{
  "day": "2026-06-29",
  "boundary": "UTC calendar day",
  "published_count": 232,
  "by_severity": {
    "CRITICAL": 11,
    "HIGH": 76,
    "MEDIUM": 101,
    "LOW": 44
  },
  "kev_count": 1,
  "exploit_reference_count": 6,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-48558",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.11484,
      "epss_percentile": 0.95664,
      "kev": true,
      "kev_due_at": "2026-07-02",
      "vendor": "SimpleHelp",
      "product": "SimpleHelp",
      "cwe": "CWE-347",
      "title": "SimpleHelp Authentication Bypass via Missing OIDC JWT Signature Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48558"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-49049",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.28307,
      "epss_percentile": 0.97964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "Helix3 extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated access to Helix3 template ajax handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49049"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-50229",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.04249,
      "epss_percentile": 0.90245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-80",
      "title": "Apache Tomcat: XSS in number guess example",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50229"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-56782",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.03344,
      "epss_percentile": 0.87688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gorse-io",
      "product": "gorse",
      "cwe": "CWE-306",
      "title": "Gorse - Unauthenticated Database Dump and Restore via /api/dump and /api/restore Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56782"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-13545",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.03231,
      "epss_percentile": 0.87247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DCS-935L",
      "cwe": "CWE-77",
      "title": "D-Link DCS-935L POST Parameter setconf.cgi sub_400E40 os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13545"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-55957",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.02863,
      "epss_percentile": 0.85651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-304",
      "title": "Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55957"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-55956",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01531,
      "epss_percentile": 0.72741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-285",
      "title": "Apache Tomcat: Security constraints for default servlet ignored method",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55956"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-58000",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01401,
      "epss_percentile": 0.70337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openwrt",
      "product": "luci-proto-openvpn",
      "cwe": "CWE-78",
      "title": "luci-proto-openvpn - Command Injection via cl_meta Parameter in generateKey",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58000"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-13538",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01306,
      "epss_percentile": 0.68275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wavlink",
      "product": "WL-NU516U1-A",
      "cwe": "CWE-74",
      "title": "Wavlink WL-NU516U1-A POST Parameter wireless.cgi sub_401D68 command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13538"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-57999",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01179,
      "epss_percentile": 0.65167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openwrt",
      "product": "luci-app-tailscale-community",
      "cwe": "CWE-78",
      "title": "luci-app-tailscale-community - Command Injection via tailscale.do_login RPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57999"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-13560",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01158,
      "epss_percentile": 0.64553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7478APC",
      "cwe": "CWE-77",
      "title": "Edimax EW-7478APC POST Request formAccept os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13560"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-13561",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01158,
      "epss_percentile": 0.64552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7478APC",
      "cwe": "CWE-77",
      "title": "Edimax EW-7478APC POST Request formiNICbasic os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13561"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-13581",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01158,
      "epss_percentile": 0.64552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7478APC",
      "cwe": "CWE-77",
      "title": "Edimax EW-7478APC POST Request formStaDrvSetup os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13581"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-34594",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01092,
      "epss_percentile": 0.6277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify: Authenticated Remote Code Execution via Command Injection in Destination Network Management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34594"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-39868",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00958,
      "epss_percentile": 0.58701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-20",
      "title": "This issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39868"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-8023",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00912,
      "epss_percentile": 0.57243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-22",
      "title": "Path traversal in Zephyr HTTP server static-filesystem resource handler allows unauthenticated remote arbitrary file read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8023"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-43715",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00891,
      "epss_percentile": 0.56619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-416",
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43715"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-43725",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00829,
      "epss_percentile": 0.54684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-20",
      "title": "The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43725"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-9105",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00805,
      "epss_percentile": 0.53928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "TL-WR841N v14",
      "cwe": "CWE-787",
      "title": "Authenticated Stack-Based Buffer Overflow in TP-Link TL-WR841N Web Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9105"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-36848",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00695,
      "epss_percentile": 0.50167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36848"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-43707",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00686,
      "epss_percentile": 0.49843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-119",
      "title": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43707"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-43745",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00679,
      "epss_percentile": 0.49563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43745"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-40521",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00627,
      "epss_percentile": 0.47367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FrontAccounting",
      "product": "FrontAccounting",
      "cwe": "CWE-22",
      "title": "FrontAccounting < 2.4.20 Path Traversal RCE via attachment upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40521"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-43716",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00598,
      "epss_percentile": 0.46019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43716"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-53404",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0058,
      "epss_percentile": 0.45161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-670",
      "title": "Apache Tomcat: Bad ornext processing in RewriteValve",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53404"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-43720",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00556,
      "epss_percentile": 0.43972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-416",
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43720"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-55607",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00552,
      "epss_percentile": 0.43755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "anthropics",
      "product": "claude-code",
      "cwe": "CWE-22",
      "title": "Claude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55607"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-55276",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00543,
      "epss_percentile": 0.43282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-670",
      "title": "Apache Tomcat: Logged effective web.xml is incomplete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55276"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-34597",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00526,
