{
  "day": "2026-07-02",
  "boundary": "UTC calendar day",
  "published_count": 265,
  "by_severity": {
    "CRITICAL": 32,
    "HIGH": 149,
    "MEDIUM": 78,
    "LOW": 6
  },
  "kev_count": 0,
  "exploit_reference_count": 4,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-58455",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.04856,
      "epss_percentile": 0.91322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Notifiarr",
      "product": "dockwatch",
      "cwe": "CWE-78",
      "title": "Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58455"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-50746",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02505,
      "epss_percentile": 0.8345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Connect Application",
      "cwe": "CWE-284",
      "title": "A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a Command Injection on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50746"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-9834",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.01542,
      "epss_percentile": 0.72928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "databasebackup",
      "product": "WP Database Backup – Unlimited Database & Files Backup by Backup for WP",
      "cwe": "CWE-77",
      "title": "WP Database Backup <= 7.11 - Authenticated (Administrator+) OS Command Injection via 'wp_db_exclude_table' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9834"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-54402",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01305,
      "epss_percentile": 0.6825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi OS Server",
      "cwe": "CWE-77",
      "title": "A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi OS to execute a Command Injection on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54402"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-50748",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01207,
      "epss_percentile": 0.65908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Access Application",
      "cwe": "CWE-20",
      "title": "A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50748"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-13368",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01012,
      "epss_percentile": 0.60443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-416",
      "title": "WatchGuard Firebox Race Condition and Use-After-Free in Mobile VPN with IKEv2 LDAP Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13368"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2022-50973",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0086,
      "epss_percentile": 0.55674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Yonyou Network Technology Co., Ltd.",
      "product": "KSOA",
      "cwe": "CWE-434",
      "title": "Yonyou KSOA 9.0 Unauthenticated File Upload RCE via ImageUpload Servlet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-50973"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-5524",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00723,
      "epss_percentile": 0.51187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Divi Engine",
      "product": "Divi Form Builder",
      "cwe": "CWE-434",
      "title": "Divi Form Builder <= 5.1.8 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execution via 'acceptFileTypes' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5524"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2024-14037",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00708,
      "epss_percentile": 0.50667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Guangzhou Red Sea Cloud Computing Co., Ltd.",
      "product": "Red Sea Cloud eHR",
      "cwe": "CWE-434",
      "title": "Redsea Cloud eHR Unauthenticated File Upload RCE via PtFjk.mob",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-14037"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-57624",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00677,
      "epss_percentile": 0.49488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Creative Themes",
      "product": "Blocksy Companion Pro",
      "cwe": "CWE-94",
      "title": "WordPress Blocksy Companion Pro plugin <= 2.1.46 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57624"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-57100",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00653,
      "epss_percentile": 0.48505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Entra Provisioning Service",
      "cwe": "CWE-918",
      "title": "Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57100"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-13050",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00651,
      "epss_percentile": 0.48435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-787",
      "title": "WatchGuard Firebox networkd Out of Bounds Write Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13050"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-7311",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00651,
      "epss_percentile": 0.48434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tinypng",
      "product": "TinyPNG – JPEG, PNG & WebP image compression",
      "cwe": "CWE-22",
      "title": "TinyPNG <= 3.6.13 - Authenticated (Author+) Arbitrary File Deletion via 'convert.path' in 'tiny_compress_images' Post Meta",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7311"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-54998",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00648,
      "epss_percentile": 0.48302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Online",
      "cwe": "CWE-863",
      "title": "Microsoft Exchange Online Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54998"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-13251",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00641,
      "epss_percentile": 0.47951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "perfmatters",
      "product": "Perfmatters",
      "cwe": "CWE-22",
      "title": "Perfmatters <= 2.6.4 - Unauthenticated Arbitrary File Read via 's' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13251"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-13054",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00621,
      "epss_percentile": 0.4708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-22",
      "title": "WatchGuard Firebox Arbitrary File Write via Path Traversal in Management Web UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13054"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-54403",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0062,
      "epss_percentile": 0.47053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi OS Server",
      "cwe": "CWE-22",
      "title": "A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to bypass authentication of such UniFi OS devices or instances.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54403"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-45499",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00608,
      "epss_percentile": 0.46463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Open AI",
      "cwe": "CWE-918",
      "title": "Azure OpenAI Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45499"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-13053",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00607,
      "epss_percentile": 0.46382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-787",
      "title": "WatchGuard Firebox Authenticated Out of Bounds Write in Management CLI Command Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13053"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-12413",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00598,
      "epss_percentile": 0.46007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Libreswan Project",
      "product": "libreswan",
      "cwe": "CWE-193",
      "title": "IKEv2 Denial of Service via malformed fragmentation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12413"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-13383",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00597,
      "epss_percentile": 0.45973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-787",
