{
  "day": "2026-06-30",
  "boundary": "UTC calendar day",
  "published_count": 641,
  "by_severity": {
    "CRITICAL": 97,
    "HIGH": 200,
    "MEDIUM": 327,
    "LOW": 17
  },
  "kev_count": 0,
  "exploit_reference_count": 11,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-8451",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.15654,
      "epss_percentile": 0.96571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NetScaler",
      "product": "ADC",
      "cwe": "CWE-125",
      "title": "Insufficient input validation leading to memory overread",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8451"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-58138",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.07183,
      "epss_percentile": 0.93783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "conductor-oss",
      "product": "conductor",
      "cwe": "CWE-94",
      "title": "Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58138"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-48276",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.05055,
      "epss_percentile": 0.9162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-434",
      "title": "ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48276"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-48313",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.04164,
      "epss_percentile": 0.90066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-22",
      "title": "ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48313"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-13773",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.03415,
      "epss_percentile": 0.87927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Extreme Scale",
      "cwe": "CWE-918",
      "title": "IBM WebSphere eXtreme Scale is affected by server side request forgery when ORB is used as Transport Protocol",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13773"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-56413",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.03155,
      "epss_percentile": 0.86925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StoneFly",
      "product": "Storage Concentrator",
      "cwe": "CWE-78",
      "title": "OS Command Injection in StoneFly Storage Concentrator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56413"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-56415",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.03148,
      "epss_percentile": 0.86893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stonefly",
      "product": "Storage Concentrator",
      "cwe": "CWE-78",
      "title": "OS Command Injection in StoneFly Storage Concentrator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56415"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-48277",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01817,
      "epss_percentile": 0.76964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-20",
      "title": "ColdFusion | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48277"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-48281",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01817,
      "epss_percentile": 0.76964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-20",
      "title": "ColdFusion | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48281"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-56700",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01683,
      "epss_percentile": 0.75113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grav",
      "product": "Grav",
      "cwe": "CWE-78",
      "title": "Grav - Multiple Remote Code Execution Vulnerabilities via Unsafe Unserialize and Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56700"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-48283",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01553,
      "epss_percentile": 0.7314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-434",
      "title": "ColdFusion | Unrestricted Upload of File with Dangerous Type (CWE-434)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48283"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-56808",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0155,
      "epss_percentile": 0.73092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AVTECH Security Corporation",
      "product": "DGM3103SCT",
      "cwe": "CWE-78",
      "title": "DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead to arbitrary command execution with the root privilege by a user who can log in to the web management console of the affected product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56808"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-48315",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01454,
      "epss_percentile": 0.71347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-20",
      "title": "ColdFusion | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48315"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-53917",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01177,
      "epss_percentile": 0.6509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ActiveMQ",
      "cwe": "CWE-789",
      "title": "Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: Unbounded memory allocation in OpenWire property unmarshalling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53917"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-48285",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00939,
      "epss_percentile": 0.58138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-918",
      "title": "ColdFusion | Server-Side Request Forgery (SSRF) (CWE-918)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48285"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-54475",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00902,
      "epss_percentile": 0.56957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ActiveMQ Broker",
      "cwe": "CWE-862",
      "title": "Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Temporary destination ownership takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54475"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-48286",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00868,
      "epss_percentile": 0.55931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic (ACC)",
      "cwe": "CWE-863",
      "title": "Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48286"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-48307",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.008,
      "epss_percentile": 0.53716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-79",
      "title": "ColdFusion | Cross-site Scripting (Reflected XSS) (CWE-79)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48307"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-49877",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0078,
      "epss_percentile": 0.53097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ActiveMQ",
      "cwe": "CWE-285",
      "title": "Apache ActiveMQ: Authenticated web users retain admin access by default in the Web Console",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49877"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2025-71368",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00769,
      "epss_percentile": 0.52741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-502",
      "title": "picklescan - Arbitrary Code Execution via Undetected doctest.debug_script",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71368"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-58372",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00766,
      "epss_percentile": 0.52671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seaweedfs",
      "product": "seaweedfs",
      "cwe": "CWE-22",
      "title": "SeaweedFS < 4.34 - Cross-Bucket Object Deletion via DeleteObjects Request-Body Keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58372"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-58449",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00725,
      "epss_percentile": 0.51249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "neuml",
      "product": "txtai",
      "cwe": "CWE-94",
      "title": "txtai - Unauthenticated Remote Code Execution via Unsafe Reflection in API /reindex function Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58449"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-48314",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00712,
      "epss_percentile": 0.50772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-22",
      "title": "ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48314"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-49451",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00695,
      "epss_percentile": 0.5016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "OpenAPI.NET",
      "cwe": "CWE-674",
      "title": "Microsoft.OpenAPI: Circular schema references may terminate OpenAPI parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49451"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-56137",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00677,
      "epss_percentile": 0.49469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gotcha Gotcha Games Inc.",
      "product": "RPG MAKER MV",
      "cwe": "CWE-78",
      "title": "RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads a specially crafted save-file, arbitrary OS command may be executed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56137"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-11595",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00663,
      "epss_percentile": 0.48952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-22",
      "title": "IBM WebSphere Application Server is affected by a Path Traversal vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11595"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-27957",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00658,
      "epss_percentile": 0.48737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify: Authenticated RCE via command injection in CA certificate management feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27957"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-58116",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00643,
      "epss_percentile": 0.48085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hiyouga",
      "product": "LlamaFactory",
      "cwe": "CWE-94",
      "title": "LLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58116"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2025-71374",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00638,
      "epss_percentile": 0.4783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-502",
      "title": "picklescan - Arbitrary Code Execution via Undetected profile.Profile.run",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71374"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2025-71352",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00637,
      "epss_percentile": 0.47793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-693",
      "title": "picklescan - Remote Code Execution via Undetected trace.Trace.runctx in Pickle Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71352"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-58166",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00628,
      "epss_percentile": 0.47399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBMB",
      "product": "ChatDev",
      "cwe": "CWE-22",
      "title": "OpenBMB ChatDev - Unauthenticated Path Traversal in Upload Handler Allows Arbitrary File Write and Delete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58166"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2025-71363",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00585,
      "epss_percentile": 0.45384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-502",
      "title": "picklescan - Arbitrary Code Execution via Undetected cProfile.run in Pickle Deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71363"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-49432",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00577,
      "epss_percentile": 0.44994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ActiveMQ",
      "cwe": "CWE-20",
      "title": "Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: STOMP negative content-length enables denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49432"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-13967",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00574,
      "epss_percentile": 0.44862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Heap buffer overflow in V8 in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13967"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2025-71349",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00562,
      "epss_percentile": 0.4427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-502",
      "title": "picklescan - Arbitrary Code Execution via Undetected trace.Trace.run in Pickle Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71349"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-13787",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0056,
      "epss_percentile": 0.44173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13787"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2025-71355",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00552,
      "epss_percentile": 0.43785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Picklescan",
      "product": "Picklescan",
      "cwe": "CWE-184",
      "title": "Picklescan - Arbitrary Code Execution via Unsafe Numpy Function Detection Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71355"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-58370",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00546,
      "epss_percentile": 0.43436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "woodpecker-ci",
      "product": "woodpecker",
      "cwe": "CWE-290",
      "title": "Woodpecker < 3.15.0 - GitLab Approval Gate Bypass via Spoofable Commit Author Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58370"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-58016",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00545,
      "epss_percentile": 0.43399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "GLib",
      "cwe": "CWE-191",
      "title": "Glib: integer underflow in gio/gdbusintrospection.c via \"g_dbus_node_info_new_for_xml\"",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58016"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-10109",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00544,
      "epss_percentile": 0.43345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-94",
      "title": "IBM® Db2® is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10109"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-50734",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00544,
      "epss_percentile": 0.43347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ActiveMQ Client",
      "cwe": "CWE-789",
      "title": "Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire memory-allocation DoS during wire format negotiation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50734"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-53916",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00544,
      "epss_percentile": 0.43347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ActiveMQ",
      "cwe": "CWE-789",
      "title": "Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53916"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-11367",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00525,
      "epss_percentile": 0.423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "andrasweb",
      "product": "PixMagix – WordPress Image Editor",
      "cwe": "CWE-22",
      "title": "PixMagix <= 1.7.2 - Authenticated (Author+) Path Traversal in 'layers[].id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11367"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-13779",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00523,
      "epss_percentile": 0.4216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chromoting in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13779"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-13898",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0051,
      "epss_percentile": 0.41333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Cast Receiver in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13898"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-13899",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0051,
      "epss_percentile": 0.41333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in HTML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13899"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-13788",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00502,
      "epss_percentile": 0.40891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Fullscreen in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13788"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2025-71371",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00499,
      "epss_percentile": 0.40712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-502",
      "title": "picklescan - Remote Code Execution via code.InteractiveInterpreter Detection Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71371"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-50003",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00497,
      "epss_percentile": 0.40612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OFFIS DICOM",
      "product": "DCMTK Toolkit",
      "cwe": "CWE-22",
      "title": "OFFIS DCMTK Toolkit Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50003"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-8655",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00493,
      "epss_percentile": 0.40383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NetScaler",
      "product": "ADC",
      "cwe": "CWE-119",
      "title": "Multiple Memory overflow vulnerabilities leading to unpredictable or erroneous behavior and Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8655"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-50750",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00489,
      "epss_percentile": 0.40109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ActiveMQ Broker",
      "cwe": "CWE-400",
      "title": "Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire DoS following fix for CVE-2026-49270",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50750"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-53691",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00488,
      "epss_percentile": 0.40095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Redeight",
      "product": "Redeight CMS",
      "cwe": "CWE-434",
      "title": "Remote Code Execution in Redeight CMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53691"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-8452",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00487,
      "epss_percentile": 0.39961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NetScaler",
      "product": "ADC",
      "cwe": "CWE-119",
      "title": "Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8452"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-13786",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0048,
      "epss_percentile": 0.39534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Ozone in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13786"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-13815",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0048,
      "epss_percentile": 0.39534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Blink in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13815"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-58015",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.39482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "GLib",
      "cwe": "CWE-22",
      "title": "Glib: path traversal in glib/gio/gdbusauthmechanismsha1.c via keyring_lookup_entry and mechanism_client_data_receive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58015"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-14162",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00472,
      "epss_percentile": 0.39001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Advantech",
      "product": "Hospital Quering Management",
      "cwe": "CWE-306",
      "title": "Advantech｜Hospital Quering Management - Missing Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14162"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-13474",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00472,
      "epss_percentile": 0.38994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NetScaler",
      "product": "ADC",
      "cwe": "CWE-401",
      "title": "Denial of service via malformed HTTP/2 requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13474"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-52760",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00472,