      "epss_percentile": 0.42339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify: Authenticated Host RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34597"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-53434",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00525,
      "epss_percentile": 0.42285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-390",
      "title": "Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53434"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-43701",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.005,
      "epss_percentile": 0.40789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-284",
      "title": "The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to process restricted web content outside the sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43701"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-43713",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00481,
      "epss_percentile": 0.39605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-284",
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Visiting a website may leak sensitive data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43713"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-51219",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00477,
      "epss_percentile": 0.39331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows attackers to cause a Denial of Service (DoS) via a crafted payload.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51219"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-13763",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00473,
      "epss_percentile": 0.39121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "AWS Application Load Balancer",
      "cwe": "CWE-444",
      "title": "HTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load Balancer with AWS WAF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13763"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-37637",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00471,
      "epss_percentile": 0.38901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37637"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-55955",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00467,
      "epss_percentile": 0.3867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-287",
      "title": "Apache Tomcat: EncryptInterceptor not protected against replay attacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55955"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-13517",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "JD12L",
      "cwe": "CWE-119",
      "title": "Tenda JD12L WifiBasicSet formWifiBasicSet stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13517"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-13518",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "JD12L",
      "cwe": "CWE-119",
      "title": "Tenda JD12L addressNat fromAddressNat stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13518"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-13519",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "JD12L",
      "cwe": "CWE-119",
      "title": "Tenda JD12L NatStaticSetting fromNatStaticSetting stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13519"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-13539",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wavlink",
      "product": "WL-NU516U1-A",
      "cwe": "CWE-119",
      "title": "Wavlink WL-NU516U1-A POST Parameter wireless.cgi sub_407504 stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13539"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-56018",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00459,
      "epss_percentile": 0.38191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GTERMARS",
      "product": "JavaScript::Minifier::XS",
      "cwe": "CWE-400",
      "title": "JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory growth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56018"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-43705",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00458,
      "epss_percentile": 0.38083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-843",
      "title": "A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43705"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-13582",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00455,
      "epss_percentile": 0.3789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7478APC",
      "cwe": "CWE-119",
      "title": "Edimax EW-7478APC POST Request formUSBAccount buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13582"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-13528",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00447,
      "epss_percentile": 0.37396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YunaiV",
      "product": "ruoyi-vue-pro",
      "cwe": "CWE-22",
      "title": "YunaiV/zhijiantianya ruoyi-vue-pro AppFileController File Upload Endpoint FileServiceImpl.java generateUploadPath path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13528"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-13562",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.37225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7478APC",
      "cwe": "CWE-119",
      "title": "Edimax EW-7478APC POST Request formiNICSiteSurvey buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13562"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-13563",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.37226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7478APC",
      "cwe": "CWE-119",
      "title": "Edimax EW-7478APC POST Request formL2TPSetup stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13563"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-13564",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.37225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7478APC",
      "cwe": "CWE-119",
      "title": "Edimax EW-7478APC POST Request formPPPoESetup stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13564"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-13580",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.37225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7478APC",
      "cwe": "CWE-119",
      "title": "Edimax EW-7478APC POST Request formQoS buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13580"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-13583",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.37224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Edimax",
      "product": "EW-7478APC",
      "cwe": "CWE-119",
      "title": "Edimax EW-7478APC POST Request formUSBFolder buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13583"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-13762",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "Amazon CloudFront",
      "cwe": "CWE-444",
      "title": "HTTP/2 Stream Parser Confusion Body-Inspection Bypass in Amazon CloudFront with AWS WAF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13762"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-43718",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00437,
      "epss_percentile": 0.36558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-121",
      "title": "A stack overflow was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43718"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-43721",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00437,
      "epss_percentile": 0.36592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-732",
      "title": "This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to silently hijack clipboard data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43721"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-43732",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00436,
      "epss_percentile": 0.36541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-22",
      "title": "A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may disclose sensitive user information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43732"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-25707",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00421,
      "epss_percentile": 0.35318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "libzypp",
      "cwe": "CWE-23",
      "title": "Handcrafted repo metadata may cause arbitrary local files to be overwritten by libzypp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25707"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-13587",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00419,
      "epss_percentile": 0.35149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seladb",
      "product": "PcapPlusPlus",
      "cwe": "CWE-119",
      "title": "seladb PcapPlusPlus LightPcapNg light_pcapng.c parse_by_block_type heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13587"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-13165",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00418,
      "epss_percentile": 0.35087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Krajowa Izba Rozliczeniowa",
      "product": "SzafirHost",
      "cwe": "CWE-434",
      "title": "Remote Code Execution in SzafirHost",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13165"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-41052",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00414,
      "epss_percentile": 0.34659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-305",
      "title": "Rancher Privilege Escalation from Project Owner to Host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41052"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-51218",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00409,
