwe": "CWE-284",
      "title": "A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48928"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-10835",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "SALESmanago & Leadoo",
      "cwe": null,
      "title": "SALESmanago & Leadoo < 3.11.3 - Subscriber+ SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10835"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-56026",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chris Carlevato",
      "product": "utm.codes",
      "cwe": "CWE-918",
      "title": "WordPress utm.codes plugin <= 1.9.0 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56026"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-49355",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-200",
      "title": "OpenProject: Private work package data disclosure through single meeting agenda item API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49355"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-54840",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.1188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tribulant Software",
      "product": "Newsletters",
      "cwe": "CWE-862",
      "title": "WordPress Newsletters plugin <= 4.13 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54840"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-57643",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AF themes",
      "product": "WP Post Author",
      "cwe": "CWE-89",
      "title": "WordPress WP Post Author plugin <= 3.9.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57643"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-57667",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adrian Tobey",
      "product": "Groundhogg",
      "cwe": "CWE-89",
      "title": "WordPress Groundhogg plugin <= 4.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57667"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-52884",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "notepad-plus-plus",
      "product": "notepad-plus-plus",
      "cwe": "CWE-42",
      "title": "Notepad++: CVE-2026-48800 Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52884"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-44696",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-79",
      "title": "OpenProject: Stored CSS injection via Sanitize::Config::RELAXED[:css] enables phishing overlays and data exfiltration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44696"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-56011",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chrisvrichardson",
      "product": "MapPress Maps for WordPress",
      "cwe": "CWE-79",
      "title": "WordPress MapPress Maps for WordPress plugin <= 2.97.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56011"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2025-64636",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rhewlif",
      "product": "Donation Thermometer",
      "cwe": "CWE-862",
      "title": "WordPress Donation Thermometer plugin <= 2.2.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-64636"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-24547",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SiteGround",
      "product": "SiteGround Email Marketing",
      "cwe": "CWE-862",
      "title": "WordPress SiteGround Email Marketing plugin <= 1.7.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24547"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-57629",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.10938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StatCounter",
      "product": "StatCounter",
      "cwe": "CWE-79",
      "title": "WordPress StatCounter plugin <= 2.1.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57629"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-57649",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.11047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "studiowombat",
      "product": "Shoppable Images Lite",
      "cwe": "CWE-862",
      "title": "WordPress Shoppable Images Lite plugin <= 1.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57649"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-57636",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tomdever",
      "product": "wpForo Forum",
      "cwe": "CWE-89",
      "title": "WordPress wpForo Forum plugin <= 3.0.9 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57636"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-57642",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bestwebsoft",
      "product": "Gallery",
      "cwe": "CWE-89",
      "title": "WordPress Gallery plugin <= 4.7.8 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57642"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-57644",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jetmonsters",
      "product": "Restaurant Menu by MotoPress",
      "cwe": "CWE-89",
      "title": "WordPress Restaurant Menu by MotoPress plugin <= 2.4.10 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57644"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-57653",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpjobportal",
      "product": "WP Job Portal",
      "cwe": "CWE-89",
      "title": "WordPress WP Job Portal plugin <= 2.5.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57653"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-57662",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wasiliy Strecker",
      "product": "Contest Gallery",
      "cwe": "CWE-89",
      "title": "WordPress Contest Gallery plugin <= 30.0.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57662"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-57663",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Igor Benic",
      "product": "Recipe Maker For Your Food Blog from Zip Recipes",
      "cwe": "CWE-89",
      "title": "WordPress Recipe Maker For Your Food Blog from Zip Recipes plugin <= 8.2.7 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57663"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-56046",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CridioStudio",
      "product": "ListingPro",
      "cwe": "CWE-79",
      "title": "WordPress ListingPro theme <= 2.9.11 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56046"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2025-63041",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Code Amp",
      "product": "Forget About Shortcode Buttons",
      "cwe": "CWE-862",
      "title": "WordPress Forget About Shortcode Buttons plugin <= 2.1.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-63041"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-55189",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.10305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "rustfs",
      "cwe": "CWE-862",
      "title": "RustFS: FTP frontend skips IAM authorization on object reads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55189"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-44732",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-639",
      "title": "OpenProject: IDOR on OpenProject through /api/v3/documents/{id} via PATCH parameter \"project_id\" leads to Unauthorized Modification of Resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44732"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-50136",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-306",
      "title": "Budibase: Unauthenticated S3 signed upload URL generation allows arbitrary writes with stored datasource credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50136"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2025-7958",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00197,
      "epss_percentile": 0.09786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trellix",