      "epss_percentile": 0.38975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ActiveMQ",
      "cwe": "CWE-79",
      "title": "Apache ActiveMQ, Apache ActiveMQ Web Console: Stored XSS via Unescaped values in ActiveMQ Web Console",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52760"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-14164",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0047,
      "epss_percentile": 0.38876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-415",
      "title": "Libarchive: double-free vulnerability in rar5 decompression logic via dangling filtered_buf pointer in init_unpack()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14164"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-49434",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ActiveMQ Broker",
      "cwe": "CWE-20",
      "title": "Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All: LdapNetworkConnector instantiates denied transports and a remote-properties broker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49434"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-13794",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00462,
      "epss_percentile": 0.38363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13794"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-13925",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00462,
      "epss_percentile": 0.38363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Downloads in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13925"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-13870",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00461,
      "epss_percentile": 0.38288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13870"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-13885",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00461,
      "epss_percentile": 0.38287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Skia in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13885"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-13965",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00461,
      "epss_percentile": 0.38288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Oilpan in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13965"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-58375",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00458,
      "epss_percentile": 0.38105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jeecgboot",
      "product": "jimureport",
      "cwe": "CWE-306",
      "title": "JimuReport 2.5.0 - Unauthenticated Report Export via /jmreport/auto/export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58375"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-10817",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00458,
      "epss_percentile": 0.38103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NetScaler",
      "product": "ADC",
      "cwe": "CWE-125",
      "title": "Insufficient input validation leading to memory overread",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10817"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-41053",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00454,
      "epss_percentile": 0.37824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-303",
      "title": "Over-inclusive team membership expansion in GitHub App authentication provider for Rancher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41053"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-52195",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00452,
      "epss_percentile": 0.37718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_472f08 component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52195"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-52196",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00452,
      "epss_percentile": 0.37717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_416f28 component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52196"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-56233",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00451,
      "epss_percentile": 0.37664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-22",
      "title": "Capgo - SSRF and Privilege Escalation via Path Traversal in Builder Upload Proxy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56233"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-7871",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00448,
      "epss_percentile": 0.37474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-502",
      "title": "Insecure Deserialization in Redis Cache Backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7871"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-55721",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00447,
      "epss_percentile": 0.37337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StoneFly",
      "product": "Storage Concentrator",
      "cwe": "CWE-89",
      "title": "SQL Injection in StoneFly Storage Concentrator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55721"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-13776",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00444,
      "epss_percentile": 0.37132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13776"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-13805",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00444,
      "epss_percentile": 0.37135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in GFX in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13805"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-13811",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00444,
      "epss_percentile": 0.37135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in IME in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13811"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-13821",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00444,
      "epss_percentile": 0.37135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Canvas in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13821"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-13845",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00444,
      "epss_percentile": 0.37134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in DOM in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13845"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-13848",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00444,
      "epss_percentile": 0.37136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Forms in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13848"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-13888",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00444,
      "epss_percentile": 0.37136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13888"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-13798",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00443,
      "epss_percentile": 0.37076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13798"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-14161",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00437,
      "epss_percentile": 0.36614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Advantech",
      "product": "Hospital Queuing Management",
      "cwe": "CWE-200",
      "title": "Advantech｜Hospital Queuing Management - Sensitive Data Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14161"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-58446",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00437,
      "epss_percentile": 0.3659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "presenton",
      "product": "presenton",
      "cwe": "CWE-306",
      "title": "Presenton < 0.8.8-beta - Authentication Bypass of Session Auth via Unprotected MCP Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58446"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-13901",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00436,
      "epss_percentile": 0.3647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13901"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-13903",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00436,
      "epss_percentile": 0.36469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13903"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-13799",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00436,
      "epss_percentile": 0.36474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in QUIC in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13799"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-13789",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00435,
      "epss_percentile": 0.36414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13789"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-44628",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00434,
      "epss_percentile": 0.36302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OFFIS DICOM",
      "product": "DCMTK Toolkit",
      "cwe": "CWE-843",
      "title": "OFFIS DCMTK Toolkit Type Confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44628"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-13802",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00433,
      "epss_percentile": 0.36235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13802"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-13791",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00426,
      "epss_percentile": 0.35682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Downloads in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13791"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-13774",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00424,
      "epss_percentile": 0.35558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13774"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-52193",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_447CAC component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52193"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-52198",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_425994 component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52198"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-35505",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OFFIS DICOM",
      "product": "DCMTK Toolkit",
      "cwe": "CWE-401",
      "title": "OFFIS DCMTK Toolkit Missing Release of Memory after Effective Lifetime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35505"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-50254",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.3486,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OFFIS DICOM",
      "product": "DCMTK Toolkit",
      "cwe": "CWE-401",
      "title": "OFFIS DCMTK Toolkit Missing Release of Memory after Effective Lifetime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50254"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-58170",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "Vibe-Trading",
      "cwe": "CWE-22",
      "title": "Vibe-Trading < 0.1.10 - Path Traversal in Proposal Identifier Allows Forging Live Trading Mandates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58170"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-7803",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00415,
      "epss_percentile": 0.34813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-20",
      "title": "Flow Validation Bypass via Empty Component Type Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7803"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-10816",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00415,
      "epss_percentile": 0.34757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NetScaler",
      "product": "ADC",
      "cwe": "CWE-610",
      "title": "Arbitrary File Read (Unauthenticated)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10816"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-13830",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.34744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13830"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-13919",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00413,
      "epss_percentile": 0.34649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13919"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-13921",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00413,
      "epss_percentile": 0.34649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in DeviceBoundSessionCredentials in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13921"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-13930",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00413,
      "epss_percentile": 0.34649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Actor in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13930"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-58172",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00412,
      "epss_percentile": 0.34479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThreeMammals",
      "product": "Ocelot",
      "cwe": "CWE-288",
      "title": "Ocelot - IP Allow/Block List Bypass for WebSocket Upgrade Requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58172"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-58168",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00412,
      "epss_percentile": 0.34532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "DeepTutor",
      "cwe": "CWE-862",
      "title": "DeepTutor < 1.4.10 - Insecure Default Grants Unrestricted MCP Tool Access to Non-Admin Users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58168"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-13792",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0041,
      "epss_percentile": 0.34341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Touchbar in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13792"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-13843",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0041,
      "epss_percentile": 0.34342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13843"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-13846",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0041,
      "epss_percentile": 0.34342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13846"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-13869",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0041,
      "epss_percentile": 0.34339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Device in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13869"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-13909",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0041,
      "epss_percentile": 0.3434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13909"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-13920",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0041,
      "epss_percentile": 0.34342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13920"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-13934",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0041,
      "epss_percentile": 0.3434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13934"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-13817",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13817"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-13835",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13835"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-13915",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.3434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13915"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-13918",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13918"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-13928",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13928"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-13938",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in Fonts in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13938"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-52868",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OFFIS DICOM",
      "product": "DCMTK Toolkit",
      "cwe": "CWE-22",
      "title": "OFFIS DCMTK Toolkit Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52868"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-13968",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00409,
      "epss_percentile": 0.34282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a malicious file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13968"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-52197",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00409,
      "epss_percentile": 0.34289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_44af70 component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52197"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-13775",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00407,
      "epss_percentile": 0.34118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13775"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-13780",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00407,
      "epss_percentile": 0.34119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13780"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-13781",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00407,
      "epss_percentile": 0.34118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13781"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-13785",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00407,
      "epss_percentile": 0.34119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13785"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-13783",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00407,
      "epss_percentile": 0.34119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13783"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-13784",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00407,
      "epss_percentile": 0.34119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13784"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-13923",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00406,
      "epss_percentile": 0.34023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in GPU in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13923"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-13943",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00406,
      "epss_percentile": 0.34023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in CSS in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13943"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-13803",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00405,
      "epss_percentile": 0.3391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in Chrome Tabs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13803"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-13831",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Out of bounds read and write in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13831"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-13855",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13855"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-13906",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00401,
      "epss_percentile": 0.33493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Codecs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13906"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-53690",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00399,
      "epss_percentile": 0.33358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Redeight",
      "product": "Redeight CMS",
      "cwe": "CWE-89",
      "title": "SQL Injection in Redeight CMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53690"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-13819",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00399,
      "epss_percentile": 0.33272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13819"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-14104",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00398,
      "epss_percentile": 0.33134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14104"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-14067",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.3305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14067"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-13924",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00397,
      "epss_percentile": 0.33058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13924"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-13926",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00397,