      "epss_percentile": 0.34267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-122",
      "title": "A heap buffer overflow in the TS7Worker::PerformFunctionWrite() function (/core/s7_server.cpp) of snap7 v1.4.3 allows attackers to cause a Denial of Service (DoS) via a crafted packet.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51218"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-53427",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00405,
      "epss_percentile": 0.33906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "leandrocp",
      "product": "mdex",
      "cwe": "CWE-79",
      "title": "Cross-site scripting in MDEx via unescaped highlight_lines_class code-fence attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53427"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-43703",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00404,
      "epss_percentile": 0.33859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-125",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43703"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-43676",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00395,
      "epss_percentile": 0.32898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-125",
      "title": "An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43676"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-13589",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00394,
      "epss_percentile": 0.32727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seladb",
      "product": "PcapPlusPlus",
      "cwe": "CWE-119",
      "title": "seladb PcapPlusPlus Telnet Subnegotiation Packet TelnetLayer.cpp getSubCommand heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13589"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-13590",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00394,
      "epss_percentile": 0.32727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seladb",
      "product": "PcapPlusPlus",
      "cwe": "CWE-119",
      "title": "seladb PcapPlusPlus Modbus Protocol ModbusLayer.h getLength heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13590"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-43742",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00393,
      "epss_percentile": 0.32638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-416",
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43742"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-56017",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0039,
      "epss_percentile": 0.32359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GTERMARS",
      "product": "JavaScript::Minifier::XS",
      "cwe": "CWE-125",
      "title": "JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful token of the input is a slash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56017"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-13676",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fast-uri",
      "product": "fast-uri",
      "cwe": "CWE-436",
      "title": "fast-uri vulnerable to host confusion via failed IDN canonicalization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13676"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-13546",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00383,
      "epss_percentile": 0.31651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Feehi",
      "product": "CMS",
      "cwe": "CWE-287",
      "title": "Feehi CMS REST API Endpoint articles missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13546"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-13571",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00383,
      "epss_percentile": 0.31659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple Food Ordering System",
      "cwe": "CWE-840",
      "title": "SourceCodester Simple Food Ordering System cart.php logic error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13571"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-43704",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00382,
      "epss_percentile": 0.31488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-416",
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious web extension may be able to cause an unexpected process crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43704"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-11720",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00381,
      "epss_percentile": 0.31445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "MCP Toolbox for Databases (googleapis/mcp-toolbox)",
      "cwe": "CWE-22",
      "title": "Path Traversal in googleapis/mcp-toolbox HTTP Tool URL Builder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11720"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-13588",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0038,
      "epss_percentile": 0.31287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seladb",
      "product": "PcapPlusPlus",
      "cwe": "CWE-119",
      "title": "seladb PcapPlusPlus TLS Hello SSLHandshake.cpp getHandshakeVersion heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13588"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-13749",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00378,
      "epss_percentile": 0.31061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Snowflake",
      "product": "Snowflake CLI",
      "cwe": "CWE-94",
      "title": "Snowflake CLI Arbitrary Code Execution via Snowpark Annotation Processor Template Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13749"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-13592",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "liftoff-sr",
      "product": "CIPster",
      "cwe": "CWE-119",
      "title": "liftoff-sr CIPster EtherNet IP Message append out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13592"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-43708",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-20",
      "title": "The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may exfiltrate data cross-origin.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43708"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-43706",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00368,
      "epss_percentile": 0.30035,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-415",
      "title": "A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43706"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-56124",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shimosyan",
      "product": "phpUploader",
      "cwe": "CWE-359",
      "title": "phpUploader < 2.0.2 Unauthenticated Database Exposure via index model",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56124"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-13543",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00364,
      "epss_percentile": 0.29611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Documenso",
      "cwe": "CWE-287",
      "title": "Documenso Google OAuth Login handle-oauth-callback-url.ts improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13543"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-43740",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00362,
      "epss_percentile": 0.2946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may result in the disclosure of process memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43740"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-56285",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.29245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zedeus",
      "product": "nitter",
      "cwe": "CWE-918",
      "title": "Nitter - Server-Side Request Forgery in /video Media Proxy Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56285"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-43712",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0036,
      "epss_percentile": 0.2924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-125",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43712"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-51221",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "A buffer overflow in the Get_Attribute_List function of EIPStackGroup OpENer commit 76b95c allows attackers to cause a Denial of Service (DoS) via supplying a crafted Common Packet Format (CPF) packet.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51221"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-43727",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0035,
      "epss_percentile": 0.28172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-416",
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43727"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-57960",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.27022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HiEventsDev",
      "product": "Hi.Events",
      "cwe": "CWE-359",
      "title": "Hi.Events 1.9.0 - Unauthenticated Attendee PII Exposure via Check-in List short_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57960"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-41992",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00335,
      "epss_percentile": 0.26552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "gzip",
      "cwe": "CWE-126",
      "title": "Global Buffer Overflow in GNU gzip",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41992"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-57331",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00334,
      "epss_percentile": 0.26472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "videowhisper",
      "product": "Paid Videochat Turnkey Site",