      "product": "Trellix Network Security NX, EX, FX, AX, and CMS",
      "cwe": "CWE-94",
      "title": "A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can execute arbitrary code using the web interface and Alert artifact details.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7958"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-13426",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09826,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "github.com/mattermost/mattermost/server/public",
      "cwe": "CWE-22",
      "title": "Client4 fails to validate path parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13426"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-53914",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00196,
      "epss_percentile": 0.09635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "Kotlin",
      "cwe": "CWE-502",
      "title": "In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53914"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-57918",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00195,
      "epss_percentile": 0.09583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sahlberg",
      "product": "libnfs",
      "cwe": "CWE-191",
      "title": "libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c during a connection to a crafted NFS server, when the expected pdu size exceeds the absolute pdu size from the xid/record-marker.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57918"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-55069",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.09503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kestra-io",
      "product": "kestra",
      "cwe": "CWE-916",
      "title": "Kestra BasicAuth Password Stored as SHA-512 Enables Offline Brute-Force Attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55069"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-3472",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00194,
      "epss_percentile": 0.09483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-693",
      "title": "Markdown image rendering bypass in AI bot tool result posts in Mattermost",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3472"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2025-63079",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bdthemes",
      "product": "Live Copy Paste for Elementor",
      "cwe": "CWE-862",
      "title": "WordPress Live Copy Paste for Elementor plugin <= 1.5.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-63079"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-57926",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00188,
      "epss_percentile": 0.08767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-1321",
      "title": "In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57926"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-44731",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-639",
      "title": "OpenProject: Improper Access Control on OpenProject through /projects/[projectName]/meetings via \"invited_user_id\" in GET parameter \"filters\" leads to user names disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44731"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-52779",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-639",
      "title": "OpenProject: Cross-project authorization bypass allows deleting public Calendar and Team Planner queries from unauthorized projects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52779"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-48935",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00185,
      "epss_percentile": 0.08413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodejs",
      "product": "node",
      "cwe": "CWE-276",
      "title": "A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48935"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-57645",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.08307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tribulant Software",
      "product": "Newsletters",
      "cwe": "CWE-862",
      "title": "WordPress Newsletters plugin <= 4.13 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57645"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-28385",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "lxd",
      "cwe": "CWE-918",
      "title": "SSRF via image import from URL allows internal network probing by authenticated users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28385"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-57652",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.0807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JoomSky",
      "product": "JS Help Desk",
      "cwe": "CWE-639",
      "title": "WordPress JS Help Desk plugin <= 3.1.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57652"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-57665",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.0807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GravityKit",
      "product": "GravityView",
      "cwe": "CWE-639",
      "title": "WordPress GravityView plugin <= 3.0.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57665"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-55188",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.07964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "rustfs",
      "cwe": "CWE-200",
      "title": "RustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55188"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-57430",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SEOPress Free",
      "product": "SEOPress PRO",
      "cwe": "CWE-862",
      "title": "WordPress SEOPress PRO plugin <= 9.1.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57430"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-57634",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Folio Team",
      "product": "PPWP",
      "cwe": "CWE-639",
      "title": "WordPress PPWP plugin <= 1.9.19 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57634"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-57921",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00177,
      "epss_percentile": 0.07531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-862",
      "title": "In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57921"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-57620",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tim Strifler",
      "product": "Exclusive Addons Elementor",
      "cwe": "CWE-79",
      "title": "WordPress Exclusive Addons Elementor plugin <= 2.7.9.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57620"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-57646",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Majestic Support",
      "product": "Majestic Support",
      "cwe": "CWE-639",
      "title": "WordPress Majestic Support plugin <= 1.1.7 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57646"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-47778",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-158",
      "title": "Envoy: Embedded NUL in TLS DNS SAN Truncation in the Default TLS Certificate Validator. (Auth Bypass)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47778"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-56039",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WordPress.com",
      "product": "Quick Interest Slider",
      "cwe": "CWE-79",
      "title": "WordPress Quick Interest Slider plugin <= 3.1.6 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56039"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-56040",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WordPress.com",
      "product": "Gutenverse Form",
      "cwe": "CWE-79",