      "epss_percentile": 0.33057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13926"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-13883",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.32995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13883"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-13825",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.32995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13825"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-13829",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Settings in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13829"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-13834",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13834"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-13897",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00395,
      "epss_percentile": 0.32848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13897"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2025-71350",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00395,
      "epss_percentile": 0.32882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "picklescan",
      "product": "picklescan",
      "cwe": "CWE-502",
      "title": "picklescan - Undetected Remote Code Execution via torch.utils.collect_env.run",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71350"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-13891",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13891"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-13958",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00392,
      "epss_percentile": 0.32481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Codecs in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13958"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-13806",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00391,
      "epss_percentile": 0.32419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Accessibility in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13806"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-13790",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00388,
      "epss_percentile": 0.32147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in Scroll in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13790"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-13810",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00388,
      "epss_percentile": 0.32147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in Input in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13810"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-13847",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00388,
      "epss_percentile": 0.32147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13847"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-13922",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00388,
      "epss_percentile": 0.32146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13922"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-13935",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00388,
      "epss_percentile": 0.32146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in ComputePressure in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13935"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-13947",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00387,
      "epss_percentile": 0.32095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in XR in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13947"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-13950",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00387,
      "epss_percentile": 0.32095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13950"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-13889",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00384,
      "epss_percentile": 0.31721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Side-channel information leakage in WebAuthentication in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13889"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-13782",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0038,
      "epss_percentile": 0.31275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13782"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-13796",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0038,
      "epss_percentile": 0.31275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13796"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-13797",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0038,
      "epss_percentile": 0.31275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13797"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-13777",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in iOSWeb in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13777"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-13911",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00379,
      "epss_percentile": 0.31241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient policy enforcement in Spellcheck in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13911"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-13833",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00375,
      "epss_percentile": 0.30787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13833"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-13900",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00375,
      "epss_percentile": 0.30817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13900"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-13937",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00374,
      "epss_percentile": 0.30647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13937"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-13954",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00374,
      "epss_percentile": 0.30647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in XML in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13954"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-13807",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.30549,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Import in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a malicious file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13807"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-13816",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00373,
      "epss_percentile": 0.30542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in File Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13816"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-13910",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00373,
      "epss_percentile": 0.30542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13910"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-10562",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00372,
      "epss_percentile": 0.30521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Archer AX20 V2.0",
      "cwe": "CWE-601",
      "title": "Unauthenticated Open Redirect Vulnerability on TP-Link Archer AX20 Web Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10562"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-13801",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13801"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-13804",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13804"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-13823",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13823"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-13832",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Headless in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13832"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-13841",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13841"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-13951",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13951"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-58013",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "GLib",
      "cwe": "CWE-126",
      "title": "Glib: buffer over-read in glib/giochannel.c via \"g_io_channel_read_line_backend\"",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58013"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-13814",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13814"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-13873",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Layout in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13873"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-13813",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13813"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-13824",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13824"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-13856",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Speech in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13856"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-13893",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0037,
      "epss_percentile": 0.3029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebUI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13893"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-56278",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00367,
      "epss_percentile": 0.29941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-798",
      "title": "Flowise - Session Hijacking via Weak Default Express Session Secret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56278"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-58011",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00367,
      "epss_percentile": 0.29972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "GLib",
      "cwe": "CWE-125",
      "title": "Glib: out-of-bounds read in glib/gdatetime.c:g_date_time_get_ymd via invalid gdatetime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58011"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-13875",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00366,
      "epss_percentile": 0.29814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in GPU in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13875"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-13853",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00363,
      "epss_percentile": 0.29591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Journeys in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13853"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-13854",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00363,
      "epss_percentile": 0.29591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13854"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-13859",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00363,
      "epss_percentile": 0.29591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13859"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-13861",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00363,
      "epss_percentile": 0.29592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Core in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13861"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-13878",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00363,
      "epss_percentile": 0.29591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13878"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-13880",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00363,
      "epss_percentile": 0.29592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13880"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-58010",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.2954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "GLib",
      "cwe": "CWE-126",
      "title": "Glib: buffer over-read in glib/gvariant-serialiser.c via gvs_tuple_is_normal()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58010"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-58012",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.2954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "GLib",
      "cwe": "CWE-126",
      "title": "Glib: buffer over-read in g_regex_replace() via glib/gregex.c:string_append() and g_utf8_next_char()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58012"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-58369",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00362,
      "epss_percentile": 0.29454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "woodpecker-ci",
      "product": "woodpecker",
      "cwe": "CWE-476",
      "title": "Woodpecker < 3.15.0 - Unauthenticated NULL Pointer Dereference in /api/orgs/lookup Enables Log-Flooding Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58369"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-13969",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00361,
      "epss_percentile": 0.29392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in UI in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13969"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-13970",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00361,
      "epss_percentile": 0.29393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Media in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13970"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-13971",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00361,
      "epss_percentile": 0.29393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13971"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-11708",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0036,
      "epss_percentile": 0.29261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-79",
      "title": "IBM WebSphere Application Server is affected by a cross-site scripting vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11708"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-13809",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00359,
      "epss_percentile": 0.2917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13809"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-13932",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00359,
      "epss_percentile": 0.29114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Sharing in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13932"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-13936",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00359,
      "epss_percentile": 0.29114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Passwords in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13936"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-13864",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.29062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in WebHID in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13864"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-13858",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00358,
      "epss_percentile": 0.29058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in FFmpeg in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13858"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-10134",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00357,
      "epss_percentile": 0.28929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10134"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-13892",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00356,
      "epss_percentile": 0.28802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13892"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-13877",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00354,
      "epss_percentile": 0.28617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13877"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-13961",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00354,
      "epss_percentile": 0.28617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13961"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-56286",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-306",
      "title": "Capgo - Account Deletion Without Password Confirmation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56286"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-13871",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00353,
      "epss_percentile": 0.28564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in GuestView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13871"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-13962",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00353,
      "epss_percentile": 0.28565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient data validation in PDF in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13962"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-13207",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frangoteam",
      "product": "FUXA SCADA/HMI",
      "cwe": "CWE-290",
      "title": "Frangoteam FUXA SCADA/HMI Authentication Bypass by Spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13207"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-14178",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00351,
      "epss_percentile": 0.2831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openGauss-server",
      "product": "openGauss-server-7.0.0-RC2",
      "cwe": "CWE-416",
      "title": "openGauss存在非法内存访问导致DoS漏洞",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14178"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-13766",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0035,
      "epss_percentile": 0.2815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EXODIST",
      "product": "DBIx::QuickORM",
      "cwe": "CWE-89",
      "title": "DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13766"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-56300",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00349,
      "epss_percentile": 0.2808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-200",
      "title": "Capgo - Unauthenticated API Key Validity and Permission Oracle via RPC Functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56300"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-13851",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00348,
      "epss_percentile": 0.27989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13851"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-13852",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00348,
      "epss_percentile": 0.27989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13852"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-13149",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "juliangruber",
      "product": "brace-expansion",
      "cwe": "CWE-400",
      "title": "brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13149"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2025-53648",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00348,
      "epss_percentile": 0.2802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Gravitino",
      "cwe": "CWE-89",
      "title": "Apache Gravitino: SQL misconfiguration can access or truncate files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53648"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-13828",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00346,
      "epss_percentile": 0.2775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13828"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-13964",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13964"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-6953",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Intermark IT",
      "product": "WebControl CMS",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in Intermark IT's WebControl CMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6953"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-13820",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00344,
      "epss_percentile": 0.27529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Skia in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13820"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-13890",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13890"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-13933",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00342,
      "epss_percentile": 0.27354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13933"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-56219",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-287",
      "title": "Capgo - Unauthenticated RBAC Bindings and Email Disclosure via get_org_user_access_rbac NULL-auth Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56219"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-13818",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0034,
      "epss_percentile": 0.2714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13818"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-13953",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0034,