      "title": "WatchGuard Firebox ikestubd Out of Bounds Write Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13383"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-13384",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00597,
      "epss_percentile": 0.45973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-787",
      "title": "WatchGuard Firebox wgagent Out of Bounds Write Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13384"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-13768",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00582,
      "epss_percentile": 0.45274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gardyn",
      "product": "Gardyn Home Firmware",
      "cwe": "CWE-798",
      "title": "Gardyn IoT Hub Use of Hard-coded Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13768"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2024-58352",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00564,
      "epss_percentile": 0.44376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shenzhen Landray Software Co., Ltd.",
      "product": "Landry Office Automation (OA)",
      "cwe": "CWE-564",
      "title": "Landray OA Unauthenticated HQL Injection via wechatLoginHelper.do",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-58352"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-58465",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00555,
      "epss_percentile": 0.43886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eclipse-wakaama",
      "product": "wakaama",
      "cwe": "CWE-770",
      "title": "Eclipse Wakaama CoAP Block1 Handler Unbounded Memory Allocation DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58465"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-52830",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00545,
      "epss_percentile": 0.43379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "leshchenko1979",
      "product": "fast-mcp-telegram",
      "cwe": "CWE-22",
      "title": "fast-mcp-telegram: Bearer token path traversal bypasses reserved Telegram session protection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52830"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-41106",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00531,
      "epss_percentile": 0.42622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Copilot",
      "cwe": "CWE-601",
      "title": "Microsoft 365 Copilot Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41106"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-55115",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00523,
      "epss_percentile": 0.42147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Protect Application",
      "cwe": "CWE-918",
      "title": "A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55115"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-44941",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0052,
      "epss_percentile": 0.41977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "libzypp",
      "cwe": "CWE-23",
      "title": "libzypp path traversal via \"keyhint\" in repomd.xml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44941"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-54400",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00519,
      "epss_percentile": 0.4191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Access Application",
      "cwe": "CWE-284",
      "title": "A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54400"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-38971",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0051,
      "epss_percentile": 0.4133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-125",
      "title": "ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_control.cpp in GCS_MAVLINK::handle_serial_control().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38971"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-58466",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00505,
      "epss_percentile": 0.41078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EstrellaXD",
      "product": "Auto_Bangumi",
      "cwe": "CWE-1392",
      "title": "AutoBangumi < 3.2.8 - Hard-coded Default Credentials via add_default_user()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58466"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-13084",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00499,
      "epss_percentile": 0.40707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-476",
      "title": "Null Pointer Dereference in WatchGuard Fireware OS iked Process",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13084"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-50747",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00488,
      "epss_percentile": 0.40061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Talk Application",
      "cwe": "CWE-89",
      "title": "A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi Talk Application to escalate privileges on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50747"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-58652",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00482,
      "epss_percentile": 0.3964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openwrt",
      "product": "luci-app-travelmate",
      "cwe": "CWE-78",
      "title": "luci-app-travelmate - Arbitrary Command Execution via UCI Script Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58652"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-55952",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00481,
      "epss_percentile": 0.39582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-1284",
      "title": "TLS 1.3 server denial of service via malformed ClientHello pre-shared key extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55952"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-59094",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0047,
      "epss_percentile": 0.38872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pathwaycom",
      "product": "pathway",
      "cwe": "CWE-407",
      "title": "Pathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matching in Document Store",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59094"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-52187",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00452,
      "epss_percentile": 0.37717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_483ba0 component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52187"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-52189",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00452,
      "epss_percentile": 0.37717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_487330 component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52189"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-52191",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00452,
      "epss_percentile": 0.37717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_444C8C component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52191"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-38970",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00451,
      "epss_percentile": 0.37637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-674",
      "title": "pdfcpu through v0.11.1 contains an uncontrolled-recursion denial-of-service issue in pkg/pdfcpu/model/parse.go. The parser descends recursively through nested PDF objects, including arrays, via ParseObjectContext() and parseArray() without enforcing a maximum nesting depth.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38970"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-55116",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00414,
      "epss_percentile": 0.34713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "Dream Machines",
      "cwe": "CWE-284",
      "title": "A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55116"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-44935",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00412,
      "epss_percentile": 0.3454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-1287",
      "title": "Rancher Fleet vulnerable to cross namespace secret disclosure via unvalidated `valuesFrom` references in Helm Deployer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44935"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-52192",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00409,