      "title": "WordPress Gutenverse Form plugin <= 2.4.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56040"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-56045",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ValvePress",
      "product": "Automatic",
      "cwe": "CWE-79",
      "title": "WordPress Automatic plugin < 3.135.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56045"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-56047",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Perfmatters, Powered Kinsta + GeneratePress Docs Changelog Feature requests Legal Affiliate Contact",
      "product": "perfmatters",
      "cwe": "CWE-79",
      "title": "WordPress perfmatters plugin <= 2.6.3 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56047"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-56072",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xtemos",
      "product": "WoodMart",
      "cwe": "CWE-79",
      "title": "WordPress WoodMart theme <= 8.5.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56072"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-57322",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weDevs",
      "product": "weMail",
      "cwe": "CWE-79",
      "title": "WordPress weMail plugin <= 2.1.2 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57322"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-57325",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jellywp",
      "product": "NanoMag",
      "cwe": "CWE-79",
      "title": "WordPress NanoMag theme <= 1.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57325"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-44733",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-620",
      "title": "OpenProject: Business Logic Error on OpenProject through PATCH request to /api/v3/users/me permits to bypass password requirements",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44733"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-57627",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeum",
      "product": "Kirki",
      "cwe": "CWE-918",
      "title": "WordPress Kirki plugin <= 6.0.11 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57627"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-56063",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bPlugins",
      "product": "MailChimp Block",
      "cwe": "CWE-862",
      "title": "WordPress MailChimp Block plugin <= 1.1.15 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56063"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-57660",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "magepeopleteam",
      "product": "Booking and Rental Manager",
      "cwe": "CWE-862",
      "title": "WordPress Booking and Rental Manager plugin <= 2.7.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57660"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-57664",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VillaTheme",
      "product": "Bopo – WooCommerce Product Bundle Builder",
      "cwe": "CWE-497",
      "title": "WordPress Bopo – WooCommerce Product Bundle Builder plugin <= 1.1.6 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57664"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-57654",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wp.insider",
      "product": "Affiliates Manager",
      "cwe": "CWE-862",
      "title": "WordPress Affiliates Manager plugin <= 2.9.49 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57654"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-57924",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-276",
      "title": "In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57924"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-57925",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-862",
      "title": "In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57925"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-52784",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.05968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-352",
      "title": "OpenProject: CSRF on TARGET through /users/:id via POST parameter \"user[admin]\"",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52784"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-47775",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-209",
      "title": "Envoy OAuth2 Filter: Padding Oracle via AES-256-CBC Cookie Decryption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47775"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-55838",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "rustfs",
      "cwe": "CWE-862",
      "title": "RustFS: Missing admin authorization on /rustfs/admin/v3/metrics allows any authenticated user to read server metrics",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55838"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-57923",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-862",
      "title": "In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57923"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-54353",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.05403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-367",
      "title": "Budibase: Potential SSRF DNS rebinding bypass in outbound fetch validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54353"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2025-68074",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GhozyLab",
      "product": "Image Carousel",
      "cwe": "CWE-79",
      "title": "WordPress Image Carousel plugin <= 1.0.0.41 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68074"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2025-68075",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kerry",
      "product": "BNE Testimonials",
      "cwe": "CWE-79",
      "title": "WordPress BNE Testimonials plugin <= 2.0.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68075"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-57431",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.0531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mervin Praison",
      "product": "Featured Image",
      "cwe": "CWE-79",
      "title": "WordPress Featured Image plugin <= 2.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57431"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-57617",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SeedProd LLC.",
      "product": "SeedProd Pro",
      "cwe": "CWE-79",
      "title": "WordPress SeedProd Pro plugin < 6.19.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57617"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-57618",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeisle",
      "product": "Neve PRO",
      "cwe": "CWE-79",
      "title": "WordPress Neve PRO theme <= 3.1.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57618"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-57638",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPManageNinja LLC",
      "product": "Fluent Booking",
      "cwe": "CWE-79",
      "title": "WordPress Fluent Booking plugin <= 2.1.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57638"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-13434",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Virtualization 4",
      "cwe": "CWE-20",
      "title": "Virt-controller-rhel9: kubevirt: kubevirt: multus default-network annotation injection via unvalidated tenant networkname when externalnetresourceinjection is enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13434"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-45257",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.0504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-123",