      "epss_percentile": 0.2714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13953"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-14121",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00339,
      "epss_percentile": 0.27015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14121"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-13884",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13884"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-13866",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00339,
      "epss_percentile": 0.27001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13866"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-54502",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00338,
      "epss_percentile": 0.2684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ohler55",
      "product": "oj",
      "cwe": "CWE-121",
      "title": "Oj: Stack Buffer Overflow in Oj.dump via Large Indent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54502"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-11712",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00336,
      "epss_percentile": 0.26639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-79",
      "title": "IBM WebSphere Application Server is affected by a cross-site scripting vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11712"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-7873",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00335,
      "epss_percentile": 0.26528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Code Injection Vulnerability in Code Validation Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7873"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-56264",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00334,
      "epss_percentile": 0.26405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crawl4AI",
      "product": "Crawl4AI",
      "cwe": "CWE-94",
      "title": "Crawl4AI - Arbitrary JavaScript Execution via /execute_js Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56264"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-13904",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00333,
      "epss_percentile": 0.26274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13904"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-12240",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00331,
      "epss_percentile": 0.26083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qlstudio",
      "product": "Export User Data",
      "cwe": "CWE-502",
      "title": "Export User Data <= 2.2.6 - Authenticated (Subscriber+) PHP Object Injection to Arbitrary File Deletion via display_name Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12240"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-13931",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0033,
      "epss_percentile": 0.25992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13931"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-7663",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00328,
      "epss_percentile": 0.25817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-863",
      "title": "Unauthenticated Cross-User MCP Resource Access and Tool Execution via Streamable Transport Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7663"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-13872",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00328,
      "epss_percentile": 0.25742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13872"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-13795",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00327,
      "epss_percentile": 0.25683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13795"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-14149",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Audio in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14149"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-57995",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phpMyFAQ",
      "product": "phpMyFAQ",
      "cwe": "CWE-269",
      "title": "phpMyFAQ - Privilege Escalation via Missing Self-Rights Constraint in GroupController::updatePermissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57995"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-4629",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.25516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-266",
      "title": "Keycloak: keycloak: privilege escalation through hardcoded role mapper injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4629"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-13850",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code inside a sandbox via a malicious file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13850"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-35098",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.25161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KTM System",
      "product": "e-BOK",
      "cwe": "CWE-307",
      "title": "Improper Restriction of Excessive Authentication Attempts in KTM System e-BOK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35098"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-56230",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-639",
      "title": "Capgo - Broken Object Level Authorization via x-limited-key-id Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56230"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-8402",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00321,
      "epss_percentile": 0.24969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eksagate Electronic Engineering and Computer Industry Trade Inc.",
      "product": "SYSGUARD 6001",
      "cwe": "CWE-89",
      "title": "SQLi in Exagate's SYSGUARD 6001",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8402"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-58014",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.25038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "GLib",
      "cwe": "CWE-193",
      "title": "Glib: off-by-one error in glib/gkeyfile.c via \"g_key_file_get_locale_string_list\"",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58014"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-56399",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0032,
      "epss_percentile": 0.24924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-918",
      "title": "Open WebUI - Server-Side Request Forgery via Location Redirect in /api/v1/retrieval/process/web",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56399"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-14023",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in SanitizerAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14023"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-14065",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14065"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-14111",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebProtect in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14111"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-14024",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14024"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-14025",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14025"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-12076",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00314,
      "epss_percentile": 0.242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Raytha",
      "product": "Raytha",
      "cwe": "CWE-89",
      "title": "SQL Injection in Raytha CMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12076"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-14086",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.24264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in HID in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14086"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-9263",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.24148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in Bluetooth Controller ISOAL framed RX reassembly leaks adjacent memory into host HCI ISO packets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9263"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-13886",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in Isolated Web Apps in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13886"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-13896",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13896"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-13917",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13917"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-14010",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00311,
      "epss_percentile": 0.23849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Codecs in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14010"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-12073",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0031,
      "epss_percentile": 0.23799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "metagauss",
      "product": "ProfileGrid – User Profiles, Groups and Communities",
      "cwe": "CWE-639",
      "title": "ProfileGrid - User Profiles, Groups and Communities <= 5.9.9.5 - Unauthenticated Privilege Escalation via Email Overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12073"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-12819",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0031,
      "epss_percentile": 0.2381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deltaww",
      "product": "DVP-12SE",
      "cwe": "CWE-306",
      "title": "DVP-12SE Missing Authentication and Unauthorized Write access Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12819"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-10652",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in Zephyr DNS resolver TXT/SRV record parsing (unvalidated `rdlength`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10652"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-58173",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.23419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "Vibe-Trading",
      "cwe": "CWE-22",
      "title": "Vibe-Trading < 0.1.10 - Path Traversal via Persistent Memory Type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58173"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-57079",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00306,
      "epss_percentile": 0.23264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SANKO",
      "product": "Net::BitTorrent",
      "cwe": "CWE-22",
      "title": "Net::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-supplied metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57079"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-13759",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.2306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Extreme Scale",
      "cwe": "CWE-502",
      "title": "IBM WebSphere eXtreme Scale is affected by Insecure Deserilization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13759"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-56247",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.23011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-266",
      "title": "Capgo - Privilege Escalation via Cross-Scope RBAC Role Assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56247"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-13959",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00303,
      "epss_percentile": 0.23044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Blink in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13959"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-6556",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00302,
      "epss_percentile": 0.22813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "@fastify/express",
      "product": "@fastify/express",
      "cwe": "CWE-285",
      "title": "@fastify/express vulnerable to middleware bypass via non-string mount paths in prefixed plugins",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6556"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-13793",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.22894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in SVG in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13793"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-13840",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.22894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in Canvas in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13840"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-13862",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.2282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in Web Authentication (Passkeys & Security Keys) in Google Chrome on iOS prior to 150.0.7871.47 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13862"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-13913",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.22894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13913"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-10655",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00301,
      "epss_percentile": 0.22807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-416",
      "title": "Use-after-free race in SNTP async client when closing the socket while the socket service is still polling it",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10655"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-54696",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00301,
      "epss_percentile": 0.22789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ruby",
      "product": "json",
      "cwe": "CWE-122",
      "title": "Ruby JSON: JSON generator heap buffer overflow when streaming to an IO",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54696"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-9711",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.003,
      "epss_percentile": 0.22678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EventON",
      "product": "EventON (Pro) - WordPress Virtual Event Calendar Plugin",
      "cwe": "CWE-89",
      "title": "EventON - WordPress Virtual Event Calendar Plugin <= 5.0.11 - Unauthenticated Blind SQL Injection via Search Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9711"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-14004",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.003,
      "epss_percentile": 0.22599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14004"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-14022",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.22572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14022"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-58374",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.22042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "w1.fi",
      "product": "hostapd",
      "cwe": "CWE-193",
      "title": "In hostapd before 2.12, a missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) Multi-Link Operation (MLO) association request processing allows an unauthenticated attacker within wireless range to send a crafted management frame containing a malformed Multi-Link Element or Per-STA Profile subelement. In hostapd_process_ml_assoc_req() in src/ap/ieee802_11_eht.c, the received link_id field can be parsed as value 15, but the corresponding links[] storage only has valid entries for lower link IDs (0 through 14). This causes an out-of-bounds write / small memory corruption during association processing before the 4-way handshake. The attack does not require network credentials, prior authentication, or user interaction. The confirmed practical impact is denial of service through hostapd process termination. This affects hostapd v2.11 and newer development snapshots before v2.12 when built with CONFIG_IEEE80211BE enabled. The issue is fixed in hostapd v2.12 and the upstream 2026-1 fixes.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58374"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-13837",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13837"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-13865",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13865"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-13867",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Geolocation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13867"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-13902",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13902"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-13912",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13912"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-13916",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13916"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-13941",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in SiteSettings in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13941"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-13960",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13960"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-13966",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in History in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13966"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-44948",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-23",
      "title": "Path Traversal in Rancher Fleet ImageScan GitRepo Path Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44948"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-44946",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-294",
      "title": "SAML Authentication Replay in Rancher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44946"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-14006",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14006"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-14091",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14091"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-14107",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Scheduling in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14107"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-45822",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SamVerschueren",
      "product": "decode-uri-component",
      "cwe": "CWE-400",
      "title": "decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls decodeComponents(), exhibiting super-linear parsing time: 200 '%ab' tokens takes approximately 0.7s, 700 tokens approximately 6s, and 1400 tokens approximately 33s. An attacker can cause significant CPU consumption and event-loop blocking via crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45822"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-13882",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0029,
      "epss_percentile": 0.21579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13882"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-14087",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.21555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Heap buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14087"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-13826",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Autofill in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13826"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-13887",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in NFC in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13887"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-13908",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21486,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Omnibox in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13908"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-13949",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in Payments in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13949"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-14074",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.21231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in WebAuthentication in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14074"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-13836",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.21257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13836"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-58169",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.2114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "Vibe-Trading",
      "cwe": "CWE-346",
      "title": "Vibe-Trading < 0.1.10 - Loopback Trust and Missing Host Validation Enable DNS-Rebinding Authentication Bypass and Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58169"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-11906",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-1284",
      "title": "IBM® Db2® federated server is vulnerable to a denial of service due to improper neutralization of special elements in the data query logic of XMLTable-derived columns by autheticated user",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11906"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-55223",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00284,