      "epss_percentile": 0.34288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_445C5C component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52192"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-13369",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00408,
      "epss_percentile": 0.34151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SaturdayDrive",
      "product": "Ninja Forms - File Uploads",
      "cwe": "CWE-22",
      "title": "Ninja Forms - File Uploads <= 3.3.29 - Unauthenticated Arbitrary File Read via File Upload Field 'files[].data.file_path' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13369"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-58467",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00407,
      "epss_percentile": 0.34062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cockpit-hq",
      "product": "cockpit",
      "cwe": "CWE-22",
      "title": "Cockpit CMS 2.14.0 - Path Traversal Local File Inclusion via index.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58467"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-55726",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00394,
      "epss_percentile": 0.32701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gardyn",
      "product": "Gardyn Home Firmware",
      "cwe": "CWE-497",
      "title": "Gardyn IoT Hub Exposure of Sensitive System Information to an Unauthorized Control Sphere",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55726"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-59093",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00389,
      "epss_percentile": 0.32192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weaviate",
      "product": "weaviate",
      "cwe": "CWE-266",
      "title": "Weaviate < 1.38.0 - Privilege Escalation via Unchecked Permissions in RBAC Role Assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59093"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2025-69133",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00388,
      "epss_percentile": 0.32142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GoodLayers",
      "product": "Tourmaster",
      "cwe": "CWE-98",
      "title": "WordPress Tourmaster plugin <= 5.4.5 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69133"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-50721",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00386,
      "epss_percentile": 0.31978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Libreswan Project",
      "product": "libreswan",
      "cwe": "CWE-347",
      "title": "IKEv1 Denial of Service via RSA-SHA1 (PKCS#1 Version 1.5 Encrypted) authentication payload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50721"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-27436",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00385,
      "epss_percentile": 0.31854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rustaurius",
      "product": "Five Star Business Profile and Schema",
      "cwe": "CWE-94",
      "title": "WordPress Five Star Business Profile and Schema plugin <= 2.3.19 - Arbitrary Code Execution vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27436"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-55117",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.31495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Access Application",
      "cwe": "CWE-22",
      "title": "A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55117"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-33592",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.31529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open62541 project / o6 Automation GmbH",
      "product": "open62541",
      "cwe": "CWE-770",
      "title": "FindServers Memory Exhaustion in open62541",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33592"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-11946",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00381,
      "epss_percentile": 0.31377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open62541 project / o6 Automation GmbH",
      "product": "open62541",
      "cwe": "CWE-770",
      "title": "GetEndpoints Memory Exhaustion in open62541",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11946"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-12657",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00381,
      "epss_percentile": 0.31437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "latepoint",
      "product": "LatePoint – Calendar Booking Plugin for Appointments and Events",
      "cwe": "CWE-639",
      "title": "LatePoint <= 5.6.2 - Unauthenticated Insecure Direct Object Reference to Arbitrary Creation via 'service_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12657"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-38968",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00379,
      "epss_percentile": 0.31225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-341",
      "title": "ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cpp use weak time-seeded pseudo-randomness during session creation. As a result, fresh authenticated logins can receive deterministic or colliding session cookies under attacker-controlled timing.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38968"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-55950",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00379,
      "epss_percentile": 0.31232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-367",
      "title": "DTLS listener crash via race condition in dtls_packet_demux causes denial of service for all sessions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55950"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-54406",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00377,
      "epss_percentile": 0.30974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Network Application",
      "cwe": "CWE-22",
      "title": "A malicious actor with access to the network and high privileges could exploit a Path Traversal vulnerability found in self-hosted instances of UniFi Network Application to escalate write permission on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54406"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-59092",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00377,
      "epss_percentile": 0.30994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "juicedata",
      "product": "juicefs",
      "cwe": "CWE-489",
      "title": "JuiceFS - Authentication Bypass via pprof and metrics Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59092"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-8147",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mlflow",
      "product": "mlflow/mlflow",
      "cwe": "CWE-284",
      "title": "Authorization Bypass in mlflow/mlflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8147"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-56004",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00375,
      "epss_percentile": 0.30774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openSUSE",
      "product": "buildservice",
      "cwe": "CWE-78",
      "title": "obs-service-tar_scm: command injection via mercurial handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56004"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-57347",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30376,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jetmonsters",
      "product": "Hotel Booking Lite",
      "cwe": "CWE-201",
      "title": "WordPress Hotel Booking Lite plugin <= 6.0.3 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57347"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-26145",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00359,
      "epss_percentile": 0.29112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Synapse",
      "cwe": "CWE-284",
      "title": "Microsoft Azure Synapse Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26145"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-59099",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00356,
      "epss_percentile": 0.28841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apereo",
      "product": "cas",
      "cwe": "CWE-323",