      "cwe": "CWE-22",
      "title": "WordPress Paid Videochat Turnkey Site plugin <= 7.4.8 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57331"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-13744",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Snowflake",
      "product": "Snowflake CLI",
      "cwe": "CWE-89",
      "title": "Snowflake CLI SQL Injection Through Improper Neutralization of User-Controlled Input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13744"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-43746",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00315,
      "epss_percentile": 0.24348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-416",
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43746"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-7656",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.24043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-290",
      "title": "Broken IPv6 Neighbor Discovery input validation allows spoofed RA/NS/NA acceptance in Zephyr net stack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7656"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-54889",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0031,
      "epss_percentile": 0.23716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "leandrocp",
      "product": "mdex",
      "cwe": "CWE-79",
      "title": "Unsanitized URL schemes in MDEx Quill Delta output allow javascript: injection (XSS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54889"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-12616",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23544,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse CSI - PIA",
      "cwe": "CWE-117",
      "title": "The /v1/upload/sbom endpoint extracts the iss claim from the attacker-supplied JWT with signature verification disabled, then interpolates that string into three log statements before any validation gate. Because the configured log format (\"%(asctime)s - %(name)s - %(levelname)s - %(message)s\") renders newlines literally, an unauthenticated attacker can forge log records that are byte-for-byte indistinguishable from PIA's genuine \"Successfully authenticated project\" message. PIA is an authentication broker whose logs are explicitly relied upon for incident response (DESIGN.md §5.4 lists \"Token verifications\" and \"Errors\" as events to log), so the ability to plant fake auth-success entries directly undermines the audit trail the service exists to produce.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12616"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-43724",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-20",
      "title": "The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43724"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-43735",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-352",
      "title": "The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may exfiltrate data cross-origin.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43735"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-28979",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.003,
      "epss_percentile": 0.22603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-125",
      "title": "An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28979"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-13758",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00295,
      "epss_percentile": 0.22115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MIK",
      "product": "CryptX",
      "cwe": "CWE-208",
      "title": "CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt_done path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13758"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-57950",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.22039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yunai",
      "product": "ruoyi-vue-pro",
      "cwe": "CWE-863",
      "title": "ruoyi-vue-pro - Incorrect Permission Namespace in ErpSaleOrderController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57950"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-13522",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00293,
      "epss_percentile": 0.21944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Investintech",
      "product": "SlimPDFReader",
      "cwe": "CWE-119",
      "title": "Investintech SlimPDFReader PDF File SlimPDFReader.exe TeighaDo+0x25cde0 out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13522"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-13549",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00293,
      "epss_percentile": 0.21872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Complaint Management System",
      "cwe": "CWE-285",
      "title": "CodeAstro Complaint Management System Report Endpoint Report.php deletereport authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13549"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-12856",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Dev Spaces 3.29",
      "cwe": "CWE-88",
      "title": "Vscode-java: vscode: command injection vulnerability in the javadoc hover provider of the vscode-java extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12856"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-43699",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-416",
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43699"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-43734",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-416",
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43734"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-13553",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Hotel Management System",
      "cwe": "CWE-284",
      "title": "itsourcecode Online Hotel Management System controller.php add unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13553"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-13533",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.21187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "agentejo",
      "product": "Cockpit CMS",
      "cwe": "CWE-425",
      "title": "agentejo Cockpit CMS htaccess config.yaml YAMLLoad file access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13533"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-43709",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-416",
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43709"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-13536",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00284,
      "epss_percentile": 0.20993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GotoHTTP",
      "cwe": "CWE-79",
      "title": "GotoHTTP reg.12x cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13536"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-56783",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "parseablehq",
      "product": "parseable",
      "cwe": "CWE-522",
      "title": "Parseable < 2.9.2 - Cleartext Credential Exposure in Notification Target API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56783"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-13547",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hanwang",
      "product": "e-Face General Management Platform",
      "cwe": "CWE-284",
      "title": "Hanwang e-Face General Management Platform upload.do unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13547"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-13568",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Inventory Management System",
      "cwe": "CWE-266",
      "title": "SourceCodester Inventory Management System User Registration Endpoint users_handler.php access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13568"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-40523",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FrontAccounting",
      "product": "FrontAccounting",
      "cwe": "CWE-89",
      "title": "FrontAccounting < 2.4.20 SQL Injection via reporting/rep710.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40523"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-40524",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FrontAccounting",
      "product": "FrontAccounting",
      "cwe": "CWE-89",
      "title": "FrontAccounting < 2.4.20 SQL Injection via get_gl_transactions()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40524"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-13554",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.19737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Hotel Management System",
      "cwe": "CWE-79",
      "title": "itsourcecode Online Hotel Management System POST Request controller.php add cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13554"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-13556",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.19737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Hotel Management System",
      "cwe": "CWE-79",
      "title": "itsourcecode Online Hotel Management System POST Request controller.php edit cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13556"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-13557",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.19738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Hotel Management System",
      "cwe": "CWE-79",
      "title": "itsourcecode Online Hotel Management System POST Request controller.php add cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13557"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-13567",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00273,
      "epss_percentile": 0.1974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Online Music Site",