      "title": "Arbitrary file overwrite via the KTLS receive path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45257"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-48936",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00154,
      "epss_percentile": 0.05118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodejs",
      "product": "node",
      "cwe": "CWE-284",
      "title": "A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48936"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-50132",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.0476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Budibase",
      "product": "budibase",
      "cwe": "CWE-284",
      "title": "Budibase: Chat Identity Link Hijacking via Missing Consent & CSRF — Account Impersonation in Budibase",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50132"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-52781",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.04737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-79",
      "title": "OpenProject: Stored XSS on openproject.example.com through /api/v3/projects/{project}/work_packages via POST parameter \"description\"",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52781"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-56823",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.04708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Significant-Gravitas",
      "product": "AutoGPT",
      "cwe": "CWE-284",
      "title": "AutoGPT: IDOR in Webhook Ping Endpoint Allows Enumeration and Cross-User Ping Triggering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56823"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-57648",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nelio Software",
      "product": "Nelio Content",
      "cwe": "CWE-862",
      "title": "WordPress Nelio Content plugin <= 4.3.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57648"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-57473",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Reolink",
      "product": "Home Hub",
      "cwe": "CWE-1391",
      "title": "A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the possibility of brute-force cracking the credentials. This issue could allow attackers on the same local network to intercept traffic between the Hub and associated cameras and compromise the credentials of connected cameras.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57473"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-57922",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-862",
      "title": "In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57922"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-36908",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.04016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "A stack overflow in the AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36908"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2025-68052",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eagle-Themes",
      "product": "Eagle Booking",
      "cwe": "CWE-352",
      "title": "WordPress Eagle Booking plugin <= 1.3.4.3 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68052"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-48529",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "github",
      "product": "github-mcp-server",
      "cwe": "CWE-284",
      "title": "GitHub MCP Server: Lockdown mode singleton in HTTP server causes cross-user GraphQL client confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48529"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-47692",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envoyproxy",
      "product": "envoy",
      "cwe": "CWE-130",
      "title": "Envoy: PROXY Protocol v2 header generator emits \"skipped\" TLVs, causing 65 KB attacker-controlled spillover into the upstream application stream",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47692"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-57656",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "peregrinethemes",
      "product": "Hester Core",
      "cwe": "CWE-79",
      "title": "WordPress Hester Core plugin <= 1.1.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57656"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-6658",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.03353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyter",
      "product": "jupyter/jupyter",
      "cwe": "CWE-79",
      "title": "Cross-site Scripting (XSS) in jupyter/nbconvert",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6658"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-54557",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jdx",
      "product": "mise",
      "cwe": "CWE-22",
      "title": "mise HTTP backend uses raw version path for install symlink destination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54557"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-53281",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.03051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "iommu/vt-d: Avoid NULL pointer dereference or refcount corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53281"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-53294",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.0305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-415",
      "title": "mailbox: mailbox-test: don't free the reused channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53294"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-53322",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-415",
      "title": "vfio/pci: Clean up DMABUFs before disabling function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53322"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-52783",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.0304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-313",
      "title": "OpenProject: Information Disclosure (cleartext storage of data) on localhost through memcached via Others \"storage.<id>.httpx_access_token\" leads to Sensitive Data Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52783"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-53296",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "mailbox: mailbox-test: free channels on probe error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53296"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-52885",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "notepad-plus-plus",
      "product": "notepad-plus-plus",
      "cwe": "CWE-367",
      "title": "Notepad++ TOCTOU: HMAC Checks Disk, Executes from Memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52885"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-55441",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jdx",
      "product": "mise",
      "cwe": "CWE-78",
      "title": "mise: Arbitrary command execution via task-include files in an untrusted, config-less repository",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55441"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-57659",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stranger Studios",
      "product": "Paid Memberships Pro - Add Member From Admin",
      "cwe": "CWE-352",
      "title": "WordPress Paid Memberships Pro - Add Member From Admin plugin <= 0.7.2 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57659"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-57650",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BlockArt",
      "product": "Magazine Blocks",
      "cwe": "CWE-79",
      "title": "WordPress Magazine Blocks plugin <= 1.8.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57650"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-57651",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nK",
      "product": "Ghost Kit",
      "cwe": "CWE-79",
