{
  "day": "2026-07-01",
  "boundary": "UTC calendar day",
  "published_count": 365,
  "by_severity": {
    "CRITICAL": 58,
    "HIGH": 123,
    "MEDIUM": 166,
    "LOW": 8
  },
  "kev_count": 1,
  "exploit_reference_count": 13,
  "awaiting_enrichment_count": 10,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-45659",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.09863,
      "epss_percentile": 0.95172,
      "kev": true,
      "kev_due_at": "2026-07-04",
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-502",
      "title": "Microsoft SharePoint Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45659"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-50160",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.1775,
      "epss_percentile": 0.96916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hoppscotch",
      "product": "hoppscotch",
      "cwe": "CWE-915",
      "title": "Mass Assignment via Onboarding Endpoint Allows Unauthenticated JWT_SECRET Overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50160"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-58452",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.02422,
      "epss_percentile": 0.82868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JAIOTlink",
      "product": "C492A-W6 Wi-Fi IP Camera",
      "cwe": "CWE-78",
      "title": "JAIOTlink C492A-W6 4.8.30.57701411 OS Command Injection via SetMAC Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58452"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-58453",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0169,
      "epss_percentile": 0.75217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JAIOTlink",
      "product": "C492A-W6 Wi-Fi IP Camera",
      "cwe": "CWE-1392",
      "title": "JAIOTlink C492A-W6 4.8.30.57701411 Hard-coded Credentials via anyka_ipc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58453"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-58457",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01657,
      "epss_percentile": 0.74715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shenzhen Aitemi E Commerce Co. Ltd.",
      "product": "M300 Wi-Fi Repeater",
      "cwe": "CWE-78",
      "title": "Shenzhen Aitemi M300 MT02 Unauthenticated OS Command Injection via protocol.csp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58457"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-7840",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01579,
      "epss_percentile": 0.73514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uvnc",
      "product": "UltraVNC",
      "cwe": "CWE-787",
      "title": "UltraVNC repeater HTTP server global buffer overflow via long URI (pre-auth RCE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7840"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-8857",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.01469,
      "epss_percentile": 0.71651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "timeline",
      "cwe": "CWE-94",
      "title": "Full RCE using EasyTimeline Extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8857"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-7838",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01403,
      "epss_percentile": 0.70397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uvnc",
      "product": "UltraVNC",
      "cwe": "CWE-190",
      "title": "UltraVNC viewer heap buffer overflow via integer overflow in RFB connection-failure reason length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7838"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-50043",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01367,
      "epss_percentile": 0.69659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Seiko Solutions Inc.",
      "product": "SkyBridge MB-A100/MB-A110",
      "cwe": "CWE-78",
      "title": "Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-A100/MB-A110. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product with an administrative privilege.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50043"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-58127",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01271,
      "epss_percentile": 0.67521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hyland",
      "product": "PACSgear MediaWriter",
      "cwe": "CWE-306",
      "title": "PACSgear MediaWriter 5.2.1 Unauthenticated RCE via .NET Remoting TCP Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58127"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-58126",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01205,
      "epss_percentile": 0.65848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hyland",
      "product": "PACSgear PACS Scan",
      "cwe": "CWE-306",
      "title": "PACSgear PACS Scan 5.2.1 Unauthenticated RCE via .NET Remoting TCP Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58126"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-57517",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01151,
      "epss_percentile": 0.64367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Control Web Panel",
      "product": "Control Web Panel",
      "cwe": "CWE-89",
      "title": "Control Web Panel < 0.9.8.1225 Blind SQL Injection via userRes Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57517"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-51947",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0113,
      "epss_percentile": 0.63824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-502",
      "title": "An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip) allows a remote attacker to execute arbitrary code via the Pivotal.Engine.Client.Services.Conversion.dll component. NOTE: this issue exists because of an incomplete fix for CVE-2026-39253.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51947"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-7828",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01057,
      "epss_percentile": 0.61793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uvnc",
      "product": "UltraVNC",
      "cwe": "CWE-190",
      "title": "UltraVNC repeater integer overflow in win_log malloc leading to heap overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7828"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-20191",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00919,
      "epss_percentile": 0.57473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Catalyst Center",
      "cwe": "CWE-22",
      "title": "Cisco Catalyst Center Arbitrary File Read Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20191"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-14191",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00886,
      "epss_percentile": 0.56448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RARLAB",
      "product": "WinRAR",
      "cwe": "CWE-129",
      "title": "WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14191"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-49119",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0069,
      "epss_percentile": 0.49986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gradio-app",
      "product": "gradio",
      "cwe": "CWE-22",
      "title": "Gradio < 6.16.0 Path Traversal via FileExplorer.preprocess()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49119"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-38142",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00685,
      "epss_percentile": 0.49787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "An unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set endpoint of Tenda AC18 v15.03.05.05 allows attackers to execute arbitrary commands via a crafted payload injected into the mac parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38142"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-34106",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0068,
      "epss_percentile": 0.4958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-78",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in subtitles.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34106"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-34107",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0068,
      "epss_percentile": 0.49579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-78",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in translate.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34107"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-13731",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00657,
      "epss_percentile": 0.48683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quantumcloud",
      "product": "WPBot – AI ChatBot for Live Support, Lead Generation, AI Services",
      "cwe": "CWE-79",
      "title": "WPBot <= 8.4.9 - Unauthenticated Stored Cross-Site Scripting via 'conversation' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13731"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-23537",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00646,
      "epss_percentile": 0.48216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Feast",
      "product": "Feast Feature Server",
      "cwe": "CWE-862",
      "title": "Feast: unauthenticated arbitrary file write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23537"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-13760",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00626,
      "epss_percentile": 0.47309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "AWS CDK",
      "cwe": "CWE-78",
      "title": "OS Command Injection in aws-cdk-lib Docker Bundling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13760"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-14439",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00601,
      "epss_percentile": 0.46145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Altium",
      "product": "Altium Enterprise Server",
      "cwe": "CWE-22",
      "title": "Path Traversal in Altium Git Service Allows Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14439"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-54428",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00587,
      "epss_percentile": 0.45495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HttpComponents Core",
      "cwe": "CWE-400",
      "title": "Apache HttpComponents Core: HPackDecoder Unlimited Header List Size Before SETTINGS ACK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54428"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-7829",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00571,
      "epss_percentile": 0.44747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uvnc",
      "product": "UltraVNC",
      "cwe": "CWE-787",
      "title": "UltraVNC repeater authenticated out-of-bounds write in rule parser via oversized token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7829"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-54399",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00565,
      "epss_percentile": 0.44431,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HttpComponents Core",
      "cwe": "CWE-400",
      "title": "Apache HttpComponents Core: Unbounded HTTP Header/Line Length in Default Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54399"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-20213",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00563,
      "epss_percentile": 0.44337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Endpoint",
      "cwe": "CWE-120",
      "title": "ClamAV PE File Format Processing Out-of-Bounds Memory Corruption Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20213"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-20214",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00563,
      "epss_percentile": 0.4434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Endpoint",
      "cwe": "CWE-120",
      "title": "ClamAV FSG File Format Processing Out-of-Bounds Memory Corruption Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20214"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-57516",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00553,
      "epss_percentile": 0.43795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anyscale, Inc",
      "product": "Ray",
      "cwe": "CWE-502",
      "title": "Ray < 2.56.0 Unsafe Deserialization RCE via WebDataset Reader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57516"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-34108",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00549,
      "epss_percentile": 0.43564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-78",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in text.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34108"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-34110",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00549,
      "epss_percentile": 0.43564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-78",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in complex_start.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34110"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-34111",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00549,
      "epss_percentile": 0.43565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-78",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speechmac_text.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34111"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-34116",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00549,
      "epss_percentile": 0.43564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-78",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in transcribe.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34116"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-58399",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00543,
      "epss_percentile": 0.43265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "antonio-castellon",
      "product": "module-auth",
      "cwe": "CWE-287",
      "title": "@acastellon/auth has an authentication bypass via spoofable headers in validateToken()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58399"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-34109",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00537,
      "epss_percentile": 0.4298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-78",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speech.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34109"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-34112",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00537,