      "cwe": "CWE-79",
      "title": "code-projects Online Music Site POST Request Feedback.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13567"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-57946",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iv-org",
      "product": "Invidious",
      "cwe": "CWE-862",
      "title": "Invidious - Private Playlist Disclosure via Unauthenticated RSS Feed Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57946"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-13521",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System preview5.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13521"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-56780",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.18571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "modoboa",
      "product": "modoboa",
      "cwe": "CWE-639",
      "title": "Modoboa < 2.9.0 - Insecure Direct Object Reference in Account Password Change API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56780"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-13524",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00264,
      "epss_percentile": 0.18407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CherryHQ",
      "product": "cherry-studio",
      "cwe": "CWE-266",
      "title": "CherryHQ cherry-studio MCP OAuth Local Callback Server callback.ts improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13524"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-13526",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System edit_class.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13526"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-13527",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System preview4.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13527"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-13550",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Baptism Information Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Baptism Information Management System delbaptism.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13550"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-13551",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Baptism Information Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Baptism Information Management System editBaptism.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13551"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-13552",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Hotel Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Hotel Management System controller.php edit sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13552"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-13555",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Online Hotel Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Online Hotel Management System controller.php add sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13555"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-13559",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Real State Services",
      "cwe": "CWE-74",
      "title": "code-projects Real State Services single-list_sale.php add sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13559"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-13565",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System edit_class1.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13565"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-13566",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.1829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Class and Exam Timetabling System",
      "cwe": "CWE-74",
      "title": "SourceCodester Class and Exam Timetabling System preview3.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13566"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-57953",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "its-a-feature",
      "product": "Mythic",
      "cwe": "CWE-863",
      "title": "Mythic < 3.4.0.60 - Unauthorized Automation Workflow Modification via eventing_import_automatic_webhook Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57953"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-43731",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-416",
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to memory corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43731"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-43722",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-20",
      "title": "The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2. An app may be able to leak sensitive kernel state.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43722"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-12912",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-122",
      "title": "Libtiff: libtiff: heap-based buffer overflow via crafted pixarlog-compressed tiff image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12912"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-57346",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17549,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Epiphyt",
      "product": "Embed Privacy",
      "cwe": "CWE-22",
      "title": "WordPress Embed Privacy plugin <= 1.12.3 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57346"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-57332",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Swings",
      "product": "Wallet System for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Wallet System for WooCommerce plugin <= 2.7.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57332"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-13437",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "PowerShell Universal",
      "cwe": "CWE-201",
      "title": "Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privileged authentication tokens via App Tokens serialized in plaintext in job API responses.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13437"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-57498",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00253,
      "epss_percentile": 0.1709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-639",
      "title": "Coolify Cross-Team IDOR: Livewire Components Accept Unscoped server_id and destination_uuid — Deploy to Other Teams' Servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57498"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-57341",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Colissimo",
      "product": "Colissimo Officiel : Méthodes de livraison pour WooCommerce",
      "cwe": "CWE-639",
      "title": "WordPress Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin <= 2.9.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57341"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-39872",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39872"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-43663",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43663"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-57957",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0025,
      "epss_percentile": 0.16622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "papermark",
      "product": "papermark",
      "cwe": "CWE-942",
      "title": "Papermark 0.22.0 - CORS Misconfiguration in Viewer Upload Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57957"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-57327",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.1656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mainwp",
      "product": "MainWP",
      "cwe": "CWE-862",
      "title": "WordPress MainWP plugin <= 6.1.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57327"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-57951",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "its-a-feature",
      "product": "Mythic",
      "cwe": "CWE-863",
      "title": "Mythic < 3.4.0.60 - Broken Permission Filter in payload_build_step Table",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57951"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-43700",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.15966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-346",
      "title": "A cross-origin issue was addressed with improved tracking of security origins. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may disclose sensitive user information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43700"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-43726",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-416",
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected process crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43726"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-57947",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pinpoint-apm",
      "product": "pinpoint",
      "cwe": "CWE-918",
      "title": "Pinpoint - Server-Side Request Forgery via Alarm Webhook Registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57947"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-13529",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00239,
      "epss_percentile": 0.15273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "YzmCMS",
      "cwe": "CWE-74",
      "title": "YzmCMS index.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13529"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-43717",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-416",
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43717"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-57955",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SigNoz",
      "product": "signoz",
      "cwe": "CWE-89",