      "title": "WordPress Ghost Kit plugin <= 3.6.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57651"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-53295",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mailbox: add sanity check for channel array",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53295"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-53286",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-415",
      "title": "idpf: fix double free and use-after-free in aux device error paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53286"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-53303",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "f2fs: protect extension_list reading with sb_lock in f2fs_sbi_show()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53303"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-36907",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "A stack overflow in the AP4_StsdAtom::AP4_StsdAtom component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36907"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-53290",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "drm/xe/eustall: Fix drm_dev_put called before stream disable in close",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53290"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-53300",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "net: enetc: fix NTMP DMA use-after-free issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53300"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-57641",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contempoinc",
      "product": "Real Estate 7",
      "cwe": "CWE-352",
      "title": "WordPress Real Estate 7 theme <= 3.5.9 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57641"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-53279",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/gma500/oaktrail_lvds: fix hang on init failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53279"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-53287",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "audit: fix incorrect inheritable capability in CAPSET records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53287"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-53289",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "ice: fix NULL pointer dereference in ice_reset_all_vfs()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53289"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-53291",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "ALSA: hda/conexant: Fix missing error check for jack detection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53291"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-53306",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.0249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-193",
      "title": "tty: hvc_iucv: fix off-by-one in number of supported devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53306"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-8797",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NEC Corporation",
      "product": "ExpressUpdate Agent for Windows",
      "cwe": "CWE-782",
      "title": "An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8797"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-53288",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-674",
      "title": "arm64: Reserve an extra page for early kernel mapping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53288"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-53298",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "net: airoha: Move ndesc initialization at end of airoha_qdma_init_rx_queue()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53298"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-53282",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "x86/kexec: Push kjump return address even for non-kjump kexec",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53282"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-53283",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "iommu/amd: Bounds-check devid in __rlookup_amd_iommu()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53283"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-53297",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "net: mana: Guard mana_remove against double invocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53297"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-53299",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.0229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "net: airoha: Move ndesc initialization at end of airoha_qdma_init_tx()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53299"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-53301",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "reset: amlogic: t7: Fix null reset ops",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53301"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-53302",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.0225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "crypto: eip93 - fix hmac setkey algo selection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53302"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-53305",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.0229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "usb: typec: ps883x: Fix Oops at unbind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53305"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-53320",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nilfs2: reject zero bd_oblocknr in nilfs_ioctl_mark_blocks_dirty()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53320"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-57635",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FunnelKit",
      "product": "FunnelKit Payment Gateway for Stripe WooCommerce",
      "cwe": "CWE-352",
      "title": "WordPress FunnelKit Payment Gateway for Stripe WooCommerce plugin <= 1.14.0.3 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57635"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-21734",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.02019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-823",
      "title": "GPU DDK - libusc OOB write at TreeRemove during WebGPU shader compilation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21734"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-53314",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.02036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "padata: Put CPU offline callback in ONLINE section to allow failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53314"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-39031",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-321",
      "title": "Lansweeper lsrunase 2.0 and lsencrypt 2.0 use RC4 encryption with a hardcoded 142-byte static key array to encrypt credentials. An 8-character prefix is stored in cleartext alongside the ciphertext. This allows an attacker with local access to recover any encrypted password to plaintext using a single SHA-1 hash and RC4 decryption operation, with no brute force required.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39031"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-55448",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jdx",
      "product": "mise",
      "cwe": "CWE-78",
      "title": "mise: Local credential_command executes untrusted config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55448"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-53324",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "net: mana: Use pci_name() for debugfs directory naming",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53324"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2023-20572",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics",