      "epss_percentile": 0.20974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "swaldman",
      "product": "c3p0",
      "cwe": "CWE-502",
      "title": "c3p0 exposes a deserialization \"sink\" via JDBC DataSource bean properties",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55223"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-56365",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00284,
      "epss_percentile": 0.2102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-401",
      "title": "ImageMagick - Memory Leak in PNG Encoder via MNG Image Writing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56365"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-13772",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Extreme Scale",
      "cwe": "CWE-470",
      "title": "IBM WebSphere eXtreme Scale's OQL is affected by remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13772"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-13838",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00283,
      "epss_percentile": 0.20826,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13838"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-13839",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00283,
      "epss_percentile": 0.20826,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13839"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-13842",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13842"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-13946",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.2074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-352",
      "title": "Inappropriate implementation in ScriptInjections in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13946"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-13952",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.2074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-352",
      "title": "Inappropriate implementation in PerformanceAPIs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13952"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2025-71381",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hono",
      "product": "Hono",
      "cwe": "CWE-113",
      "title": "Hono - Vary Header Injection in CORS Middleware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71381"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-10653",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-415",
      "title": "Non-atomic `net_buf` reference counts cause double-free / free-list corruption under concurrent unref",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10653"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-57585",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "msgpack",
      "product": "msgpack-python",
      "cwe": "CWE-416",
      "title": "MessagePack: Out-of-bounds read/crash on Unpacker reuse after caught error",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57585"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-54592",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.2033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ohler55",
      "product": "oj",
      "cwe": "CWE-125",
      "title": "Oj: Stack Buffer Overflow in Oj::Doc#each_child via Deeply Nested Input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54592"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-57080",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SANKO",
      "product": "Net::BitTorrent",
      "cwe": "CWE-400",
      "title": "Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefix",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57080"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-57081",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SANKO",
      "product": "Net::BitTorrent",
      "cwe": "CWE-400",
      "title": "Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57081"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-4360",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00277,
      "epss_percentile": 0.20219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Software Foundation",
      "product": "CPython",
      "cwe": "CWE-281",
      "title": "Tarfile.extract() doesn't fully respect filter parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4360"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-11589",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Support Plus Responsive Ticket System",
      "cwe": null,
      "title": "WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Stored XSS via File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11589"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-13939",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00276,
      "epss_percentile": 0.20137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13939"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-14064",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.19996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in PageInfo in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14064"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-13972",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13972"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-14033",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.19836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14033"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-10560",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00272,
      "epss_percentile": 0.19676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-287",
      "title": "Unauthenticated Access to Private Flow Build Events and Cancellation in Langflow OSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10560"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-6954",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.1969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Intermark IT",
      "product": "WebControl CMS",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities in Intermark IT's WebControl CMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6954"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-13868",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.19445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Network in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13868"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-13895",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.19408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Autofill in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13895"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-13907",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.19408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in iOSWeb in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13907"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-14032",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14032"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-14108",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14108"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-13876",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged network position to bypass content security policy via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13876"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-13974",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in Safe Browsing in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13974"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-13881",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13881"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-14120",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00265,
      "epss_percentile": 0.18535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14120"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-14125",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.18579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14125"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-58174",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.1851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nesquena",
      "product": "hermes-webui",
      "cwe": "CWE-732",
      "title": "Hermes WebUI < 0.51.521 - Cross-Profile Authorization Bypass via Unset Session Profile on Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58174"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-13874",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.18501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in DataTransfer in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13874"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-58176",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.18493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dromara",
      "product": "RuoYi-Vue-Plus",
      "cwe": "CWE-862",
      "title": "RuoYi-Vue-Plus - Missing Authorization on Workflow Task Management Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58176"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-14007",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in PermissionsPolicy in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14007"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-14017",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00263,
      "epss_percentile": 0.18218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14017"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-14043",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00263,
      "epss_percentile": 0.18216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in GetUserMedia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14043"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-14044",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00263,
      "epss_percentile": 0.18217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14044"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-14055",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00263,
      "epss_percentile": 0.18217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Device Trust in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14055"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-14109",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00263,
      "epss_percentile": 0.18216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14109"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-14027",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in SignIn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14027"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-14036",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14036"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-14041",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14041"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-14078",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebRTC in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14078"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-58377",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jeecgboot",
      "product": "JeecgBoot",
      "cwe": "CWE-862",
      "title": "JeecgBoot 3.9.2 - Missing Authorization on OpenAPI Credential Management Endpoints Exposes Access/Secret Keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58377"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-14090",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Insufficient validation of untrusted input in CameraCapture in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14090"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-14106",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00262,
      "epss_percentile": 0.18183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14106"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-11590",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Support Plus Responsive Ticket System",
      "cwe": null,
      "title": "WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated SQL Injection via filter[elements] Array Keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11590"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-11806",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server - Liberty",
      "cwe": "CWE-444",
      "title": "IBM WebSphere Application Server Liberty is affected by a an arbitrary file read vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11806"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-13857",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.18176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Geometry in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13857"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-13860",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.18176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in Autofill in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13860"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-13956",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.18176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13956"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-56318",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-200",
      "title": "Capgo - Information Disclosure via /private/validate_password_compliance Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56318"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-56327",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-203",
      "title": "Capgo - Unauthenticated Organization Existence Oracle via public.invite_user_to_org RPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56327"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-13812",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13812"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-14051",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in GamepadAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14051"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-14070",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Integer overflow in WebNN in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14070"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-14088",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Canvas in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14088"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-50040",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StoneFly",
      "product": "Storage Concentrator",
      "cwe": "CWE-79",
      "title": "Cross-site Scripting in StoneFly Storage Concentrator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50040"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-56350",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-285",
      "title": "n8n - SSO Enforcement Bypass via API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56350"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-14038",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00257,
      "epss_percentile": 0.17555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14038"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-56249",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-285",
      "title": "Capgo - Unauthorized Channel Overwrite and Ownership Takeover via POST /channel Name Collision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56249"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-14021",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14021"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-14050",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14050"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-14059",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in Related-Website-Sets in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14059"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-14085",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14085"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-14103",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in SSL in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14103"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-9132",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.1759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitHub",
      "product": "Enterprise Server",
      "cwe": "CWE-862",
      "title": "Missing authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository contents via the Copilot pull request diff summary endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9132"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-11541",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00256,
      "epss_percentile": 0.17406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "CICS Transaction Gateway for Multiplatforms",
      "cwe": "CWE-444",
      "title": "Inconsistent Interpretation of HTTP Requests in CICS Transaction Gateway for Multiplatforms.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11541"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-14099",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14099"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-13985",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-290",
      "title": "Inappropriate implementation in MediaCapture in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13985"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-14113",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00254,
      "epss_percentile": 0.17139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14113"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-14146",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14146"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-12818",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00253,
      "epss_percentile": 0.16991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deltaww",
      "product": "DVP-12SE",
      "cwe": "CWE-770",
      "title": "DVP-12SE Exposure of Sensitive Information Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12818"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-14009",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.1697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14009"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-10763",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.16991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hitachi Energy",
      "product": "PROMOD V",
      "cwe": "CWE-1428",
      "title": "PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support from 3rd party Digipede server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10763"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-54899",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ohler55",
      "product": "oj",
      "cwe": "CWE-416",
      "title": "Oj: Use-After-Free in Oj::Parser Symbol Key Cache Toggle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54899"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-54900",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ohler55",
      "product": "oj",
      "cwe": "CWE-190",
      "title": "Oj: Negative-Size memcpy in Oj::Parser create_id Attribute Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54900"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-54901",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ohler55",
      "product": "oj",
      "cwe": "CWE-416",
      "title": "Oj: Use-After-Free in Oj::Parser array_class/hash_class GC Marking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54901"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-54902",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ohler55",
      "product": "oj",
      "cwe": "CWE-416",
      "title": "Oj: Use-After-Free in Oj::Parser SAJ Long Key Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54902"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-54903",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ohler55",
      "product": "oj",
      "cwe": "CWE-190",
      "title": "Oj: Integer Overflow in Oj.load 2GB String Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54903"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-58171",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00253,
      "epss_percentile": 0.17082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "Vibe-Trading",
      "cwe": "CWE-22",
      "title": "Vibe-Trading < 0.1.10 - Path Traversal via Swarm Run Identifier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58171"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-14241",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00252,
      "epss_percentile": 0.16854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox",
      "cwe": "CWE-787",
      "title": "Memory safety bugs fixed in Firefox 152.0.4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14241"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-14037",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00252,