      "title": "Apereo CAS 7.3.0 < 8.0.0-RC6 - AES-GCM Nonce Reuse Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59099"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-27419",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00352,
      "epss_percentile": 0.28378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zozothemes",
      "product": "Zegen",
      "cwe": "CWE-434",
      "title": "WordPress Zegen theme <= 1.1.9 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27419"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-13371",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00351,
      "epss_percentile": 0.28282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-502",
      "title": "WatchGuard Firebox Management Web UI Denial of Service via Unsafe Deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13371"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-9563",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse Parsson",
      "cwe": "CWE-400",
      "title": "In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number of characters consumed while parsing a single JSON document. Applications that parse attacker- controlled JSON can be forced to consume excessive CPU and memory by processing very large documents, including large arrays, objects, strings, numbers, whitespace, or nested structures, resulting in a denial of service. Eclipse Parsson 1.1.8 introduces a configurable maximum parsing limit with a default limit of 15 million parser-consumed characters.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9563"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-50722",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00346,
      "epss_percentile": 0.27798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The Libreswan Project",
      "product": "libreswan",
      "cwe": "CWE-347",
      "title": "IKEv2 Denial of Service via RSA-SHA1 (PKCS#1 RSASSA-PKCS1-v1_5) authentication payload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50722"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-12472",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00346,
      "epss_percentile": 0.27741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Kirki – Freeform Page Builder, Website Builder & Customizer",
      "cwe": "CWE-862",
      "title": "Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Arbitrary Email Content Injection (Mail Relay / Phishing) via 'emailBody' and 'emailSubject' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12472"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2025-69132",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00345,
      "epss_percentile": 0.27661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zozothemes",
      "product": "Corpkit",
      "cwe": "CWE-201",
      "title": "WordPress Corpkit theme <= 1.0.5 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69132"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-5821",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elemntor",
      "product": "Image Optimizer – Optimize Images and Convert to WebP or AVIF",
      "cwe": "CWE-73",
      "title": "Image Optimizer <= 1.7.4 - Authenticated (Author+) Arbitrary File Deletion via Post Meta Field Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5821"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-59097",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00344,
      "epss_percentile": 0.27498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "taiga",
      "product": "taiga-back",
      "cwe": "CWE-862",
      "title": "Taiga < 6.10.2 - Unauthorized Due-Date Creation via API Viewsets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59097"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-49779",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Addify",
      "product": "Tax Exempt for WooCommerce",
      "cwe": "CWE-35",
      "title": "WordPress Tax Exempt for WooCommerce plugin < 1.9.5 - Path Traversal vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49779"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-57669",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0034,
      "epss_percentile": 0.27159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Vsourz Digital",
      "product": "Advanced Contact form 7 DB",
      "cwe": "CWE-862",
      "title": "WordPress Advanced Contact form 7 DB plugin <= 2.0.9 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57669"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-54405",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.27024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Network Application",
      "cwe": "CWE-20",
      "title": "A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Network Application to execute a Denial of Service (DoS) attack on the application.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54405"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-55111",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Protect Floodlight",
      "cwe": "CWE-22",
      "title": "A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Protect Floodlight devices to access files on the UniFi Protect Floodlight.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55111"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-4767",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00333,
      "epss_percentile": 0.26285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TR7 Cyber ​​Defense Inc.",
      "product": "WAF-ASP",
      "cwe": "CWE-306",
      "title": "Improper Access Control in TR7's WAF-ASP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4767"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-14249",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00333,
      "epss_percentile": 0.26293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "emarket-design",
      "product": "Request a Quote – Quote Forms for Any WordPress Site",
      "cwe": "CWE-74",
      "title": "Request a Quote Form Plugin <= 2.5.5 - Unauthenticated Code Injection via 'path' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14249"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-13459",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00333,
      "epss_percentile": 0.26339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jetmonsters",
      "product": "JetFormBuilder — Dynamic Blocks Form Builder",
      "cwe": "CWE-862",
      "title": "JetFormBuilder <= 3.6.3 - Missing Authorization to Unauthenticated Sensitive Information Disclosure via 'context' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13459"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-54886",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.26082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-400",
      "title": "SSH SFTP server denial of service via extended channel data infinite loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54886"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-57621",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00326,
      "epss_percentile": 0.25608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arraytics",
      "product": "Booktics",
      "cwe": "CWE-502",
      "title": "WordPress Booktics plugin <= 1.0.21 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57621"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-57677",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00326,
      "epss_percentile": 0.25608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Novalnet",
      "product": "Novalnet Payment Gateway for WooCommerce",
      "cwe": "CWE-502",
      "title": "WordPress Novalnet Payment Gateway for WooCommerce plugin <= 12.10.3 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57677"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-57623",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00323,
      "epss_percentile": 0.25163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BoldGrid",
      "product": "W3 Total Cache",
      "cwe": "CWE-1284",
      "title": "WordPress W3 Total Cache plugin <= 2.9.4 - Arbitrary Code Execution vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57623"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-59101",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00321,
      "epss_percentile": 0.2504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EstrellaXD",
      "product": "Auto_Bangumi",
      "cwe": "CWE-918",