      "title": "SigNoz 0.130.1 - SQL Injection in Alert History Endpoints via Rule ID Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57955"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-41896",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-287",
      "title": "Coolify: Unauthenticated Deployment Trigger via Webhook HMAC Bypass with Null Secret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41896"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-57949",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yunai",
      "product": "ruoyi-vue-pro",
      "cwe": "CWE-862",
      "title": "ruoyi-vue-pro - Missing Authorization in CRM Follow-up Record GET Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57949"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-56781",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "teableio",
      "product": "teable",
      "cwe": "CWE-639",
      "title": "Teable - Unauthenticated Hidden Field Disclosure via Projection Parameter Override",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56781"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-13593",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GTERMARS",
      "product": "CSS::Minifier::XS",
      "cwe": "CWE-401",
      "title": "CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13593"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-57335",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.14001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ads WPQuads",
      "product": "Ads by WPQuads",
      "cwe": "CWE-862",
      "title": "WordPress Ads by WPQuads plugin <= 3.0.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57335"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2025-7386",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi",
      "product": "Hitachi Virtual Storage Platform 5100, 5200, 5500, 5600, 5100H, 5200H, 5500H, 5600H, VX8",
      "cwe": "CWE-522",
      "title": "Information exposure vulnerability in Hitachi Storage Navigator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7386"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-13540",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.13639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GitBucket",
      "cwe": "CWE-918",
      "title": "GitBucket RepositoryCreationService.scala Git.cloneRepository.setURI server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13540"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-13544",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00214,
      "epss_percentile": 0.12115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Feehi",
      "product": "CMS",
      "cwe": "CWE-266",
      "title": "Feehi CMS API users access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13544"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-57956",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SigNoz",
      "product": "signoz",
      "cwe": "CWE-639",
      "title": "SigNoz < 0.133.0 - Cross-Organization Insecure Direct Object Reference in Alert Rules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57956"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-34592",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.1181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-639",
      "title": "Coolify: Cross-Team IDOR via Unscoped Server and Project Lookups Exposes SSH Keys and Infrastructure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34592"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-57943",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LibrePhotos",
      "product": "librephotos",
      "cwe": "CWE-639",
      "title": "LibrePhotos < 1.0.0 - Insecure Direct Object Reference in SetPhotosShared Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57943"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-13569",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.0021,
      "epss_percentile": 0.11503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weng-xianhu",
      "product": "EyouCMS",
      "cwe": "CWE-74",
      "title": "weng-xianhu EyouCMS API index.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13569"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-10647",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-667",
      "title": "Deadlock denial of service in USB CDC-NCM device class on TX enqueue failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10647"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-57328",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Strategy11 Team",
      "product": "Business Directory",
      "cwe": "CWE-79",
      "title": "WordPress Business Directory plugin <= 6.4.22 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57328"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-57329",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WOOCOMMERCE DESIGNER PRO",
      "product": "WooCommerce Designer Pro",
      "cwe": "CWE-79",
      "title": "WordPress WooCommerce Designer Pro plugin <= 1.9.34 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57329"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-10083",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.10771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "APCu Manager",
      "cwe": null,
      "title": "APCu Manager < 4.5.0 - Unauthenticated Stored XSS via Cache Key Pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10083"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-13532",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.10763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System departmentDoctor.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13532"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-13535",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.10764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Human Resource Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Human Resource Management System View Endpoint Employee_model.php GetFileInfo sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13535"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-13520",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System Appointment appointmentapproval.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13520"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-13525",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Human Resource Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Human Resource Management System Update_Earn_Leave Endpoint Employee_model.php emselectByCode sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13525"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-13530",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System Appointment appointmentdetail.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13530"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-13531",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System department.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13531"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-13541",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System doctorchangepassword.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13541"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-13542",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System doctorprofile.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13542"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-13548",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System doctortimings.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13548"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-13572",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System insertbillingrecord.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13572"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-13578",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System patientdetail.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13578"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-13579",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System patientchangepassword.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13579"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2025-2902",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi",
      "product": "Hitachi Virtual Storage Platform E390, E590, E790, E990, E1090, E390H, E590H, E790H, E1090H",
      "cwe": "CWE-862",
      "title": "Improper Authorization Vulnerability of Maintenance Utility in Hitachi Virtual Storage Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-2902"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-13558",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.10032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Complaint Management System",
      "cwe": "CWE-79",
      "title": "CodeAstro Complaint Management System Report addreport cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13558"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-13534",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.10135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CherryHQ",
      "product": "cherry-studio",
      "cwe": "CWE-285",
      "title": "CherryHQ cherry-studio CherryIN Preload API MemoryService.ts sha256 authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13534"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-13591",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.10019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DeepMyst",
      "product": "Mysti",
      "cwe": "CWE-266",
      "title": "DeepMyst Mysti Contact Tracking ChannelBridge.ts _isTrackedConversation improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13591"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-57959",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00193,