      "epss_percentile": 0.16918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14037"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-14102",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14102"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-13879",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via a malicious peripheral. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13879"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-13894",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged network position to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13894"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-13944",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00251,
      "epss_percentile": 0.16746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-352",
      "title": "Inappropriate implementation in DataTransfer in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13944"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-13963",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00251,
      "epss_percentile": 0.16746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-352",
      "title": "Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13963"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-56331",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-209",
      "title": "Capgo - Improper Error Handling in Accept Invitation Endpoint via Invalid Magic String",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56331"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-14008",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14008"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-14118",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-290",
      "title": "Insufficient data validation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14118"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2025-36319",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "watsonx.data intelligence",
      "cwe": "CWE-770",
      "title": "Vulnerabilities found in Watson Data Intelligence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36319"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-35097",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KTM System",
      "product": "e-BOK",
      "cwe": "CWE-521",
      "title": "Weak Password Requirements in KTM System e-BOK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35097"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-13975",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.1649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13975"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-56328",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-670",
      "title": "Capgo - Integrity Issue in Release Routing via Multiple Public Channels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56328"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-14019",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-522",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14019"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-14011",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in SurfaceCapture in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14011"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-56777",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.16089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-184",
      "title": "n8n - AST Validator Bypass in Python Code Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56777"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-58165",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.15895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openziti",
      "product": "ziti",
      "cwe": "CWE-862",
      "title": "OpenZiti - Privilege Escalation to Admin via Unauthorized Enrollment Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58165"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-14093",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00243,
      "epss_percentile": 0.15774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14093"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-14095",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00243,
      "epss_percentile": 0.15738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient policy enforcement in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14095"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-14097",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00243,
      "epss_percentile": 0.15737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in WebAppInstalls in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14097"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-14005",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.1574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Omnibox in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14005"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-13940",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Cast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13940"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-14056",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00242,
      "epss_percentile": 0.15658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Media in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14056"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-14084",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14084"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-14115",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14115"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-9836",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "InfoSphere Information Server",
      "cwe": "CWE-200",
      "title": "IBM DataStage Flow Designer application is affected by an information disclosure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9836"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2025-36321",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "watsonx.data intelligence",
      "cwe": "CWE-80",
      "title": "Vulnerabilities found in Watson Data Intelligence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36321"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-14062",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in Views in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14062"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-53432",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fzf",
      "product": "fzf",
      "cwe": "CWE-190",
      "title": "Integer Overflow in fzf",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53432"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-12560",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpqode",
      "product": "Editorial Rating – Product Review & Rating System",
      "cwe": "CWE-79",
      "title": "Editorial Rating <= 4.0.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'Link URL' Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12560"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-14122",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14122"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-12349",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "octagonwebstudio",
      "product": "Premium Addons for KingComposer",
      "cwe": "CWE-862",
      "title": "Premium Addons for KingComposer <= 1.1.1 - Missing Authorization to Unauthenticated Arbitrary Custom Sidebar Creation and Deletion via 'add_custom_sidebar' and 'remove_custom_sidebar' AJAX actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12349"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-58167",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ccfos",
      "product": "nightingale",
      "cwe": "CWE-862",
      "title": "Nightingale < 9.0.0-beta.2 - Datasource Credential Disclosure to Low-Privilege Users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58167"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-14069",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in WebNN in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14069"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-14071",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in WebAudio in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14071"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-14098",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14098"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-14100",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient data validation in NetworkCache in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14100"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-14058",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in Parser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14058"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-13973",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in UI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13973"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-10513",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pfefferle",
      "product": "Webmention",
      "cwe": "CWE-79",
      "title": "Webmention <= 5.8.0 - Unauthenticated Stored Cross-Site Scripting via MF2 'photo'/'url' Author Properties",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10513"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-54673",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron-userland",
      "product": "electron-builder",
      "cwe": "CWE-200",
      "title": "electron-updater: Cross-origin redirect leaks `PRIVATE-TOKEN` and mixed-case `Authorization` credentials in `builder-util-runtime`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54673"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-58448",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YunaiV",
      "product": "yudao-cloud",
      "cwe": "CWE-862",
      "title": "yudao-cloud < 2026.06 - BPM Module Broken Access Control via process-instance API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58448"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-14101",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.14516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14101"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-12085",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "UCD - IBM UrbanCode Deploy",
      "cwe": "CWE-201",
      "title": "IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptable to an Insertion of Sensitive Information Into Sent Data vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12085"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-56333",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-20",
      "title": "Capgo - Server-Side Validation Bypass via Direct Browser-Side Organization Security Settings Updates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56333"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-9576",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.1462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Fluent Booking",
      "cwe": null,
      "title": "Fluent Booking < 2.1.2 - Calendar Manager+ Sensitive Information Disclosure via Attendee Export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9576"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-14066",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14066"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-12388",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.14413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-266",
      "title": "Keycloak-broker: keycloak: privilege escalation to realm administrator via improper authorization in identity provider mapper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12388"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-14117",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.14416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14117"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-14034",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.14481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14034"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-13449",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00232,
      "epss_percentile": 0.14318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Business Automation Manager Open Editions",
      "cwe": "CWE-611",
      "title": "XXE attack in IBM Business Automation Manager Open Editions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13449"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-44949",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14389,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-306",
      "title": "Unauthenticated namespace creation and RBAC injection via rancher-webhook FleetWorkspace mutating webhook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44949"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-13978",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Insufficient policy enforcement in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13978"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-13979",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13979"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-14152",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0023,
      "epss_percentile": 0.14084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds read and write in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14152"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-13980",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13980"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-13981",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13981"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-14052",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in FileSystem in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14052"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-44947",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-281",
      "title": "Stale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in Rancher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44947"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-14035",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14035"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-14061",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14061"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-14096",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14096"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-56369",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.1399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-323",
      "title": "ImageMagick - Information Disclosure via AES-CTR Nonce Reuse in PasskeyEncipherImage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56369"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-14054",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14054"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-10140",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00228,
      "epss_percentile": 0.13877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-639",
      "title": "Cross-Tenant API Key Reuse and Billing Fraud in Langflow Voice Mode Subsystem",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10140"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-14014",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14014"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-14112",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.1361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-203",
      "title": "Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14112"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-58447",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iv-org",
      "product": "Invidious",
      "cwe": "CWE-639",
      "title": "Invidious - Cross-User Playlist Video Deletion via Missing Ownership Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58447"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-11546",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00222,
      "epss_percentile": 0.13095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server - Liberty",
      "cwe": "CWE-918",
      "title": "IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11546"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-56320",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-285",
      "title": "Capgo - Org/App Scope Mismatch in Device Creation Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56320"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-27955",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify: Command Injection via Single-Quote Breakout in `executeInDocker()`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27955"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-28322",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.1301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Database Performance Analyzer",
      "cwe": "CWE-20",
      "title": "SolarWinds Database Performance Analyzer Stored Cross-Site Scripting Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28322"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-13995",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.12982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Autofill in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13995"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-14209",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.4",
      "cwe": "CWE-639",
      "title": "Keycloak-admin-ui: keycloak-admin-ui:admin ui extension brute-force-user endpoint bypasses fgapv2 user view restrictions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14209"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-58376",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dolibarr",
      "product": "dolibarr",
      "cwe": "CWE-89",
      "title": "Dolibarr - SQL Injection via sqlfilters Parameter in Multiple REST API List Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58376"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-14148",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14148"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-13808",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient data validation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive information from process memory via physical access to the device. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13808"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-14151",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.12829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-669",
      "title": "Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14151"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-13996",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Permissions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13996"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-14002",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Geolocation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14002"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2025-36328",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "watsonx.data intelligence",
      "cwe": "CWE-209",
      "title": "Error Message Containing Sensitive Information found in Watson Data Intelligence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36328"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-14040",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.12588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in BrowserTag in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14040"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-13988",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13988"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-14082",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.1254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in Storage in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14082"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-14049",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14049"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-27883",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-639",
      "title": "Coolify: IDOR in Deployment API - Cross-Team Deployment Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27883"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-53433",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fzf",
      "product": "fzf",
      "cwe": "CWE-407",
      "title": "Denial of Service in fzf",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53433"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-12114",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmart",
      "product": "Team Members – Multi Language Supported Team Plugin",
      "cwe": "CWE-79",
      "title": "Team Members <= 8.7 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'custom_css' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12114"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-14155",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14155"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-58371",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0021,