      "title": "AutoBangumi < 3.2.8 - SSRF via /api/v1/setup/test-downloader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59101"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-14029",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "trainingbusinesspros",
      "product": "Groundhogg — CRM, Newsletters, and Marketing Automation",
      "cwe": "CWE-89",
      "title": "Groundhogg <= 4.5.8 - Authenticated (Custom+) SQL Injection via 'select' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14029"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-11896",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joedolson",
      "product": "My Calendar – Accessible Event Manager",
      "cwe": "CWE-639",
      "title": "My Calendar <= 3.7.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'vcal' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11896"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-54407",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Protect Application",
      "cwe": "CWE-284",
      "title": "A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54407"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-9145",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crmperks",
      "product": "Database for Contact Form 7, WPforms, Elementor forms",
      "cwe": "CWE-22",
      "title": "Database for Contact Form 7, WPforms, Elementor forms <= 1.5.1 - Unauthenticated Arbitrary File Copy/Upload via Elementor Pro Form Upload Field 'raw_value'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9145"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-58578",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lobehub",
      "product": "lobehub",
      "cwe": "CWE-1333",
      "title": "LobeChat < 2.2.10-canary.15 - Regular Expression Denial of Service in GitHub Skill Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58578"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-54408",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00304,
      "epss_percentile": 0.23125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Protect Application",
      "cwe": "CWE-284",
      "title": "A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54408"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-56037",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themify",
      "product": "Themify Popup",
      "cwe": "CWE-502",
      "title": "WordPress Themify Popup plugin <= 1.4.3 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56037"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-57353",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.22591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LinkWhisper",
      "product": "Link Whisper Premium",
      "cwe": "CWE-862",
      "title": "WordPress Link Whisper Premium plugin <= 2.9.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57353"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-57355",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.22591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RadiusTheme",
      "product": "Classified Listing",
      "cwe": "CWE-862",
      "title": "WordPress Classified Listing plugin <= 5.4.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57355"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-9188",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00297,
      "epss_percentile": 0.2234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wappointment",
      "product": "Appointment Bookings for Zoom GoogleMeet and more – Wappointment",
      "cwe": "CWE-639",
      "title": "Appointment Bookings for Zoom GoogleMeet and more – Wappointment <= 2.7.6 - Unauthenticated Insecure Direct Object Reference via Predictable 'edit_key' / 'appointmentkey' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9188"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-42382",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.22028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "Audrey",
      "cwe": "CWE-98",
      "title": "WordPress Audrey theme <= 1.5 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42382"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-57268",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.21923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GeoWebPlayer",
      "cwe": "CWE-129",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57268"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-57273",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.21942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GeoWebPlayer",
      "cwe": "CWE-120",
      "title": "GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57273"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-57274",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.21943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GeoWebPlayer",
      "cwe": "CWE-120",
      "title": "GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57274"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-57275",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.21943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GeoWebPlayer",
      "cwe": "CWE-120",
      "title": "GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57275"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-57276",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.21943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GeoWebPlayer",
      "cwe": "CWE-120",
      "title": "GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57276"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2025-69134",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Merkulove",
      "product": "OpenAI Chatbot for WordPress – Helper",
      "cwe": "CWE-862",
      "title": "WordPress OpenAI Chatbot for WordPress – Helper plugin <= 1.1.4 - Arbitrary Content Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69134"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-57277",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GeoWebPlayer",
      "cwe": "CWE-120",
      "title": "GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57277"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-57278",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GeoWebPlayer",
      "cwe": "CWE-120",
      "title": "GeoVision GeoWebPlayer Websocket Server connectInfo handler stack-based buffer overflow vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57278"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-12122",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Kirki – Freeform Page Builder, Website Builder & Customizer",
      "cwe": "CWE-862",
      "title": "Kirki <= 6.0.11 - Missing Authorization to Unauthenticated Sensitive Information Exposure via kirki_post_apis_nopriv AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12122"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-57752",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.2071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iNET",
      "product": "iNET Webkit",
      "cwe": "CWE-89",
      "title": "WordPress iNET Webkit plugin 1.2.4 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57752"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-54404",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi OS Server",
      "cwe": "CWE-89",
      "title": "A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi OS to escalate privileges within such UniFi OS devices or instances.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54404"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-56841",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Protect Application",
      "cwe": "CWE-89",
      "title": "A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Application to escalate privileges on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56841"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-27060",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Repute Infosystems",
      "product": "ARMember Premium",
      "cwe": "CWE-502",
      "title": "WordPress ARMember Premium plugin < 7.6 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27060"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-27414",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fuelthemes",
      "product": "Werkstatt",
      "cwe": "CWE-502",
      "title": "WordPress Werkstatt theme <= 4.8.3 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27414"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-13357",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.20496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "propertyhive",