      "epss_percentile": 0.4298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-78",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speechmac.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34112"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-34113",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00537,
      "epss_percentile": 0.4298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-78",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speech_text.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34113"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-34114",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00537,
      "epss_percentile": 0.42981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-78",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in translate_text.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34114"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-34115",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00537,
      "epss_percentile": 0.42979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-78",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in transcribe_amazon.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34115"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-34117",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00537,
      "epss_percentile": 0.42981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-78",
      "title": "Guardian Language-System Unauthenticated OS Command Injection via id Parameter in text_to_subtitles.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34117"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-52186",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00527,
      "epss_percentile": 0.42396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SQL Injection vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to execute arbitrary code via the gohead/sub_463bbc component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52186"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-7831",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00525,
      "epss_percentile": 0.42306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uvnc",
      "product": "UltraVNC",
      "cwe": "CWE-193",
      "title": "UltraVNC viewer off-by-one stack overflow in ServerInit desktop name parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7831"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-58454",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00523,
      "epss_percentile": 0.42147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JAIOTlink",
      "product": "C492A-W6 Wi-Fi IP Camera",
      "cwe": "CWE-94",
      "title": "JAIOTlink C492A-W6 4.8.30.57701411 RCE via /Anyka/config Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58454"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-11387",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00515,
      "epss_percentile": 0.41707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cozyvision1",
      "product": "SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery",
      "cwe": "CWE-287",
      "title": "SMS Alert <= 3.9.5 - Unauthenticated Privilege Escalation via Arbitrary Password Reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11387"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-24270",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00513,
      "epss_percentile": 0.41538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "AIStore framework",
      "cwe": "CWE-290",
      "title": "NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lead to denial of service, escalation of privileges, information disclosure, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24270"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2025-15646",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00512,
      "epss_percentile": 0.41499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BPS",
      "product": "HTML::Gumbo",
      "cwe": "CWE-125",
      "title": "HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15646"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-20215",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.005,
      "epss_percentile": 0.40771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Endpoint",
      "cwe": "CWE-120",
      "title": "ClamAV 7Zip File Format Processing Out-of-Bounds Memory Corruption Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20215"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-20216",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.005,
      "epss_percentile": 0.40771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Endpoint",
      "cwe": "CWE-770",
      "title": "ClamAV InstallShield File Format Processing Resource Exhaustion Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20216"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-20217",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.005,
      "epss_percentile": 0.40772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Endpoint",
      "cwe": "CWE-120",
      "title": "ClamAV PESpin File Format Processing Out-of-Bounds Memory Corruption Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20217"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-20243",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.005,
      "epss_percentile": 0.40772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Endpoint",
      "cwe": "CWE-120",
      "title": "ClamAV ALZ Archive Processing Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20243"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-20244",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.005,
      "epss_percentile": 0.40772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Secure Endpoint",
      "cwe": "CWE-120",
      "title": "ClamAV DMG File Processing Denial of Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20244"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-24264",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00481,
      "epss_percentile": 0.39632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Triton Inference Server",
      "cwe": "CWE-409",
      "title": "NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause improper handling of highly compressed data. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24264"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-34099",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00459,
      "epss_percentile": 0.38195,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-89",
      "title": "Guardian Language-System Unauthenticated SQL Injection via id Parameter in job_info.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34099"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-6687",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00458,
      "epss_percentile": 0.38118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ChaN",
      "product": "FatFs",
      "cwe": "CWE-121",
      "title": "FatFs Stack Buffer Overflow via Uncapped exFAT Label Length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6687"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-50521",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00456,
      "epss_percentile": 0.3802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-416",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50521"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-52190",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00452,
      "epss_percentile": 0.37718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_448384 component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52190"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-24266",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.37287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Triton Inference Server",
      "cwe": "CWE-416",
      "title": "NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause a use-after-free issue. A successful exploit of this vulnerability might lead to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24266"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-6683",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00429,
      "epss_percentile": 0.35973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ChaN",
      "product": "FatFs",
      "cwe": "CWE-369",
      "title": "FatFs Divide-by-Zero in exFAT Sync",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6683"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-6684",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00429,
      "epss_percentile": 0.35973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ChaN",
      "product": "FatFs",
      "cwe": "CWE-835",
      "title": "FatFs Infinite Loop in GPT Partition Scan",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6684"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-6682",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00428,
      "epss_percentile": 0.35845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ChaN",
      "product": "FatFs",
      "cwe": "CWE-190",
      "title": "FatFs Integer Overflow in FAT32 Volume Mount",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6682"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-6688",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00428,
      "epss_percentile": 0.3585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ChaN",
      "product": "FatFs",
      "cwe": "CWE-120",
      "title": "FatFs Buffer Overflow via Unbounded LFN Filename Copy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6688"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-7839",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00425,
      "epss_percentile": 0.3568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uvnc",
      "product": "UltraVNC",
      "cwe": "CWE-798",
      "title": "UltraVNC repeater ships hardcoded default admin password allowing unauthenticated admin access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7839"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-14265",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "AWS Advanced JDBC Wrapper",
      "cwe": "CWE-502",
      "title": "RCE via Deserialization in AWS Advanced JDBC Wrapper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14265"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-6070",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00409,
      "epss_percentile": 0.34233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cmsjunkie",
      "product": "WP-BusinessDirectory – Business directory plugin for WordPress",
      "cwe": "CWE-73",
      "title": "WP-BusinessDirectory <= 4.0.1 - Unauthenticated Arbitrary File Deletion via Path Traversal via '_filename' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6070"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-58451",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00409,
      "epss_percentile": 0.34252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "horde",
      "product": "imp",
      "cwe": "CWE-22",
      "title": "Horde IMP < 7.0.1 Path Traversal via Compose.php img src",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58451"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-53355",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00399,
      "epss_percentile": 0.33269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "net: rds: clear i_sends on setup unwind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53355"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-44042",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00388,
      "epss_percentile": 0.3214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uvnc",
      "product": "UltraVNC",
      "cwe": "CWE-193",
      "title": "UltraVNC repeater wi_uudecode off-by-one in base64 decode boundary check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44042"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-6686",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00378,
      "epss_percentile": 0.31066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ChaN",
      "product": "FatFs",
      "cwe": "CWE-908",
      "title": "FatFs Use of Uninitialized Clusters After Seek Past EOF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6686"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-34100",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00373,
      "epss_percentile": 0.30541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-89",
      "title": "Guardian Language-System Unauthenticated SQL Injection via id Parameter in media.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34100"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-34101",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00373,
      "epss_percentile": 0.30541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-89",
      "title": "Guardian Language-System Unauthenticated SQL Injection via id Parameter in text_file.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34101"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-34102",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00373,
      "epss_percentile": 0.30541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-89",
      "title": "Guardian Language-System Unauthenticated SQL Injection via id Parameter in job_info_get.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34102"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-34103",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00373,
      "epss_percentile": 0.3054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-89",
      "title": "Guardian Language-System Unauthenticated SQL Injection via id Parameter in subtitles.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34103"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-34104",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00373,
      "epss_percentile": 0.30541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-89",
      "title": "Guardian Language-System Unauthenticated SQL Injection via name Parameter in designer.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34104"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-34105",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00373,
      "epss_percentile": 0.3054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-89",
      "title": "Guardian Language-System Unauthenticated SQL Injection via id Parameter in translate_text.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34105"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-56149",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00368,