      "epss_percentile": 0.09324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HiEventsDev",
      "product": "Hi.Events",
      "cwe": "CWE-367",
      "title": "Hi.Events 1.9.0 - Promo Code Max-Usage Bypass via Asynchronous Job Race Condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57959"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-57942",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LibreTranslate",
      "product": "LibreTranslate",
      "cwe": "CWE-348",
      "title": "LibreTranslate - IP Spoofing via X-Forwarded-For Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57942"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-57334",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weDevs",
      "product": "WP User Frontend",
      "cwe": "CWE-862",
      "title": "WordPress WP User Frontend plugin <= 4.3.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57334"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-57339",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Strategy11 Team",
      "product": "Business Directory",
      "cwe": "CWE-862",
      "title": "WordPress Business Directory plugin <= 6.4.23 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57339"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-57340",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.0908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shohei.tanaka",
      "product": "Japanized For WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Japanized For WooCommerce plugin <= 2.9.12 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57340"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-13570",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00191,
      "epss_percentile": 0.09118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Inventory Management System",
      "cwe": "CWE-79",
      "title": "SourceCodester Inventory Management System User Registration Endpoint users_handler.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13570"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-57945",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.08961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "photoprism",
      "product": "photoprism",
      "cwe": "CWE-639",
      "title": "PhotoPrism - Unauthorized User Profile Modification via PUT /api/v1/users/{uid} Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57945"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-13752",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.08781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Snowflake",
      "product": "Snowflake CLI",
      "cwe": "CWE-89",
      "title": "Snowflake CLI SQL Injection Through Improper Neutralization of Parameters in Secret Creation and SPCS Service Log Commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13752"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-31016",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-352",
      "title": "Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the IdentityServer account profile endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31016"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-56457",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "HCL DevOps Deploy / HCL Launch",
      "cwe": "CWE-532",
      "title": "HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56457"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-57326",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Strategy11 Team",
      "product": "Business Directory",
      "cwe": "CWE-79",
      "title": "WordPress Business Directory plugin <= 6.4.22 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57326"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-57676",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Matteo Manna",
      "product": "Simple User Avatar",
      "cwe": "CWE-639",
      "title": "WordPress Simple User Avatar plugin <= 4.9 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57676"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-57320",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RealMag777",
      "product": "BEAR",
      "cwe": "CWE-79",
      "title": "WordPress BEAR plugin <= 1.1.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57320"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-57952",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "its-a-feature",
      "product": "Mythic",
      "cwe": "CWE-862",
      "title": "Mythic < 3.4.0.60 - Unauthorized C2 Profile Configuration Access via Unverified Payload UUID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57952"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-54888",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "leandrocp",
      "product": "mdex",
      "cwe": "CWE-674",
      "title": "Uncontrolled recursion over deeply nested Markdown crashes the BEAM in mdex",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54888"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-57954",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yahoo",
      "product": "elide",
      "cwe": "CWE-862",
      "title": "Elide 7.1.17 - Permission Bypass in Sort Expression Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57954"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-57958",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "inovector",
      "product": "mixpost",
      "cwe": "CWE-79",
      "title": "Mixpost 2.6.0 - Reflected XSS via OAuth Callback Error Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57958"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-9267",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse tinydtls",
      "cwe": "CWE-125",
      "title": "Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in the check_server_certificate() function that allows unauthenticated attackers to trigger reads beyond valid buffer boundaries by crafting a Certificate handshake message with a specific fragment_length value. Attackers can exploit missing buffer length validation before uint24 reads, memcmp, and memcpy operations during DTLS epoch 0 on both client and server paths to cause denial of service on memory-constrained devices.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9267"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-57330",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.0639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stylemix",
      "product": "MasterStudy LMS",
      "cwe": "CWE-79",
      "title": "WordPress MasterStudy LMS plugin <= 3.7.27 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57330"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-13537",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00162,
      "epss_percentile": 0.05897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Human Resource Management System",
      "cwe": "CWE-352",
      "title": "CodeAstro Human Resource Management System cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13537"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-55844",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00161,
      "epss_percentile": 0.05748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "home-assistant",
      "product": "core",
      "cwe": "CWE-319",
      "title": "Home Assistant: iOS Companion App ignores internal SSID allowlist for connections – possible leak of access token and sensor data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55844"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-54369",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00153,
      "epss_percentile": 0.04964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "acl project",
      "product": "acl",
      "cwe": "CWE-59",
      "title": "acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54369"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-10648",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-476",
      "title": "NULL-pointer dereference in MCUmgr serial/console SMP transport on buffer-pool exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10648"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-40522",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FrontAccounting",
      "product": "FrontAccounting",
      "cwe": "CWE-89",
      "title": "FrontAccounting < 2.4.20 SQL Injection via rep601.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40522"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-13757",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-674",
      "title": "P11-kit: stack exhaustion via unbounded recursion in rpc attribute parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13757"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-57997",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strapi",
      "product": "strapi",
      "cwe": "CWE-327",
      "title": "Strapi users-permissions - JWT Algorithm Confusion via Missing Algorithm Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57997"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-57333",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spencer Haws",
      "product": "Link Whisper Free",
      "cwe": "CWE-79",
      "title": "WordPress Link Whisper Free plugin <= 0.9.4 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57333"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-57336",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Astoundify",
      "product": "Jobify",
      "cwe": "CWE-79",
      "title": "WordPress Jobify theme <= 4.3.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57336"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-57337",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PluginOps",
      "product": "Landing Page Builder",
      "cwe": "CWE-79",