      "product": "Houzez Property Feed",
      "cwe": "CWE-89",
      "title": "Houzez Property Feed <= 2.5.46 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13357"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-57748",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shopify Help Center",
      "product": "Shopify",
      "cwe": "CWE-98",
      "title": "WordPress Shopify plugin <= 1.0.0 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57748"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2025-58902",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AncoraThemes",
      "product": "Lighthouse",
      "cwe": "CWE-98",
      "title": "WordPress Lighthouse theme <= 1.2.12 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58902"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-27412",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StylemixThemes",
      "product": "Pearl - Corporate Business",
      "cwe": "CWE-98",
      "title": "WordPress Pearl - Corporate Business theme <= 3.4.10 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27412"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-8441",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "https://wpreviewslider.com/",
      "product": "WP Review Slider Pro",
      "cwe": "CWE-89",
      "title": "WP Review Slider Pro <= 12.7.2 - Unauthenticated SQL Injection via 'notinstring' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8441"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-13722",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.1964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-347",
      "title": "WatchGuard Firebox Firmware Image Validation Bypass in WatchGuard Fireware OS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13722"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-54409",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Protect Application",
      "cwe": "CWE-665",
      "title": "A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulnerability found in UniFi Protect Application to bypass authentication in UniFi Protect Cameras.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54409"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-11592",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "icegram",
      "product": "Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress",
      "cwe": "CWE-862",
      "title": "Email Subscribers & Newsletters <= 5.9.27 - Missing Authorization to Authenticated (Contributor+) Settings Modification via ig_es_handle_request AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11592"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-54477",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.19388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gardyn",
      "product": "Gardyn Home Firmware",
      "cwe": "CWE-644",
      "title": "Gardyn IoT Hub Improper Neutralization of HTTP Headers for Scripting Syntax",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54477"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2025-69094",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeMove",
      "product": "Unicamp",
      "cwe": "CWE-89",
      "title": "WordPress Unicamp theme <= 2.2.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69094"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-57749",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeBoy",
      "product": "SportsPress Pro",
      "cwe": "CWE-98",
      "title": "WordPress SportsPress Pro plugin <= 2.7.29 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57749"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-14449",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.1919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "u5CMS",
      "product": "u5CMS",
      "cwe": "CWE-79",
      "title": "POST-based reflected XSS via the thanks parameter in form components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14449"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-8247",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-787",
      "title": "WatchGuard Firebox admd Out of Bounds Write Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8247"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-10104",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18431,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nikhilgadhiya",
      "product": "Product Video Gallery for Woocommerce",
      "cwe": "CWE-79",
      "title": "Product Video Gallery for Woocommerce <= 1.5.1.8 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via custom_thumbnail Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10104"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-5348",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.18147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kodezen",
      "product": "Academy LMS – WordPress LMS Plugin for Complete eLearning Solution",
      "cwe": "CWE-639",
      "title": "Academy LMS <= 3.8.1 - Unauthenticated Insecure Direct Object Reference to Private Topic Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5348"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-53422",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00262,
      "epss_percentile": 0.18158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-204",
      "title": "SFTP REALPATH path-existence oracle allowing filesystem enumeration outside configured root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53422"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-57625",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00261,
      "epss_percentile": 0.18012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASE",
      "product": "Admin and Site Enhancements (ASE) Pro",
      "cwe": "CWE-79",
      "title": "WordPress Admin and Site Enhancements (ASE) Pro plugin <= 8.8.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57625"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-55114",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Network Application",
      "cwe": "CWE-284",
      "title": "A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55114"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-53357",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53357"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-39448",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CoderPress",
      "product": "NOWPayments for WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress NOWPayments for WooCommerce plugin <= 1.4.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39448"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-57685",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "drfuri",
      "product": "Martfury - WooCommerce Marketplace WordPress Theme",
      "cwe": "CWE-862",
      "title": "WordPress Martfury - WooCommerce Marketplace WordPress theme theme <= 3.2.8 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57685"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-57272",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.17041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GeoWebPlayer",
      "cwe": "CWE-129",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57272"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-50281",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.17066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-915",
      "title": "Craft CMS: Mass assignment via id in newAttributes during bulk duplicate overwrites existing elements",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50281"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-57680",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.16988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeum",
      "product": "Kirki",
      "cwe": "CWE-639",
      "title": "WordPress Kirki plugin <= 6.0.11 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57680"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-9272",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Flowmon ADS",
      "cwe": "CWE-89",
      "title": "Possibility of unintended database operations when querying data related to detected anomalies in Progress Flowmon ADS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9272"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-57269",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GeoWebPlayer",