      "epss_percentile": 0.30022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56149"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-13468",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00367,
      "epss_percentile": 0.29939,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeisle",
      "product": "Visualizer – Tables & Charts Manager with Built-in AI Generator",
      "cwe": "CWE-862",
      "title": "Visualizer <= 4.0.3 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via /visualizer/v1/action/{chart}/{type}/ REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13468"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-11883",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WebAuthn Provider for Two Factor",
      "cwe": null,
      "title": "WebAuthn Provider for Two Factor < 2.5.6 - 2FA Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11883"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-56016",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00361,
      "epss_percentile": 0.29401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MARKSTOS",
      "product": "CGI::Session::ID::md5",
      "cwe": "CWE-338",
      "title": "CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56016"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-8387",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00357,
      "epss_percentile": 0.28976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "allegroai",
      "product": "allegroai/clearml",
      "cwe": "CWE-23",
      "title": "Relative Path Traversal in allegroai/clearml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8387"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-56150",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.28214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Fleet Server",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in Fleet Server Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56150"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-14383",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.28029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-94",
      "title": "Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14383"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-53492",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "containerd",
      "product": "containerd",
      "cwe": "CWE-20",
      "title": "containerd CRI checkpoint restore CDI annotation smuggling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53492"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-56148",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00347,
      "epss_percentile": 0.27894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-674",
      "title": "Uncontrolled Recursion in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56148"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-36912",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A NULL pointer dereference in the AP4_AtomSampleTable::GetSample() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36912"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-38891",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-20",
      "title": "An improper input validation in the gazebo_ros_diff_drive.cpp component of gazebo_plugins v3.9.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted geometry_msgs::Twist message.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38891"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-12127",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More",
      "cwe": "CWE-93",
      "title": "WPForms <= 1.10.2 - Improper Neutralization of CRLF Sequences to Unauthenticated Email Header Injection via Reply-To Display Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12127"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-53906",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0034,
      "epss_percentile": 0.27093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MyComplianceOffice",
      "product": "MCO",
      "cwe": "CWE-22",
      "title": "Path Disclosure and Path Traversal in MCO",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53906"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-51946",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.26678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) allows a remote attacker to execute arbitrary code and obtain sensitive information via the the __sort_type URL parameter on all /admin/info/{table} endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51946"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-50195",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00332,
      "epss_percentile": 0.2626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "containerd",
      "product": "containerd",
      "cwe": "CWE-345",
      "title": "containerd: CRI checkpoint import allows local image tag poisoning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50195"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-55791",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.26071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-79",
      "title": "Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55791"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-13706",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.00328,
      "epss_percentile": 0.25819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "UrlShortener",
      "cwe": "CWE-20",
      "title": "UrlShortener extension url validation can be bypassed due to difference between php url parsing and WHATWG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13706"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-14385",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14385"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-55153",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "swaldman",
      "product": "mchange-commons-java",
      "cwe": "CWE-470",
      "title": "mchange-commons-java contains elements susceptible to abuse via JNDI injection and \"deserialization gadgets\"",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55153"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-5136",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.25607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6.16 for RHEL 8",
      "cwe": "CWE-266",
      "title": "Foreman: foreman: privilege escalation to administrator-level access via usergroup role assignment manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5136"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-58025",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.2542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "MediaWiki",
      "cwe": "CWE-94",
      "title": "Remote Code Execution via Unsafe Deserialization in LogItem Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58025"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-54908",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0032,
      "epss_percentile": 0.24909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pion",
      "product": "dtls",
      "cwe": "CWE-125",
      "title": "Pion DTLS: Denial of service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54908"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-14407",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-94",
      "title": "Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14407"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-12110",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "taskbuilder",
      "product": "Taskbuilder – Project Management & Task Management Tool With Kanban Board",
      "cwe": "CWE-89",
      "title": "Taskbuilder <= 5.0.8 - Authenticated (Subscriber+) SQL Injection via 'task_search' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12110"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-24260",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Container Toolkit",
      "cwe": "CWE-367",
      "title": "NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use race condition. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, and data tampering.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24260"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-44041",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uvnc",
      "product": "UltraVNC",
      "cwe": "CWE-125",
      "title": "UltraVNC vncWc2Mb calls wcslen() before validating that the wide string is NUL-terminated",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44041"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-55886",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00315,
      "epss_percentile": 0.24348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xdan",
      "product": "jodit",
      "cwe": "CWE-1321",
      "title": "Jodit Editor: Prototype Pollution in Jodit via Jodit.modules.Helpers.set()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55886"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-58592",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LadybirdBrowser",
      "product": "Ladybird",
      "cwe": "CWE-787",
      "title": "Ladybird - Web-Reachable Code Execution via Dangling FunctionType Reference in WebAssembly ESM Integration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58592"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-55790",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-79",
      "title": "Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55790"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-12923",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "emarket-design",
      "product": "Video Gallery – YouTube Gallery, Playlist & Video Grid",
      "cwe": "CWE-98",
      "title": "Video Gallery <= 4.0.3 - Authenticated (Subscriber+) Arbitrary Function Call via 'path' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12923"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-12090",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0031,
      "epss_percentile": 0.23787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "taskbuilder",
      "product": "Taskbuilder – Project Management & Task Management Tool With Kanban Board",
      "cwe": "CWE-89",
      "title": "Taskbuilder <= 5.0.8 - Authenticated (Subscriber+) SQL Injection via 'wppm_proj_filter' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12090"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-14405",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00307,
      "epss_percentile": 0.23435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14405"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-12142",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webaways",
      "product": "NEX-Forms – Ultimate Forms Plugin for WordPress",
      "cwe": "CWE-79",
      "title": "NEX-Forms <= 9.2.2 - Unauthenticated Stored Cross-Site Scripting via '_name[]' Array Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12142"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-13228",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.2263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "latepoint",
      "product": "LatePoint – Calendar Booking Plugin for Appointments and Events",
      "cwe": "CWE-269",
      "title": "LatePoint <= 5.6.3 - Authenticated (Custom+) Privilege Escalation to Administrator via 'order[customer_id]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13228"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-14198",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00299,
      "epss_percentile": 0.22527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "@fastify/middie",
      "product": "@fastify/middie",
      "cwe": "CWE-436",
      "title": "@fastify/middie vulnerable to authorization bypass via encoded slash in path parameter values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14198"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-1239",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.2247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kstover",
      "product": "Ninja Forms – The Contact Form Builder That Grows With You",
      "cwe": "CWE-862",
      "title": "Ninja Forms <= 3.14.1 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via token/refresh REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1239"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-14363",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.21976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - Cargo Extension",
      "cwe": "CWE-89",
      "title": "Cargo Extension: SQLi in Special:Drilldown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14363"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-55794",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.2193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-94",
      "title": "Craft CMS: Potential authenticated Remote Code Execution via referrer redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55794"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-12904",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stellarwp",
      "product": "Kadence Blocks — Page Builder Toolkit for Gutenberg Editor",
      "cwe": "CWE-639",
      "title": "Kadence Blocks <= 3.7.7 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Optimizer Data Deletion/Read/Modification via 'post_path' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12904"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-14430",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14430"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-14181",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "@fastify/middie",
      "product": "@fastify/middie",
      "cwe": "CWE-248",
      "title": "@fastify/middie standalone engine vulnerable to Denial of Service via malformed percent-encoded paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14181"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-13603",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00288,
      "epss_percentile": 0.21375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "pretix-oppwa",
      "cwe": "CWE-20",
      "title": "SSRF with API key leak in pretix-oppwa",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13603"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-11823",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.21054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repute Infosystems",
      "product": "BookingPress Appointment Booking Pro",
      "cwe": "CWE-89",
      "title": "BookingPress Appointment Booking Pro <= 5.7.1 - Unauthenticated SQL Injection via 'store_service_date' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11823"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-11568",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.20948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Product Configurator for WooCommerce",