      "cwe": "CWE-208",
      "title": "An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing the input of an arbitrary message, potentially leading to a loss of data integrity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-20572"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-53317",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.0173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "wifi: mt76: mt7921: Place upper limit on station AID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53317"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-53318",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.0173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "wifi: mt76: mt7925: prevent NULL pointer dereference in mt7925_tx_check_aggr()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53318"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2023-20540",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00114,
      "epss_percentile": 0.01716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMD",
      "product": "AMD Ryzen™ 3000 Series Desktop Processors",
      "cwe": "CWE-208",
      "title": "An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing arbitrary message input, potentially leading to a loss of data integrity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-20540"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-44018",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.0165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docling-project",
      "product": "docling",
      "cwe": "CWE-409",
      "title": "Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44018"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-38571",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-312",
      "title": "Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, in the unauthenticated UART debug console of the Tenda N300 F3 (V603) allow a physically proximate attacker to obtain stored WPA2 credentials in cleartext and to read or write arbitrary memory via the serial console.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38571"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-53307",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "pinctrl: pinconf-generic: Fully validate 'pinmux' property",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53307"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-53310",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "soc/tegra: cbb: Fix cross-fabric target timeout lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53310"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-53311",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "fuse: fix uninit-value in fuse_dentry_revalidate()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53311"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-53312",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-835",
      "title": "iommu/riscv: Remove overflows on the invalidation path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53312"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-53321",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "io_uring/napi: cap busy_poll_to 10 msec",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53321"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-57655",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00109,
      "epss_percentile": 0.01416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jay Versluis",
      "product": "Child Theme Wizard",
      "cwe": "CWE-352",
      "title": "WordPress Child theme Wizard plugin <= 1.4 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57655"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-46710",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00108,
      "epss_percentile": 0.01387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "notepad-plus-plus",
      "product": "notepad-plus-plus",
      "cwe": "CWE-426",
      "title": "Notepad++: Privilege Escalation in the Installer via Uncontrolled Executable Search Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46710"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-53278",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.0133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "arm_mpam: Check whether the config array is allocated before destroying it",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53278"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-53280",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.0133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "iommu: Fix NULL group->domain dereference in pci_dev_reset_iommu_done()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53280"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-53285",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-617",
      "title": "drm/amd/display: Wrap DCN32 phantom-plane allocation in DC_RUN_WITH_PREEMPTION_ENABLED",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53285"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-53292",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-617",
      "title": "net: phonet: do not BUG_ON() in pn_socket_autobind() on failed bind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53292"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-45195",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00106,
      "epss_percentile": 0.01248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-280",
      "title": "GPU DDK - rgxfw_set_mips_fault_address(&psInit->sFaultPhysAddr) is untrusted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45195"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-4339",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.01164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-918",
      "title": "SSRF via unvalidated attachment URLs in Mattermost Agents plugin MCP server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4339"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-57637",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.01176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tychesoftwares",
      "product": "Abandoned Cart Lite for WooCommerce",
      "cwe": "CWE-352",
      "title": "WordPress Abandoned Cart Lite for WooCommerce plugin <= 6.8.0 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57637"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-53315",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "drm/amd/ras: Fix NULL deref in ras_core_get_utc_second_timestamp()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53315"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-53304",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.0102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "scsi: sg: Resolve soft lockup issue when opening /dev/sgX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53304"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-53308",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.01008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "power: supply: max77705: Free allocated workqueue and fix removal order",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53308"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-53313",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.0101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "drm/amd/display: Avoid NULL dereference in dc_dmub_srv error paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53313"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-53316",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "drm/amd/ras: Fix NULL deref in ras_core_ras_interrupt_detected()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53316"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-53319",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-617",