      "cwe": "CWE-129",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57269"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-59096",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dapr",
      "product": "dapr",
      "cwe": "CWE-346",
      "title": "Dapr - OIDC Discovery Issuer and JWKS URI Injection via Unvalidated X-Forwarded-Host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59096"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-27433",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.16086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StylemixThemes",
      "product": "Motors",
      "cwe": "CWE-862",
      "title": "WordPress Motors theme <= 5.6.80 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27433"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-54887",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-1394",
      "title": "DTLS server cookie bypass during startup window due to empty initial cookie secret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54887"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-57271",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GeoWebPlayer",
      "cwe": "CWE-129",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57271"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-57679",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0024,
      "epss_percentile": 0.15351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ahmadgb",
      "product": "GeekyBot",
      "cwe": "CWE-89",
      "title": "WordPress GeekyBot plugin <= 1.2.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57679"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-57683",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0024,
      "epss_percentile": 0.15352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Epsiloncool",
      "product": "WP Fast Total Search",
      "cwe": "CWE-89",
      "title": "WordPress WP Fast Total Search plugin <= 1.80.280 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57683"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-10077",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "yootheme",
      "cwe": null,
      "title": "YOOtheme Pro < 5.0.35 - Author+ Stored XSS via UIkit Data Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10077"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-54401",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi OS Server",
      "cwe": "CWE-918",
      "title": "A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) to escalate privileges within such UniFi OS devices or instances.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54401"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-59098",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lobehub",
      "product": "lobehub",
      "cwe": "CWE-639",
      "title": "LobeChat 2.2.9 - Cross-User Document Disclosure via Unscoped RAG Semantic Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59098"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-13125",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.15003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GeoWebPlayer",
      "cwe": "CWE-306",
      "title": "GeoVision GeoWebPlayer 1.1.1.0 Websocket Server function vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13125"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-52188",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.15009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-119",
      "title": "Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead//sub_497498 component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52188"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2025-71385",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netdata",
      "product": "netdata",
      "cwe": "CWE-79",
      "title": "Netdata < 2.3.1 - Reflected Cross-Site Scripting via love Parameter in ilove.svg Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71385"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-11600",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "envothemes",
      "product": "Envo's Templates & Widgets for Elementor and WooCommerce",
      "cwe": "CWE-862",
      "title": "Envo's Templates & Widgets for Elementor and WooCommerce <= 1.4.26 - Missing Authorization to Authenticated (Author+) Private Content Disclosure via Envo Tabs Widget 'templates' Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11600"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-59095",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lobehub",
      "product": "lobehub",
      "cwe": "CWE-918",
      "title": "LobeChat < 2.2.10-canary.18 - SSRF via importFromUrl and fetchImageFromUrl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59095"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-57688",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gurmehub",
      "product": "POS Entegratör",
      "cwe": "CWE-862",
      "title": "WordPress POS Entegratör plugin <= 3.7.103 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57688"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-57746",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Booked",
      "cwe": "CWE-862",
      "title": "WordPress Booked plugin <= 3.0.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57746"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-13704",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.14421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stellarwp",
      "product": "GiveWP – Donation Plugin and Fundraising Platform",
      "cwe": "CWE-79",
      "title": "GiveWP <= 4.16.1 - Authenticated (Give Worker+) Stored Cross-Site Scripting via Sequioa Form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13704"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-12134",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "beardev",
      "product": "JoomSport – for Sports: Team & League, Football, Hockey & more",
      "cwe": "CWE-862",
      "title": "JoomSport <= 5.7.8 - Authenticated (Subscriber+) Missing Authorization to Arbitrary Group Creation/Modification via season_groupedit AJAX action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12134"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-14336",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse CSI - PIA",
      "cwe": "CWE-918",
      "title": "PIA's OIDC issuer allowlist for Jenkins tokens uses a bare string-prefix check (issuer.startswith(' https://ci.eclipse.org ') in is_issuer_known, pia/models.py:139) instead of validating the issuer as a properly host-bounded URL. An attacker can craft an issuer such as https://ci.eclipse.org@evil.host (userinfo trick) or https://ci.eclipse.org.evil.host (suffix trick) that satisfies the prefix check while pointing the OIDC discovery and JWKS fetches at a server the attacker controls. An unauthenticated caller of POST /v1/upload/sbom can use this to force PIA to make outbound HTTP(S) requests to an arbitrary attacker-chosen host, and to have oidc.verify_token accept a JWT signed with the attacker's own key.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14336"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-57267",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GeoWebPlayer",
      "cwe": "CWE-129",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57267"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-57270",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GeoWebPlayer",
      "cwe": "CWE-129",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57270"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-57681",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paolo",
      "product": "GeoDirectory",
      "cwe": "CWE-918",
      "title": "WordPress GeoDirectory plugin <= 2.8.161 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57681"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-55113",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00223,
      "epss_percentile": 0.13195,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Talk Application",
      "cwe": "CWE-918",
      "title": "A malicious actor with access to the network could exploit a Server-Side Request Forgery (SSRF) vulnerability found in UniFi Talk Application to execute a Denial of Service (DoS) attack and bypass authentication in certain UniFi Talk API endpoints.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55113"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-57689",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fuelthemes",