      "cwe": null,
      "title": "Product Configurator for WooCommerce < 1.7.3 - Unauthenticated Private/Draft Product Data Disclosure via pc_get_data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11568"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-57692",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LCweb",
      "product": "PrivateContent",
      "cwe": "CWE-266",
      "title": "WordPress PrivateContent plugin <= 9.9.2 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57692"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-58521",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00283,
      "epss_percentile": 0.20911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - Cargo Extension",
      "cwe": "CWE-89",
      "title": "SQLi in Cargo extension via year range filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58521"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-44040",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00283,
      "epss_percentile": 0.20857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uvnc",
      "product": "UltraVNC",
      "cwe": "CWE-338",
      "title": "UltraVNC vncauth.c uses time-seeded libc rand() to generate VNC authentication challenge bytes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44040"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-49087",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49087"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-56151",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-20",
      "title": "Improper Input Validation in Kibana Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56151"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-14393",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14393"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-58024",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "MediaWiki",
      "cwe": "CWE-200",
      "title": "API identification of users on private wikis",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58024"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-12575",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deltaww",
      "product": "DVP80ES3",
      "cwe": "CWE-404",
      "title": "DVP80ES3 Improper Resource Shutdown or Release Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12575"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-5142",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6.16 for RHEL 8",
      "cwe": "CWE-639",
      "title": "Foreman: foreman: cross-tenant private ssh key disclosure via taxonomy scoping bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5142"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-5051",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Vault",
      "cwe": "CWE-22",
      "title": "Audit Log Plugin Directory Guard Bypass via Legacy path Option",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5051"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-14387",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00276,
      "epss_percentile": 0.20118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14387"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-14392",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00276,
      "epss_percentile": 0.20119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14392"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-12579",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deltaww",
      "product": "AS228T",
      "cwe": "CWE-288",
      "title": "AS228T - Authentication Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12579"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-54756",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.19759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xdan",
      "product": "jodit",
      "cwe": "CWE-1321",
      "title": "Jodit Editor: Prototype pollution via Jodit.configure() / ConfigMerge",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54756"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-50280",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.19701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-284",
      "title": "Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50280"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-14422",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14422"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-12902",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stellarwp",
      "product": "Kadence Blocks — Page Builder Toolkit for Gutenberg Editor",
      "cwe": "CWE-862",
      "title": "Kadence Blocks <= 3.7.7 - Missing Authorization to Authenticated (Contributor+) Arbitrary Media Attachment Creation via kadence_import_process_pattern/kadence_import_process_data AJAX Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12902"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-13602",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.1959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix",
      "product": "pretix",
      "cwe": "CWE-20",
      "title": "Session takeover vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13602"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2025-23350",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00269,
      "epss_percentile": 0.19158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "BlueField GA",
      "cwe": "CWE-787",
      "title": "NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-23350"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2025-23351",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00269,
      "epss_percentile": 0.19159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "BlueField GA",
      "cwe": "CWE-787",
      "title": "NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write out of bounds by crafted input. A successful exploit of this vulnerability may lead to arbitrary code execution on the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-23351"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-10539",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00268,
      "epss_percentile": 0.19038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BMC",
      "product": "Control-M/Server",
      "cwe": "CWE-305",
      "title": "Unauthenticated command injection in Control-M/Server communication command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10539"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-55792",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.1901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-200",
      "title": "Craft CMS: Sensitive File Disclosure / Server-Side File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55792"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-10750",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Royal MCP",
      "cwe": null,
      "title": "Royal MCP < 1.4.26 - Subscriber+ Insufficient Authorization in MCP Tools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10750"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-11988",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00267,
      "epss_percentile": 0.18976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thimpress",
      "product": "LearnPress – WordPress LMS Plugin for Create and Sell Online Courses",
      "cwe": "CWE-639",
      "title": "LearnPress <= 4.3.9.1 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Information Disclosure via 'userId' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11988"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-5135",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6.16 for RHEL 8",
      "cwe": "CWE-639",
      "title": "Foreman: foreman: unauthorized modification of host configurations via broken access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5135"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-14258",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-835",
      "title": "Dhcpcd: dhcpcd infinite loop and out-of-bounds read via zero-length ipv6 nd option in router advertisement handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14258"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-14382",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00265,
      "epss_percentile": 0.18536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14382"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-14409",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.18556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14409"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-47262",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.18533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "containerd",
      "product": "containerd",
      "cwe": "CWE-400",
      "title": "containerd image-triggered runtime DoS via unbounded group parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47262"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-50283",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.18558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-639",
      "title": "Craft CMS: Unauthorized Deletion of Source Assets During File Replacement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50283"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-14395",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.18496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14395"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-14431",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.18473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14431"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-14193",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deltaww",
      "product": "DVP80ES300T",
      "cwe": "CWE-129",
      "title": "DVP80ES300T - Improper Validation of Array Index Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14193"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-54712",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-java-instrumentation",
      "cwe": "CWE-400",
      "title": "OpenTelemetry Javaagent RMI context propagation allows resource exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54712"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-14384",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14384"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-14386",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14386"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-14388",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14388"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-13454",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jetmonsters",
      "product": "MotoPress Appointment Booking",
      "cwe": "CWE-89",
      "title": "MotoPress Appointment Booking <= 2.4.5 - Authenticated (Staff+) SQL Injection via 's' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13454"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-14340",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitHub",
      "product": "Enterprise Server",
      "cwe": "CWE-863",
      "title": "An incorrect authorization vulnerability in GitHub Enterprise Server allows issue creation in unrelated public repositories",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14340"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-14403",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14403"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-55793",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.1757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-79",
      "title": "Craft CMS: Stored XSS via Structure entry title in table view",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55793"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-12408",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.1756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rilwis",
      "product": "Slim SEO – A Fast & Automated SEO Plugin For WordPress",
      "cwe": "CWE-200",
      "title": "Slim SEO <= 4.9.8 - Authenticated (Contributor+) Insufficient Authorization to Private Content Disclosure via 'object.ID' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12408"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-58033",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "MediaWiki",
      "cwe": "CWE-200",
      "title": "\"Total number of distinct authors\" statistic at action=info does not exclude revisions where the author name was deleted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58033"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-14411",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00253,
      "epss_percentile": 0.1701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14411"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-14420",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00253,
      "epss_percentile": 0.17011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14420"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-14415",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.17011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14415"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-12577",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.1699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deltaww",
      "product": "DVP80ES3",
      "cwe": "CWE-358",
      "title": "DVP80ES3 Improperly Implemented Security Check for Standard vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12577"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-2891",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.16993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc",
      "product": "CCX",
      "cwe": "CWE-400",
      "title": "Poly Voice Devices (CCX, Trio, Edge E) – Potential Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2891"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-49090",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elasticsearch",
      "cwe": "CWE-400",
      "title": "Uncontrolled Resource Consumption in Elasticsearch Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49090"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-12133",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "beardev",
      "product": "JoomSport – for Sports: Team & League, Football, Hockey & more",
      "cwe": "CWE-862",
      "title": "JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Deletion via season_groupdel AJAX action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12133"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-14428",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14428"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-50284",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-862",