      "epss_percentile": 0.11482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seaweedfs",
      "product": "seaweedfs",
      "cwe": "CWE-79",
      "title": "SeaweedFS < 4.30 - Cross-Origin Information Disclosure via Unvalidated JSONP callback Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58371"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2025-36327",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "watsonx.data intelligence",
      "cwe": "CWE-602",
      "title": "Vulnerabilities found in Watson Data Intelligence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36327"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-9106",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitHub",
      "product": "Enterprise Server",
      "cwe": "CWE-451",
      "title": "UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screen",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9106"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-11714",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00207,
      "epss_percentile": 0.11138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server - Liberty",
      "cwe": "CWE-918",
      "title": "IBM WebSphere Application Server Liberty is affected by an authorization bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11714"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-57204",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.11026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-400",
      "title": "pypdf: Missing stream length values ignore defined limits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57204"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-14116",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.10938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14116"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-14015",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in WebRTC in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14015"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-14012",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14012"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-13986",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Media UI in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13986"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-13982",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00205,
      "epss_percentile": 0.10838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13982"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-13989",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13989"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2025-36372",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.1064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-538",
      "title": "IBM® Db2® could disclose sensitive information to an authenticated user from the monitoring and event tables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36372"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-14127",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Printing in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14127"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-14130",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Incorrect security UI in Omnibox in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14130"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-14140",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14140"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-14141",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in Document Picture-in-Picture in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14141"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2025-24816",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nokia",
      "product": "MantaRay NM",
      "cwe": "CWE-284",
      "title": "An Improper Access Control vulnerability in Nokia MantaRay NM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-24816"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-13929",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13929"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-14045",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.1033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14045"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-14156",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-862",
      "title": "Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14156"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-58373",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cvat-ai",
      "product": "cvat",
      "cwe": "CWE-862",
      "title": "CVAT < 2.69.0 - Missing Authorization on Quality Reports parent_id Filter Leaks Cross-Organization Report Existence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58373"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-14075",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass no-referrer policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14075"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-10564",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-918",
      "title": "SSRF Vulnerability in Langflow OSS Legacy Components Bypasses Protection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10564"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-14016",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-352",
      "title": "Inappropriate implementation in SVG in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14016"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-54500",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ohler55",
      "product": "oj",
      "cwe": "CWE-125",
      "title": "Oj: intern.c form_attr has an uninitialized stack read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54500"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-14020",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebXR in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14020"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-14042",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14042"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-14072",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14072"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-14089",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in PopupBlocker in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14089"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-13957",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.0999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Incorrect security UI in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13957"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2026-10654",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00198,
      "epss_percentile": 0.09942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-362",
      "title": "RFCOMM session-disconnect race leaks session/L2CAP and denies further RFCOMM service in Zephyr Bluetooth Classic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10654"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-13822",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Extensions in Google Chrome on Android prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13822"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-13990",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in DataTransfer in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13990"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-56224",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-384",
      "title": "Capgo - Login CSRF and Session Fixation via URL Query Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56224"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-14110",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1021",
      "title": "Inappropriate implementation in DarkMode in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14110"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-48192",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "Mendix Studio Pro 10.11",
      "cwe": "CWE-94",
      "title": "A vulnerability has been identified in Mendix Studio Pro 10.11 (All versions), Mendix Studio Pro 10.12 (All versions), Mendix Studio Pro 10.13 (All versions), Mendix Studio Pro 10.14 (All versions), Mendix Studio Pro 10.15 (All versions), Mendix Studio Pro 10.16 (All versions), Mendix Studio Pro 10.17 (All versions), Mendix Studio Pro 10.18 (All versions), Mendix Studio Pro 10.19 (All versions), Mendix Studio Pro 10.20 (All versions), Mendix Studio Pro 10.21 (All versions), Mendix Studio Pro 10.22 (All versions), Mendix Studio Pro 10.23 (All versions), Mendix Studio Pro 10.24 (All versions < V10.24.21), Mendix Studio Pro 11.0 (All versions), Mendix Studio Pro 11.1 (All versions), Mendix Studio Pro 11.10 (All versions), Mendix Studio Pro 11.11 (All versions), Mendix Studio Pro 11.2 (All versions), Mendix Studio Pro 11.3 (All versions), Mendix Studio Pro 11.4 (All versions), Mendix Studio Pro 11.5 (All versions), Mendix Studio Pro 11.6 (All versions < V11.6.7), Mendix Studio Pro 11.7 (All versions), Mendix Studio Pro 11.8 (All versions), Mendix Studio Pro 11.9 (All versions). Affected versions of Mendix Studio Pro do not properly validate or sanitize project files processed during the build pipeline. This could allow an attacker who tricks a user into opening and running a specially crafted malicious project locally on their system to execute arbitrary code in the context of that user.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48192"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2025-36359",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DevOps Automation",
      "cwe": "CWE-613",
      "title": "IBM DevOps Loop is susceptible to an Insufficient Session Expiration vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36359"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-13945",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00193,
      "epss_percentile": 0.09345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Insufficient policy enforcement in Extensions in Google Chrome on Linux prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13945"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-13948",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00193,
      "epss_percentile": 0.09345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13948"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-56334",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-284",
      "title": "Capgo - Missing UPDATE RLS Policy for Build Status Persistence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56334"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-14013",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in SVG in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14013"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-13992",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.0916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in UI in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13992"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-8141",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.09023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Connekt Media",
      "product": "Ajax Load More - Filters",
      "cwe": "CWE-79",
      "title": "Ajax Load More - Filters <= 3.4.1 - Unauthenticated Stored Cross-Site Scripting via 'taxonomy_include_children' Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8141"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-14068",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14068"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-14083",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in HTML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14083"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-14073",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebXR in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14073"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-14076",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14076"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-14057",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in FedCM in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14057"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-14079",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14079"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-14080",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in TabSwitcher in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via malicious network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14080"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-56809",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ricoh Company, Ltd.",
      "product": "Multiple laser printers and MFPs which implement Ricoh Web Image Monitor",
      "cwe": "CWE-79",
      "title": "Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of the user who accesses a crafted URL.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56809"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-13942",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00187,
      "epss_percentile": 0.08617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Video Capture in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13942"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-13800",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13800"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-10129",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-918",
      "title": "SSRF via HTTP Redirect Following in Langflow API Request Component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10129"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-13863",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13863"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-13927",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13927"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-3602",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "App Connect Enterprise",
      "cwe": "CWE-89",
      "title": "IBM App Connect Enterprise and IBM Integration Bus for z/OS toolkit is vulnerable to an sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3602"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-10585",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitHub",
      "product": "Enterprise Server",
      "cwe": "CWE-79",
      "title": "Stored cross-site scripting vulnerability in GitHub Enterprise Server allowed arbitrary JavaScript execution via crafted Discussion titles in the Q&A category",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10585"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-13778",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00183,
      "epss_percentile": 0.08173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebUSB in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13778"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-13984",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.0825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-290",
      "title": "Incorrect security UI in TabStrip in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13984"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-13987",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in Mobile in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13987"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-13994",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Credential Management in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13994"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-14126",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in UI in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14126"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-14134",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Autofill in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14134"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-14047",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14047"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-14081",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.08014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14081"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-13914",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Passwords in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13914"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-14153",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.08003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14153"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-14046",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14046"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-13976",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.0783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Insufficient data validation in Storage in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13976"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-14131",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14131"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-14132",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in WebXR in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14132"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-14123",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14123"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-14128",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14128"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-14136",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14136"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-14143",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in Passwords in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14143"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-14137",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14137"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-56356",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.0756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-79",
      "title": "n8n - Stored Cross-Site Scripting in Chat Trigger Node Custom CSS Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56356"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-58450",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "invoiceninja",
      "product": "invoiceninja",
      "cwe": "CWE-601",
      "title": "Invoice Ninja 5.13.26 - Open Redirect in Client Portal Login via intended Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58450"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2026-13999",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13999"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-27956",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-639",
      "title": "Coolify: Cross-team application domain enumeration via domains_by_server endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27956"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2026-57082",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.0733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SANKO",
      "product": "Net::BitTorrent",
      "cwe": "CWE-330",
      "title": "Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57082"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2026-14031",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.0737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in File Input in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14031"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-14077",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.0737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Select in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14077"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-11594",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-79",
      "title": "IBM WebSphere Application Server is affected by multiple cross-site scripting vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11594"
    },
    {
      "rank": 564,
      "cve_id": "CVE-2026-14135",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14135"
    },
    {
      "rank": 565,
      "cve_id": "CVE-2026-14142",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1021",
      "title": "Inappropriate implementation in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14142"
    },
    {
      "rank": 566,
      "cve_id": "CVE-2026-14105",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in Speech in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14105"
    },
    {
      "rank": 567,
      "cve_id": "CVE-2026-14114",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14114"
    },
    {
      "rank": 568,
      "cve_id": "CVE-2026-13977",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in HTMLParser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13977"
    },
    {
      "rank": 569,
      "cve_id": "CVE-2026-14000",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14000"
    },
    {
      "rank": 570,
      "cve_id": "CVE-2026-14001",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14001"