      "title": "blk-wbt: remove WARN_ON_ONCE from wbt_init_enable_default()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53319"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-53293",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00098,
      "epss_percentile": 0.00873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "drm/amdgpu: fix AMDGPU_INFO_READ_MMR_REG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53293"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-57657",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Noor Alam",
      "product": "Gmail SMTP",
      "cwe": "CWE-352",
      "title": "WordPress Gmail SMTP plugin <= 1.2.3.19 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57657"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-13322",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00094,
      "epss_percentile": 0.00688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Virtualization 4",
      "cwe": "CWE-770",
      "title": "Kubevirt: virt-handler-rhel9: kubevirt: unbounded virtio-serial readline in virt-handler causes oom denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13322"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-45256",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00092,
      "epss_percentile": 0.00591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeBSD",
      "product": "FreeBSD",
      "cwe": "CWE-269",
      "title": "Missing permission check in thr_kill2(2)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45256"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-53323",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0009,
      "epss_percentile": 0.00527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "net: dsa: remove redundant netdev_lock_ops() from conduit ethtool ops",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53323"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-45407",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00089,
      "epss_percentile": 0.00483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dokku",
      "product": "dokku",
      "cwe": "CWE-522",
      "title": "Dokku: Git Credentials in .netrc Stored World-Readable Due to Premature touch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45407"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2024-23581",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00066,
      "epss_percentile": 0.00024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Traveler for Microsoft Outlook",
      "cwe": "CWE-347",
      "title": "HCL Traveler for Microsoft Outlook (HTMO) is susceptible to an application modification vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23581"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-12411",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-12411 (Canonical lxd). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-28385",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-28385 (Canonical lxd). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45807",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45807 (kestra-io kestra). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47204",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47204 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47205",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47205 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47207",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47207 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47220",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47220 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47221",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47221 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47775",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47775 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47778",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47778 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48042",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48042 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48044",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48044 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48090",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48090 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48743",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48743 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48770",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48770 (notepad-plus-plus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48778",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48778 (notepad-plus-plus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48800",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48800 (notepad-plus-plus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49869",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49869 (kestra-io kestra). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49984",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49984 (kestra-io kestra). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50132",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50132 (budibase). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50136",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50136 (budibase). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50137",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50137 (budibase). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50765",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50765. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50766",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50766. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50767",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50767. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-52884",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-52884 (notepad-plus-plus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-52885",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-52885 (notepad-plus-plus). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-53576",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-53576 (kestra-io kestra). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-53577",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-53577 (kestra-io kestra). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54350",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54350 (budibase). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54351",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54351 (budibase). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54352",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54352 (budibase). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54353",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54353 (budibase). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55069",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55069 (kestra-io kestra). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55686",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55686 (podman-container-tools podman). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56876",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56876 (max-mapper extract-zip). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57920",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57920 (Peplink InControl). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-9639",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-9639 (Canonical LXD). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-9640",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-9640 (Canonical LXD). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