      "title": "Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50284"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-5138",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Satellite 6.16 for RHEL 8",
      "cwe": "CWE-639",
      "title": "Foreman: foreman: information disclosure via improper validation of nested request parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5138"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-14432",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14432"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-7517",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dhruvin",
      "product": "Custom Payment Gateways for WooCommerce",
      "cwe": "CWE-79",
      "title": "Custom Payment Gateways for WooCommerce <= 2.1.0 - Unauthenticated Stored Cross-Site Scripting via 'alg_wc_cpg_input_fields' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7517"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-13246",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stellarwp",
      "product": "GiveWP – Donation Plugin and Fundraising Platform",
      "cwe": "CWE-79",
      "title": "GiveWP <= 4.16.0 - Authenticated (Author+) Stored Cross-Site Scripting via 'block_id' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13246"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-10538",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BMC",
      "product": "Control-M/Enterprise Manager",
      "cwe": "CWE-502",
      "title": "Improper deserialization handling in Control-M Components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10538"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-14427",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14427"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-50279",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-285",
      "title": "Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50279"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-53903",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MyComplianceOffice",
      "product": "MCO",
      "cwe": "CWE-639",
      "title": "Insecure Direct Object Reference in MCO",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53903"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-58036",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00244,
      "epss_percentile": 0.15856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "MediaWiki",
      "cwe": "CWE-200",
      "title": "Users API leaks whether privileged users have their user groups disabled for lack of 2FA",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58036"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-14397",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00243,
      "epss_percentile": 0.15742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14397"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-14416",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00243,
      "epss_percentile": 0.15742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14416"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-55594",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-400",
      "title": "ImageMagick: Stack Overflow in MVG decoder due to missing depth check.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55594"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-13707",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.0024,
      "epss_percentile": 0.15323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "OAuth",
      "cwe": "CWE-384",
      "title": "Session fixation attacks on improperly configured OAuth 1.0a tools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13707"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-12224",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wedevs",
      "product": "Dokan Pro",
      "cwe": "CWE-269",
      "title": "Dokan Pro <= 5.0.4 - Authenticated (Vendor+) Privilege Escalation via update_capabilities REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12224"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-55661",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinacms",
      "product": "tinacms",
      "cwe": "CWE-79",
      "title": "TinaCMS rich-text (slatejson) rendering does not sanitize link/image URLs, allowing stored XSS via dangerous URL schemes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55661"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-14396",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.1506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14396"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-14401",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.15028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14401"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-14412",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.15027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14412"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-11794",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Advanced Form Integration — Connect Forms to 200+ Apps",
      "cwe": null,
      "title": "Advanced Form Integration < 2.1.1 - Unauthenticated Privilege Escalation via Breakdance Form Role Mapping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11794"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-14390",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00235,
      "epss_percentile": 0.14683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14390"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-14394",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14394"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-14414",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14414"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-9107",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpchill",
      "product": "Kali Forms — Contact Form & Drag-and-Drop Builder",
      "cwe": "CWE-79",
      "title": "Kali Forms <= 2.4.13 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'kaliforms_field_components' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9107"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-10095",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opajaap",
      "product": "WP Photo Album Plus",
      "cwe": "CWE-79",
      "title": "WP Photo Album Plus <= 9.1.13.005 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'subtext' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10095"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-14391",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14391"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-58027",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.1451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "AbuseFilter",
      "cwe": "CWE-200",
      "title": "QueryAbuseFilter API can be used to see the hit count of private filters, which is hidden in the UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58027"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-14389",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00233,
      "epss_percentile": 0.14466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-472",
      "title": "Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14389"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-12435",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stylemix",
      "product": "Motors – Car Dealership & Classified Listings Plugin",
      "cwe": "CWE-862",
      "title": "Motors <= 1.4.111 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Meta Modification via 'stm_mark_as_sold_car' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12435"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-58026",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.00232,
      "epss_percentile": 0.1438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "MediaWiki",
      "cwe": "CWE-200",
      "title": "$wgNonincludableNamespaces can be bypassed by embedding redirect in other namespaces",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58026"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-14429",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14429"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-12113",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codepeople",
      "product": "Appointment Booking Calendar",
      "cwe": "CWE-862",
      "title": "Appointment Booking Calendar <= 1.4.02 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12113"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-53909",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MyComplianceOffice",
      "product": "MCO",
      "cwe": "CWE-434",
      "title": "Arbitrary File Upload in MCO",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53909"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-55577",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-754",
      "title": "ImageMagick: Heap Buffer Overflow in ImageMagick MVG decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55577"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-14399",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14399"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-14402",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14402"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-14408",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14408"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-54704",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-java-instrumentation",
      "cwe": "CWE-532",
      "title": "OpenTelemetry Java Instrumentation: JDBC Auto-Instrumentation Logging Clear-Text Passwords",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54704"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-14400",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14400"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-14423",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00221,
      "epss_percentile": 0.1289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14423"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-46680",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "containerd",
      "product": "containerd",
      "cwe": "CWE-269",
      "title": "containerd user ID handling bypass allows runAsNonRoot evasion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46680"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-58029",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "MediaWiki",
      "cwe": "CWE-287",
      "title": "Full Account Takeover from BotPasswords and OAuth via action=changeauthenticationdata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58029"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-7830",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.1276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uvnc",
      "product": "UltraVNC",
      "cwe": "CWE-326",
      "title": "UltraVNC MS-Logon II uses 64-bit Diffie-Hellman and seeded libc rand() enabling credential interception",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7830"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-53466",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-190",
      "title": "ImageMagick: Heap Buffer Over-Read in XCF decoder due to integer conversion overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53466"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-57962",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Thunderbird",
      "cwe": "CWE-400",
      "title": "Denial-of-service via malicious LDAP address-book server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57962"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-55688",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AsyncHttpClient",
      "product": "async-http-client",
      "cwe": "CWE-1275",
      "title": "AsyncHttpClient: Cookie stored for an unrelated domain (cookie tossing) via ThreadSafeCookieStore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55688"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-54260",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.0022,
      "epss_percentile": 0.12798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wagtail",
      "product": "wagtail",
      "cwe": "CWE-400",
      "title": "Wagtail: Denial of service via unbounded filter specs in the image preview",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54260"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-14425",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00218,
      "epss_percentile": 0.126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14425"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-14426",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00217,
      "epss_percentile": 0.12396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14426"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-54786",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00217,
      "epss_percentile": 0.12446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bytecodealliance",
      "product": "wasmtime",
      "cwe": "CWE-400",
      "title": "Wasmtime: Leak in WASIp1 `fd_renumber` implementation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54786"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-14398",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00215,
      "epss_percentile": 0.12214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14398"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-14419",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00215,
      "epss_percentile": 0.12214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14419"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-14424",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00215,
      "epss_percentile": 0.12214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14424"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-14421",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14421"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-12754",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e4jvikwp",
      "product": "VikBooking Hotel Booking Engine & PMS",
      "cwe": "CWE-79",
      "title": "VikBooking Hotel Booking Engine & PMS <= 1.8.12 - Reflected Cross-Site Scripting via 'layoutstyle' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12754"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-13323",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Open VSX",
      "cwe": "CWE-79",