    },
    {
      "rank": 571,
      "cve_id": "CVE-2026-14053",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14053"
    },
    {
      "rank": 572,
      "cve_id": "CVE-2026-13955",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0017,
      "epss_percentile": 0.06783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13955"
    },
    {
      "rank": 573,
      "cve_id": "CVE-2025-36333",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "watsonx.data intelligence",
      "cwe": "CWE-841",
      "title": "Vulnerabilities found in Watson Data Intelligence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36333"
    },
    {
      "rank": 574,
      "cve_id": "CVE-2026-13991",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13991"
    },
    {
      "rank": 575,
      "cve_id": "CVE-2026-56364",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00169,
      "epss_percentile": 0.06707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-401",
      "title": "ImageMagick - Memory Leak in LoadOpenCLDeviceBenchmark() via Malformed XML",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56364"
    },
    {
      "rank": 576,
      "cve_id": "CVE-2026-7874",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00168,
      "epss_percentile": 0.06499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-338",
      "title": "Weak Cryptographic Key Derivation Exposed All Stored Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7874"
    },
    {
      "rank": 577,
      "cve_id": "CVE-2026-9002",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Extreme Scale",
      "cwe": "CWE-400",
      "title": "IBM WebSphere eXtremes Scale is affected by uncontrolled resource consumption when XDF is enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9002"
    },
    {
      "rank": 578,
      "cve_id": "CVE-2026-56377",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-22",
      "title": "ImageMagick - Policy Bypass via Incorrect Path Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56377"
    },
    {
      "rank": 579,
      "cve_id": "CVE-2026-14028",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.0603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14028"
    },
    {
      "rank": 580,
      "cve_id": "CVE-2026-14138",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.0603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14138"
    },
    {
      "rank": 581,
      "cve_id": "CVE-2026-14139",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.0603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in TabStrip in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14139"
    },
    {
      "rank": 582,
      "cve_id": "CVE-2026-13849",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13849"
    },
    {
      "rank": 583,
      "cve_id": "CVE-2026-13827",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Updater in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13827"
    },
    {
      "rank": 584,
      "cve_id": "CVE-2026-13844",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13844"
    },
    {
      "rank": 585,
      "cve_id": "CVE-2026-12084",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.0591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "UCD - IBM DevOps Deploy",
      "cwe": "CWE-942",
      "title": "IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Permissive Cross-domain Security Policy with Untrusted Domains",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12084"
    },
    {
      "rank": 586,
      "cve_id": "CVE-2026-27881",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-639",
      "title": "Coolify: Cross-team deployment information disclosure via GET /api/v1/deployments/{uuid} (IDOR)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27881"
    },
    {
      "rank": 587,
      "cve_id": "CVE-2025-36324",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "watsonx.data intelligence",
      "cwe": "CWE-918",
      "title": "Vulnerabilities found in Watson Data Intelligence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36324"
    },
    {
      "rank": 588,
      "cve_id": "CVE-2026-14039",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in GetUserMedia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14039"
    },
    {
      "rank": 589,
      "cve_id": "CVE-2026-14026",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14026"
    },
    {
      "rank": 590,
      "cve_id": "CVE-2026-14030",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in SplitView in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14030"
    },
    {
      "rank": 591,
      "cve_id": "CVE-2025-36336",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "watsonx.data intelligence",
      "cwe": "CWE-319",
      "title": "Cleartext Transmission of Sensitive Information in Watson Data Intelligence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36336"
    },
    {
      "rank": 592,
      "cve_id": "CVE-2026-13983",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13983"
    },
    {
      "rank": 593,
      "cve_id": "CVE-2025-36320",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "watsonx.data intelligence",
      "cwe": "CWE-79",
      "title": "Vulnerabilities found in Watson Data Intelligence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36320"
    },
    {
      "rank": 594,
      "cve_id": "CVE-2026-35096",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KTM System",
      "product": "e-BOK",
      "cwe": "CWE-352",
      "title": "Cross-Site Request Forgery (CSRF) in KTM System e-BOK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35096"
    },
    {
      "rank": 595,
      "cve_id": "CVE-2026-13905",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive information from process memory via physical access to the device. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13905"
    },
    {
      "rank": 596,
      "cve_id": "CVE-2026-13993",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13993"
    },
    {
      "rank": 597,
      "cve_id": "CVE-2026-13997",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in Extensions in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13997"
    },
    {
      "rank": 598,
      "cve_id": "CVE-2026-13998",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in File Input in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13998"
    },
    {
      "rank": 599,
      "cve_id": "CVE-2026-14129",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in PreviewTab in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14129"
    },
    {
      "rank": 600,
      "cve_id": "CVE-2026-14150",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Speech in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14150"
    },
    {
      "rank": 601,
      "cve_id": "CVE-2026-58302",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LinuxCNC",
      "product": "LinuxCNC",
      "cwe": "CWE-22",
      "title": "rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads shared library modules via dlopen() by using a user-supplied module name. Insufficient validation of the module name allows path traversal, enabling an unprivileged local user to load an arbitrary shared library. Because the process retains elevated privileges during module loading, this results in local privilege escalation to root.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58302"
    },
    {
      "rank": 602,
      "cve_id": "CVE-2026-8403",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eksagate Electronic Engineering and Computer Industry Trade Inc.",
      "product": "SYSGUARD 6001",
      "cwe": "CWE-79",
      "title": "Stored XSS in Exagate's SYSGUARD 6001",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8403"
    },
    {
      "rank": 603,
      "cve_id": "CVE-2026-14133",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in History Embeddings in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14133"
    },
    {
      "rank": 604,
      "cve_id": "CVE-2026-14145",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14145"
    },
    {
      "rank": 605,
      "cve_id": "CVE-2026-14003",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14003"
    },
    {
      "rank": 606,
      "cve_id": "CVE-2026-14092",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in Privacy in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged network position to leak cross-origin data via malicious network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14092"
    },
    {
      "rank": 607,
      "cve_id": "CVE-2026-12578",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deltaww",
      "product": "DTMSoft",
      "cwe": "CWE-502",
      "title": "DTMSoft - Deserialization of Untrusted Data Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12578"
    },
    {
      "rank": 608,
      "cve_id": "CVE-2026-10546",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-918",
      "title": "DNS Rebinding TOCTOU Bypass of SSRF Protection in Langflow OSS URL Component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10546"
    },
    {
      "rank": 609,
      "cve_id": "CVE-2026-27882",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-208",
      "title": "Coolify: Timing Attack in GitLab Webhook Token Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27882"
    },
    {
      "rank": 610,
      "cve_id": "CVE-2026-14147",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14147"
    },
    {
      "rank": 611,
      "cve_id": "CVE-2026-35095",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "KTM System",
      "product": "e-BOK",
      "cwe": "CWE-384",
      "title": "Session fixation in KTM System e-BOK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35095"
    },
    {
      "rank": 612,
      "cve_id": "CVE-2026-50110",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00141,
      "epss_percentile": 0.03915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StoneFly",
      "product": "Storage Concentrator",
      "cwe": "CWE-798",
      "title": "Use of Hard-coded Credentials in StoneFly Storage Concentrator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50110"
    },
    {
      "rank": 613,
      "cve_id": "CVE-2026-14063",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive information from process memory via malicious network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14063"
    },
    {
      "rank": 614,
      "cve_id": "CVE-2026-11581",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Kali Forms — Contact Form & Drag-and-Drop Builder",
      "cwe": null,
      "title": "Kali Forms < 2.4.13 - Contributor+ Stored XSS via Form Field Caption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11581"
    },
    {
      "rank": 615,
      "cve_id": "CVE-2026-54672",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.03497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "electron-userland",
      "product": "electron-builder",
      "cwe": "CWE-427",
      "title": "electron-updater: Uncontrolled search path elements within `AppImage` built by `app-builder-lib`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54672"
    },
    {
      "rank": 616,
      "cve_id": "CVE-2026-56277",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-346",
      "title": "Flowise - Hardcoded CORS Wildcard in TTS Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56277"
    },
    {
      "rank": 617,
      "cve_id": "CVE-2025-12530",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "watsonx.data intelligence",
      "cwe": "CWE-319",
      "title": "Vulnerabilities found in Watson Data Intelligence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12530"
    },
    {
      "rank": 618,
      "cve_id": "CVE-2025-36323",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "watsonx.data intelligence",
      "cwe": "CWE-79",
      "title": "Vulnerabilities found in Watson Data Intelligence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36323"
    },
    {
      "rank": 619,
      "cve_id": "CVE-2026-14144",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14144"
    },
    {
      "rank": 620,
      "cve_id": "CVE-2026-14154",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14154"
    },
    {
      "rank": 621,
      "cve_id": "CVE-2026-14060",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.0303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14060"
    },
    {
      "rank": 622,
      "cve_id": "CVE-2026-56361",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-125",
      "title": "ImageMagick - Heap Buffer Overflow via Off-by-One in Morphology Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56361"
    },
    {
      "rank": 623,
      "cve_id": "CVE-2026-12610",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-825",
      "title": "Sssd: use-after-free crash in sssd' 'sssd_pam' process",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12610"
    },
    {
      "rank": 624,
      "cve_id": "CVE-2026-14048",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via a malicious peripheral. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14048"
    },
    {
      "rank": 625,
      "cve_id": "CVE-2026-54896",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00119,
      "epss_percentile": 0.02086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ohler55",
      "product": "oj",
      "cwe": "CWE-122",
      "title": "Oj: Heap Buffer Overflow in Oj.dump Exception Serialization via Large Indent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54896"
    },
    {
      "rank": 626,
      "cve_id": "CVE-2026-13455",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.02042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DALIBO",
      "product": "PostgreSQL Anonymizer",
      "cwe": "CWE-328",
      "title": "PostgreSQL Anonymizer: Unrestricted function can leak the secret salt",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13455"
    },
    {
      "rank": 627,
      "cve_id": "CVE-2026-54897",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00117,
      "epss_percentile": 0.0196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ohler55",
      "product": "oj",
      "cwe": "CWE-416",
      "title": "Oj : Use-After-Free in Oj::Doc Iterators via Reentrant Close",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54897"
    },
    {
      "rank": 628,
      "cve_id": "CVE-2026-54898",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00117,
      "epss_percentile": 0.0196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ohler55",
      "product": "oj",
      "cwe": "CWE-416",
      "title": "Oj: Use-After-Free in Oj::Parser SAJ Callback via Input Mutation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54898"
    },
    {
      "rank": 629,
      "cve_id": "CVE-2026-14119",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.0188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in Bluetooth in Google Chrome on Windows prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via a malicious peripheral. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14119"
    },
    {
      "rank": 630,
      "cve_id": "CVE-2026-56363",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-190",
      "title": "ImageMagick - Division by Zero in Binomial Kernel Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56363"
    },
    {
      "rank": 631,
      "cve_id": "CVE-2025-24815",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nokia",
      "product": "MantaRay NM",
      "cwe": "CWE-434",
      "title": "An unrestricted file upload vulnerability in Nokia MantaRay NM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-24815"
    },
    {
      "rank": 632,
      "cve_id": "CVE-2026-14018",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00108,
      "epss_percentile": 0.01373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14018"
    },
    {
      "rank": 633,
      "cve_id": "CVE-2026-8864",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00108,
      "epss_percentile": 0.01374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc.",
      "product": "HP Fan Control App",
      "cwe": "CWE-428",
      "title": "HP Fan Control App – Potential Escalation of Privilege",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8864"
    },
    {
      "rank": 634,
      "cve_id": "CVE-2026-13316",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6",
      "cwe": "CWE-918",
      "title": "Foreman: ssrf to cloud metada service through unvalidated test_url parameters in foreman config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13316"
    },
    {
      "rank": 635,
      "cve_id": "CVE-2026-14124",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00102,
      "epss_percentile": 0.01054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in CredentialProvider in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14124"
    },
    {
      "rank": 636,
      "cve_id": "CVE-2026-8944",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "engagementanalytics",
      "product": "Plugin for Google Analytics by IO technologies",
      "cwe": "CWE-352",
      "title": "Plugin for Google Analytics by IO technologies <= 1.1 - Cross-Site Request Forgery via 'ga_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8944"
    },
    {
      "rank": 637,
      "cve_id": "CVE-2026-12086",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.01048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "UCD - IBM UrbanCode Deploy",
      "cwe": "CWE-532",
      "title": "IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to a Insertion of Sensitive Information into Log File Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12086"
    },
    {
      "rank": 638,
      "cve_id": "CVE-2025-7406",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00094,
      "epss_percentile": 0.0068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nokia",
      "product": "MantaRay NM",
      "cwe": "CWE-269",
      "title": "A Sudo Privilege Escalation Vulnerability in Nokia MantaRay NM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-7406"
    },
    {
      "rank": 639,
      "cve_id": "CVE-2026-14094",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00092,
      "epss_percentile": 0.0061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Installer in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14094"
    },
    {
      "rank": 640,
      "cve_id": "CVE-2026-14160",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0009,
      "epss_percentile": 0.00528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "Escargot",
      "cwe": "CWE-367",
      "title": "Time-of-check time-of-use (TOCTOU) race condition vulnerability in Samsung Open Source Escargot allows Leveraging Race Conditions. This issue affects Escargot: bab3a5797557014ce3c2e28419a6310cfba90d0d.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14160"
    },
    {
      "rank": 641,
      "cve_id": "CVE-2026-53692",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00082,
      "epss_percentile": 0.00272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Redeight",
      "product": "Redeight CMS",
      "cwe": "CWE-328",
      "title": "Weak hashing algorithm in Redeight CMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53692"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10652",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10652 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10653",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10653 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10654",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10654 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10655",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10655 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4629",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4629 (Red Hat build of Keycloak 26.4). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54672",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54672 (electron-userland electron-builder). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56364",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56364 (ImageMagick). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58010",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58010 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58012",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58012 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58013",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58013 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58014",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58014 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58015",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58015 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58016",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58016 (GNOME GLib). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-9263",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-9263 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-20262",
      "detail": "DUE DATE PASSED — CVE-2026-20262 (Cisco Catalyst SD-WAN Manager). CISA remediation deadline was June 29, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