      "title": "WordPress Landing Page Builder plugin <= 1.5.3.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57337"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-57338",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.0399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repute InfoSystems",
      "product": "ARForms",
      "cwe": "CWE-79",
      "title": "WordPress ARForms plugin <= 7.1.2 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57338"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-53428",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.04013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "leandrocp",
      "product": "mdex",
      "cwe": "CWE-789",
      "title": "Unbounded memory allocation in highlight_lines range expansion in mdex",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53428"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-13748",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Snowflake",
      "product": "Snowflake CLI",
      "cwe": "CWE-22",
      "title": "Snowflake CLI Arbitrary Local File Read and Exfiltration Through Improper File Path Restriction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13748"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-13601",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 8",
      "cwe": "CWE-693",
      "title": "Yelp: yelp-xsl: overly permissive content security policy in yelp allows host file disclosure from flatpak applications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13601"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-54371",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "attr project",
      "product": "attr",
      "cwe": "CWE-59",
      "title": "attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54371"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-57919",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.03074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-276",
      "title": "PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\\\.\\pipe\\PBackupVSS) with a DACL that grants GENERIC_READ and GENERIC_WRITE permissions to all authenticated users. A low-privileged local attacker can connect to this pipe and send crafted IPC messages to trigger execution of arbitrary commands with SYSTEM privileges via an untrusted search path. This allows privilege escalation by placing a malicious shadow.exe in a controlled working directory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57919"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-13746",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Snowflake",
      "product": "Snowflake CLI",
      "cwe": "CWE-89",
      "title": "Snowflake CLI SQL Injection Through Improper Neutralization of Local CLI Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13746"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-53426",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "leandrocp",
      "product": "mdex",
      "cwe": "CWE-770",
      "title": "Atom-table exhaustion denial-of-service via JSON parse_document in MDEx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53426"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-57948",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pinpoint-apm",
      "product": "pinpoint",
      "cwe": "CWE-614",
      "title": "Pinpoint - Insecure Session Cookie Attributes in pinpointJwt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57948"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-53429",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "leandrocp",
      "product": "mdex",
      "cwe": "CWE-401",
      "title": "Unbounded native memory leak in mdex escaped-tag rendering enables unauthenticated denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53429"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-53325",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "agp/amd64: Fix broken error propagation in agp_amd64_probe()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53325"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-57966",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-22",
      "title": "Spice-vdagent: path traversal in file transfer via unsanitized filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57966"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-13751",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00118,
      "epss_percentile": 0.01993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Snowflake",
      "product": "Snowflake CLI",
      "cwe": "CWE-829",
      "title": "Snowflake CLI Server-Side Request Forgery via Arbitrary URL Fetch in !source/!load",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13751"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-46406",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.0201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "anthropics",
      "product": "claude-code",
      "cwe": "CWE-59",
      "title": "Claude Code: Insecure Temporary File in /copy Command Enables Response Disclosure and Symlink-Based File Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46406"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-41991",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00117,
      "epss_percentile": 0.01962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "gzip",
      "cwe": "CWE-377",
      "title": "Predictable Temporary File in GNU gzip",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41991"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-57965",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-190",
      "title": "Spice-vdagent: integer overflow in udscs_write() leading to heap buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57965"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-43743",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-362",
      "title": "A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43743"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-13523",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00112,
      "epss_percentile": 0.01602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-404",
      "title": "GPAC ISOBMFF base_encoding.c data amplification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13523"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-13595",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0011,
      "epss_percentile": 0.01449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-416",
      "title": "Util-linux: util-linux: heap use-after-free in libblkid nested partition probing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13595"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-13750",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Snowflake",
      "product": "Snowflake CLI",
      "cwe": "CWE-532",
      "title": "Snowflake CLI Sensitive Credential Exposure Through Debug Logging",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13750"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-9676",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "F4 Post Tree",
      "cwe": null,
      "title": "f4 Post Tree < 2.0.5 - Subscriber+ Arbitrary Post Parent/Menu Order Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9676"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-54370",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00088,
      "epss_percentile": 0.00456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "acl project",
      "product": "acl",
      "cwe": "CWE-367",
      "title": "acl < 2.4.0 TOCTOU Symlink Traversal via getfacl/setfacl/chacl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54370"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-22078",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00085,
      "epss_percentile": 0.00378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OPPO",
      "product": "O+ Connect",
      "cwe": "CWE-266",
      "title": "O+ Connect's lack of authentication for IPC channels led to a local privilege escalation vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22078"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-13742",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00083,
      "epss_percentile": 0.00293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Honeywell Technologies",
      "product": "IQ MultiAccess",
      "cwe": "CWE-367",
      "title": "Lack of signature verification before execution of downloaded content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13742"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2025-0824",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00083,
      "epss_percentile": 0.00288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi",
      "product": "Hitachi Virtual Storage Platform One Block 23, 24, 26, 28",
      "cwe": "CWE-347",
      "title": "lack of validation for firmware update in Hitachi Virtual Storage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-0824"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10647",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10647 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10648",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10648 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-36848",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-36848. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-7656",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-7656 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-8023",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-8023 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-12569",
      "detail": "DUE DATE PASSED — CVE-2026-12569 (PTC Windchill PDMLink). CISA remediation deadline was June 28, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-20230",
      "detail": "DUE DATE PASSED — CVE-2026-20230 (Cisco Unified Communications Manager). CISA remediation deadline was June 28, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