      "title": "In Open VSX Registry before 1.0.2, the /vscode/unpkg/ endpoint serves user-supplied HTML files with Content-Type: text/html and without a Content-Security-Policy or Content-Disposition: attachment response header. An unauthenticated attacker can register a publisher account, upload a VSIX containing a crafted HTML payload, and induce an authenticated user to visit the resulting URL. The browser renders the file inline in the open-vsx.org origin context, enabling session token exfiltration, persistent Personal Access Token (PAT) generation, and unauthorized publication of malicious extension versions. Because Open VSX extensions are distributed to VS Code, VSCodium, Cursor, Windsurf, and compatible editors, a compromised extension update constitutes a supply chain attack against all downstream users.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13323"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-14381",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-290",
      "title": "Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14381"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-58593",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.1164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NodeBB",
      "product": "NodeBB",
      "cwe": "CWE-290",
      "title": "NodeBB - ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to Local User",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58593"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-53908",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MyComplianceOffice",
      "product": "MCO",
      "cwe": "CWE-204",
      "title": "User Enumeration in MCO",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53908"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-13015",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jgwhite33",
      "product": "WP Google Review Slider",
      "cwe": "CWE-79",
      "title": "WP Google Review Slider <= 18.1 - Reflected Cross-Site Scripting via 'place' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13015"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-49088",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-532",
      "title": "Insertion of Sensitive Information into Log File in Kibana Leading to Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49088"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-5120",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.11397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dassault Systèmes",
      "product": "BIOVIA Workbook",
      "cwe": "CWE-362",
      "title": "Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 through Release 2026",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5120"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-53902",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00208,
      "epss_percentile": 0.113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MyComplianceOffice",
      "product": "MCO",
      "cwe": "CWE-266",
      "title": "Privilege Escalation in MCO",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53902"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-49858",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "api-platform",
      "product": "core",
      "cwe": "CWE-524",
      "title": "API Platform Core: Cross-user attribute leak in JSON:API and HAL item normalizers due to missing isCacheKeySafe gate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49858"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-14417",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00207,
      "epss_percentile": 0.1106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14417"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-12158",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "metagauss",
      "product": "RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login",
      "cwe": "CWE-352",
      "title": "RegistrationMagic <= 6.0.9.1 - Cross-Site Request Forgery to Privilege Escalation via 'rmc_assign_user_role_action' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12158"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-20458",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.10768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01402160; Issue ID: MSV-7298.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20458"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-53904",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MyComplianceOffice",
      "product": "MCO",
      "cwe": "CWE-307",
      "title": "Account Denial of Service in MCO",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53904"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-54263",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wagtail",
      "product": "wagtail",
      "cwe": "CWE-79",
      "title": "Wagtail: Reflected XSS in dynamic image URL generator view",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54263"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-57720",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Codexpert Inc",
      "product": "ThumbPress",
      "cwe": "CWE-862",
      "title": "WordPress ThumbPress plugin <= 6.3.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57720"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-14413",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14413"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-14404",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.1045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in PDFium in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted PDF file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14404"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-49091",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.10343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Kibana",
      "cwe": "CWE-116",
      "title": "Improper Output Neutralization for Logs in Kibana Leading to Log Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49091"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-54261",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wagtail",
      "product": "wagtail",
      "cwe": "CWE-280",
      "title": "Wagtail: Improper permission handling in image preview",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54261"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-13443",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Tutor LMS – eLearning and online course solution",
      "cwe": "CWE-79",
      "title": "Tutor LMS <= 3.9.13 - Authenticated (Author+) Stored Cross-Site Scripting via Lesson Attachment Title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13443"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-13733",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codename065",
      "product": "Download Manager",
      "cwe": "CWE-79",
      "title": "Download Manager <= 3.3.60 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13733"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-12135",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "foliovision",
      "product": "FV Flowplayer Video Player",
      "cwe": "CWE-79",
      "title": "FV Flowplayer Video Player <= 7.5.51.7212 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'video_player' Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12135"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-56152",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elastic",
      "product": "Elastic Defend",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in Elastic Defend Leading to Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56152"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-53467",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-200",
      "title": "ImageMagick: Information Disclosure in MNG decoder because allocated memory is left unchanged",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53467"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-55660",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00196,
      "epss_percentile": 0.09682,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinacms",
      "product": "tinacms",
      "cwe": "CWE-79",
      "title": "TinaCMS: Cross-origin postMessage handlers and rich-text URL-sanitization bypass enable stored XSS and session takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55660"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-10096",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qodeinteractive",
      "product": "Qi Blocks",
      "cwe": "CWE-639",
      "title": "Qi Blocks <= 1.4.9 - Insecure Direct Object Reference to Authenticated (Author+) Arbitrary Style Modification via 'page_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10096"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-14440",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00195,
      "epss_percentile": 0.09617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloudflare",
      "product": "Universal SSL",
      "cwe": "CWE-693",
      "title": "Cloudflare Universal SSL automatically managed CAA RRset supersedes customer-configured CAA records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14440"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-54164",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "api-platform",
      "product": "core",
      "cwe": "CWE-843",
      "title": "API Platform Core: Missing IRI type check enables resource type confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54164"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-58517",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - WikiLambda Extension",
      "cwe": "CWE-288",
      "title": "Blocked users can create and edit WikiLambda objects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58517"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-27409",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webba Plugins",
      "product": "Webba Booking",
      "cwe": "CWE-862",
      "title": "WordPress Webba Booking plugin <= 6.4.13 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27409"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-53905",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.0936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MyComplianceOffice",
      "product": "MCO",
      "cwe": "CWE-863",
      "title": "Unauthorized Access to Administrator ACL View in MCO",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53905"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-57963",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Thunderbird",
      "cwe": "CWE-79",
      "title": "Chat UI manipulation by injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57963"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-58032",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "MediaWiki",
      "cwe": "CWE-79",
      "title": "mw.Api.getErrorMessage() may return injected HTML if used without errorformat=html",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58032"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-14410",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14410"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-14406",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.08967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in V8 in Google Chrome prior to 150.0.7871.46 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14406"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-12732",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thimpress",
      "product": "LearnPress – WordPress LMS Plugin for Create and Sell Online Courses",
      "cwe": "CWE-79",
      "title": "LearnPress <= 4.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'class_wrapper_form' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12732"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-53489",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "containerd",
      "product": "containerd",
      "cwe": "CWE-61",
      "title": "containerd: Arbitrary host CRI log file read via symlink following in CRI checkpoint restore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53489"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-14418",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14418"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-41579",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00186,
      "epss_percentile": 0.08559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opencontainers",
      "product": "runc",
      "cwe": "CWE-61",
      "title": "runc: Malicious image with /dev symlink can trigger limited host filesystem integrity violations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41579"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-20457",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-476",
      "title": "In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01826924; Issue ID: MSV-7301.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20457"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-20461",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01267281 / MOLY01318201; Issue ID: MSV-6486.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20461"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-58263",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00179,
      "epss_percentile": 0.07792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xdan",
      "product": "jodit",
      "cwe": "CWE-79",
      "title": "Jodit Editor: Mutation XSS in jodit clean-html via a MathML/style rawtext carrier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58263"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-57721",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.0769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Reloaded",
      "product": "ApplyOnline",
      "cwe": "CWE-862",
      "title": "WordPress ApplyOnline plugin <= 2.6.7.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57721"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-11887",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Salon Booking System",
      "cwe": null,
      "title": "Salon Booking System < 10.30.20 - Subscriber+ Booking Approval Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11887"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-53488",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00176,
      "epss_percentile": 0.07465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "containerd",
      "product": "containerd",
      "cwe": "CWE-20",
      "title": "containerd CRI plugin: — image-config `LABEL` flows to restart-monitor `binary://` logger: host-root command execution from an image pull",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53488"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-58520",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - UrlShortener Extension",
      "cwe": "CWE-601",
      "title": "UrlShortener defaults to ineffective validation open to third-party redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58520"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-24243",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron-Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24243"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-24248",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron-Bridge",
      "cwe": "CWE-94",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24248"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-57736",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HubSpot",
      "product": "HubSpot",
      "cwe": "CWE-201",
      "title": "WordPress HubSpot plugin <= 11.3.51 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57736"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-14358",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - Charts Extension",
      "cwe": "CWE-79",
      "title": "Stored XSS in Wikimedia Chart pie tooltip via Data:*.tab field title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14358"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-14324",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-476",
      "title": "Pipewire: raop rtsp null deref",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14324"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-20460",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-288",
      "title": "In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01811421; Issue ID: MSV-6788.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20460"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-58030",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "SyntaxHighlight_GeSHi",
      "cwe": "CWE-79",
      "title": "SyntaxHighlight stored XSS via unsanitized 'linelinks' attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58030"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-27435",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06852,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WofficeIO",
      "product": "Woffice",
      "cwe": "CWE-862",
      "title": "WordPress Woffice theme < 5.4.33 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27435"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-58028",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.00171,
      "epss_percentile": 0.06854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "MediaWiki",
      "cwe": "CWE-79",
      "title": "Pretty-printed API output combined with centralauthtoken allows XSS with certain gadgets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58028"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-54074",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinacms",
      "product": "tinacms",
      "cwe": "CWE-94",
      "title": "@tinacms/cli: Remote Code Execution via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54074"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-24246",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00169,
      "epss_percentile": 0.0665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron-Bridge",
      "cwe": "CWE-470",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24246"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-24247",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00169,
      "epss_percentile": 0.0665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron-Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24247"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-20459",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-288",
      "title": "In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01816800; Issue ID: MSV-6842.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20459"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-58034",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.00169,
      "epss_percentile": 0.06633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "CheckUser",
      "cwe": "CWE-79",
      "title": "Stored XSS through a system message when blocking a temporary account that's related to other temporary accounts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58034"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-58035",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.00169,
      "epss_percentile": 0.06634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "MediaWiki",
      "cwe": "CWE-79",
      "title": "Stored XSS through a system message in the codex version of Special:Block",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58035"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-58037",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.00169,
      "epss_percentile": 0.06679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "MediaWiki",
      "cwe": "CWE-79",
      "title": "Core log entries for exceptions and XSS issues in log entry formatting code that may be caused by user-controlled input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58037"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-58038",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.00169,
      "epss_percentile": 0.06652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "timeline",
      "cwe": "CWE-79",
      "title": "Stored XSS through javascript URLs in SVGs generated by EasyTimeline",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58038"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-24240",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron-Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24240"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-24249",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron-Bridge",
      "cwe": "CWE-94",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24249"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-11562",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WS Form LITE",
      "cwe": null,
      "title": "WS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11562"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-54259",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wagtail",
      "product": "wagtail",
      "cwe": "CWE-280",
      "title": "Wagtail: Improper restriction handling on Documents and Images chosen endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54259"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-54262",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05874,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wagtail",
      "product": "wagtail",
      "cwe": "CWE-280",
      "title": "Wagtail: Pages translations can be created without page permissions when using simple_translation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54262"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-58031",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.00158,
      "epss_percentile": 0.0544,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wikimedia Foundation",
      "product": "MediaWiki",
      "cwe": "CWE-79",
      "title": "Stored i18n XSS in Special:ApiSandbox when a deprecated module is selected",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58031"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-24250",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.05231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron-Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper validation of allowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24250"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-24251",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.05231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron-Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of dynamically managed code resources. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24251"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-54720",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "silverstripe",
      "product": "silverstripe-framework",
      "cwe": "CWE-79",
      "title": "Silverstripe Framework: Possible XSS attack through media embed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54720"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-24244",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.05095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron-Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24244"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-24245",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.05095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron-Bridge",
      "cwe": "CWE-502",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24245"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-11981",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stellarwp",
      "product": "GiveWP – Donation Plugin and Fundraising Platform",
      "cwe": "CWE-352",
      "title": "GiveWP <= 4.15.3 - Cross-Site Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11981"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-12576",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00153,
      "epss_percentile": 0.05028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deltaww",
      "product": "DVP80ES3",
      "cwe": "CWE-924",
      "title": "DVP80ES3 Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12576"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-2387",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stephenharris",
      "product": "Event Organiser",
      "cwe": "CWE-79",
      "title": "Event Organiser <= 3.12.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via eo_events Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2387"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-11380",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jetmonsters",
      "product": "JetWidgets For Elementor",
      "cwe": "CWE-79",
      "title": "JetWidgets For Elementor <= 1.0.21 - Authenticated (Author+) Stored Cross-Site Scripting via Animated Box 'animation_effect' Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11380"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-24242",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "Megatron-Bridge",
      "cwe": "CWE-918",
      "title": "NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause server-side request forgery. A successful exploit of this vulnerability might lead to information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24242"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-5220",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DivvyDrive Information Technologies Inc.",
      "product": "DivvyDrive",
      "cwe": "CWE-79",
      "title": "Stored XSS in DivvyDrive Information Technologies' DivvyDrive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5220"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-57722",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ShortPixel",
      "product": "Enable Media Replace",
      "cwe": "CWE-79",
      "title": "WordPress Enable Media Replace plugin <= 4.2.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57722"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-34096",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-79",
      "title": "Guardian Language-System XSS via name Parameter in designer.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34096"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-34097",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-79",
      "title": "Guardian Language-System XSS via id Parameter in text_file.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34097"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-34098",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guardian",
      "product": "language-system",
      "cwe": "CWE-79",
      "title": "Guardian Language-System XSS via id Parameter in media.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34098"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-53329",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.04001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-674",
      "title": "drm/amd/display: Use krealloc_array() in dal_vector_reserve()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53329"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-53907",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.0387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MyComplianceOffice",
      "product": "MCO",
      "cwe": "CWE-79",
      "title": "Stored Cross‑Site Scripting in MCO",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53907"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-13211",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "genua",
      "product": "genucenter",
      "cwe": "CWE-201",
      "title": "Genucenter Disclosure of SNMP Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13211"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-11880",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00139,
      "epss_percentile": 0.03752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Fluent Forms",
      "cwe": null,
      "title": "Fluent Forms < 6.2.1 - Subscriber+ Subscription Cancellation via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11880"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-11570",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03545,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Submitted Posts",
      "cwe": null,
      "title": "User Submitted Posts < 20260608 - Unauthenticated Stored XSS via Author Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11570"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-57737",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Averta LTD",
      "product": "Shortcodes and extra features for Phlox theme",
      "cwe": "CWE-79",
      "title": "WordPress Shortcodes and extra features for Phlox theme plugin <= 2.17.16 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57737"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-58519",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.03329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - Cargo Extension",
      "cwe": "CWE-79",
      "title": "Stored XSS through Cargo's map format",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58519"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-6283",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DivvyDrive Information Technologies Inc.",
      "product": "DivvyDrive",
      "cwe": "CWE-79",
      "title": "Stored XSS in DivvyDrive Information Technologies' DivvyDrive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6283"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-53354",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03035,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "arm64: errata: Mitigate TLBI errata on various Arm CPUs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53354"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-53327",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.03036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "debugobjects: Do not fill_pool() if pi_blocked_on",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53327"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-12480",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00127,
      "epss_percentile": 0.02816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "keras-team",
      "product": "keras-team/keras",
      "cwe": "CWE-73",
      "title": "Arbitrary HDF5 File Read via Virtual Dataset Bypass in keras-team/keras",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12480"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-53341",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "fhandle: fix UAF due to unlocked ->mnt_ns read in may_decode_fh()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53341"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-57723",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e4jvikwp",
      "product": "VikBooking Hotel Booking Engine & PMS",
      "cwe": "CWE-352",
      "title": "WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.12 - CSRF to Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57723"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-53330",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.0254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "drm/amd/display: Fix out-of-bounds read in dp_get_eq_aux_rd_interval()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53330"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-41121",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00123,
      "epss_percentile": 0.02507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Device Management Agent",
      "cwe": "CWE-59",
      "title": "Dell Device Management Agent, versions prior to DDMA 26.05, contain an Improper Link Resolution Before File Access ('Link Following’) vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41121"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-53331",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53331"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-53332",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53332"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2025-15666",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00123,
      "epss_percentile": 0.02513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open Asset Import Library",
      "product": "Assimp",
      "cwe": "CWE-119",
      "title": "Open Asset Import Library Assimp Model File SceneCombiner.cpp Copy heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15666"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-53328",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sched_ext: Don't warn on NULL cgrp_moving_from in scx_cgroup_move_task()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53328"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-53356",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/i915/gem: Fix phys BO pread/pwrite with offset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53356"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-36909",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36909"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-53334",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "mm/damon/reclaim: handle ctx allocation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53334"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-53335",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.0211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "mm/damon/lru_sort: handle ctx allocation failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53335"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-13769",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.02008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "AWS CLI",
      "cwe": "CWE-732",
      "title": "Overly permissive File Permissions in AWS CLI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13769"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-53346",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "rust: arm64: set uwtable llvm module flag for CONFIG_UNWIND_TABLES",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53346"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-53336",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmem: layouts: onie-tlv: fix hang on unknown types",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53336"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-53337",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "net: bonding: fix NULL pointer dereference in bond_do_ioctl()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53337"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-53339",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "i2c: qcom-cci: Fix NULL pointer dereference in cci_remove()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53339"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-53343",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53343"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-53345",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "KVM: Don't WARN if memory is dirtied without a vCPU when the VM is dying",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53345"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-53347",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "drm/virtio: Fix driver removal with disabled KMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53347"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-53349",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: nf_conntrack: destroy stale expectfn expectations on unregister",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53349"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-53350",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "ASoC: wm_adsp: Fix NULL dereference when removing firmware controls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53350"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-53353",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hsr: Remove WARN_ONCE() in hsr_addr_is_self().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53353"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-36910",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.0165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-119",
      "title": "An access violation in the BaseSplitterFile::Read function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36910"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-53333",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "mm/mincore: handle non-swap entries before !CONFIG_SWAP guard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53333"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-53338",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "net: airoha: Add NULL check for of_reserved_mem_lookup() in airoha_qdma_init_hfwd_queues()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53338"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-53340",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i2c: imx: fix clock and pinctrl state inconsistency in runtime PM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53340"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-53342",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "arm64: mm: call pagetable dtor when freeing hot-removed page tables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53342"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-20462",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-122",
      "title": "In Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11006447; Issue ID: MSV-7871.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20462"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-36911",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-369",
      "title": "A division-by-zero vulnerability in the CStreamSwitcherOutputPin::DecideBufferSize function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36911"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-20463",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0011,
      "epss_percentile": 0.01456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-280",
      "title": "In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: MOLY01716533; Issue ID: MSV-6309.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20463"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-55510",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-416",
      "title": "ImageMagick: Use-After-Free in crafted 8BIM when identifying an image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55510"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-55597",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-682",
      "title": "ImageMagick: Heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55597"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-14330",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-770",
      "title": "Pipewire: pulse server alloca stack overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14330"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-53344",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "pinctrl: mcp23s08: Initialize mcp->dev and mcp->addr before regmap init",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53344"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-53348",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "ASoC: SDCA: fix NULL pointer dereference in sdca_dev_unregister_functions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53348"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-53351",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "riscv/ptrace: Use USER_REGSET_NOTE_TYPE for REGSET_CFI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53351"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-55628",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00098,
      "epss_percentile": 0.00876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-73",
      "title": "ImageMagick: Policy Bypass in concatenate operation due to missing checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55628"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-53326",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "debugobjects: Don't call fill_pool() in early boot hardirq context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53326"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-55595",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0009,
      "epss_percentile": 0.00533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-400",
      "title": "ImageMagick: Infinite Loop in connected-components when providing invalid arguments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55595"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-58518",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00088,
      "epss_percentile": 0.00467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Wikimedia Foundation",
      "product": "Mediawiki - RedirectManager Extension",
      "cwe": "CWE-352",
      "title": "Cross-Site request forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - RedirectManager Extension allows Cross Site Request Forgery. This issue affects Mediawiki - RedirectManager Extension: from * before 1.3.3.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58518"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-8480",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00087,
      "epss_percentile": 0.00422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stormshield",
      "product": "Stormshield Network Security",
      "cwe": "CWE-295",
      "title": "Connection possible to the Administration portal with a revoked certificate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8480"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-53352",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00086,
      "epss_percentile": 0.00393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "signal: clear JOBCTL_PENDING_MASK for caller in zap_other_threads()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53352"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-10540",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00078,
      "epss_percentile": 0.00148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BMC",
      "product": "Control-M/Enterprise Manager",
      "cwe": "CWE-328",
      "title": "Weak password hash protection in Control-M/Entreprise Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10540"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-12374",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00055,
      "epss_percentile": 0.00003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cato Networks",
      "product": "SDP Client",
      "cwe": "CWE-295",
      "title": "Improper XPC caller certificate validation and TOCTOU race condition in macOS PrivilegedHelperTool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12374"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13323",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13323 (Eclipse Foundation Eclipse Open VSX). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50160",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50160 (hoppscotch). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57516",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57516 (Anyscale, Inc Ray). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-6682",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-6682 (ChaN FatFs). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-6683",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-6683 (ChaN FatFs). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-6684",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-6684 (ChaN FatFs). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-6686",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-6686 (ChaN FatFs). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-6687",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-6687 (ChaN FatFs). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-6688",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-6688 (ChaN FatFs). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-8857",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-8857 (Wikimedia Foundation timeline). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