      "product": "Werkstatt",
      "cwe": "CWE-862",
      "title": "WordPress Werkstatt theme <= 4.7.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57689"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-57730",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UX-themes",
      "product": "Flatsome",
      "cwe": "CWE-862",
      "title": "WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57730"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-13131",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GeoWebPlayer",
      "cwe": "CWE-129",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13131"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-13132",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GeoWebPlayer",
      "cwe": "CWE-129",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13132"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-57264",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GeoWebPlayer",
      "cwe": "CWE-129",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57264"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-57265",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GeoWebPlayer",
      "cwe": "CWE-129",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57265"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-57266",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GeoWebPlayer",
      "cwe": "CWE-129",
      "title": "GeoVision GeoWebPlayer Websocket Server out-of-bounds read vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57266"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-55119",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.1296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Talk Application",
      "cwe": "CWE-284",
      "title": "A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Talk Application to escalate privileges within the UniFi Talk Application.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55119"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-57342",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ShortPixel",
      "product": "ShortPixel Adaptive Images",
      "cwe": "CWE-79",
      "title": "WordPress ShortPixel Adaptive Images plugin <= 3.11.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57342"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-57354",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetReviews",
      "cwe": "CWE-79",
      "title": "WordPress JetReviews plugin <= 3.0.0.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57354"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-57687",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hiroaki Miyashita",
      "product": "Custom Field Template",
      "cwe": "CWE-89",
      "title": "WordPress Custom Field Template plugin <= 2.7.8 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57687"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-57756",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "友人a丶",
      "product": "nicen-localize-image",
      "cwe": "CWE-89",
      "title": "WordPress nicen-localize-image plugin <= 1.4.9 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57756"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-57765",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Levelfourdevelopment",
      "product": "WP EasyCart",
      "cwe": "CWE-89",
      "title": "WordPress WP EasyCart plugin <= 5.9.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57765"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-56842",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.11996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Network Application",
      "cwe": "CWE-863",
      "title": "A malicious actor with access to the network and under certain conditions could exploit an Incorrect Authorization vulnerability found in UniFi Network Application to persist privileges within UniFi Network Application after such access had been removed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56842"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-10089",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "figureone",
      "product": "Insert Pages",
      "cwe": "CWE-79",
      "title": "Insert Pages <= 3.11.4 - Authenticated (Author+) Stored Cross-Site Scripting via Custom Field Keys (Meta Key Names)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10089"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-57731",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UX-themes",
      "product": "Flatsome",
      "cwe": "CWE-862",
      "title": "WordPress Flatsome theme <= 3.20.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57731"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-12166",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Little Orbit",
      "product": "GameFirst Anti-Cheat",
      "cwe": null,
      "title": "CVE-2026-12166",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12166"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2025-66076",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dylan ngo",
      "product": "Woostify Sites Library",
      "cwe": "CWE-862",
      "title": "WordPress Woostify Sites Library plugin <= 1.6.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-66076"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-8699",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.11076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Archer C5 v6.8",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) in TP-Link Archer C5 Web Management Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8699"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-50282",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craftcms",
      "product": "cms",
      "cwe": "CWE-862",
      "title": "Craft CMS: Unauthorized Deletion of Destination Folders During Forced Moves",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50282"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-55118",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.1069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi Network Application",
      "cwe": "CWE-284",
      "title": "A malicious actor with access to the network,low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi Network Application to escalate privileges within the UniFi Network Application.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55118"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-57352",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VillaTheme",
      "product": "ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce",
      "cwe": "CWE-1390",
      "title": "WordPress ALD – Dropshipping and Fulfillment for AliExpress and WooCommerce plugin <= 2.2.0 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57352"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-57753",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nathanbarry",
      "product": "Kit (formerly ConvertKit) for WooCommerce",
      "cwe": "CWE-497",
      "title": "WordPress Kit (formerly ConvertKit) for WooCommerce plugin <= 2.1.5 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57753"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-59102",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.10041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "forgejo",
      "product": "forgejo",
      "cwe": "CWE-79",
      "title": "Forgejo < 15.0.3 - Stored XSS via Actions Run Full Name Rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59102"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-55112",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "Dream Machines",
      "cwe": "CWE-284",
      "title": "A malicious actor with access to the network and low privileges and under certain conditions could exploit an Improper Access Control vulnerability found in UniFi OS with UniFi Protect Application to escalate privileges on the host device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55112"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-57348",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00197,
      "epss_percentile": 0.09782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cozmoslabs",
      "product": "Paid Member Subscriptions",
      "cwe": "CWE-918",
      "title": "WordPress Paid Member Subscriptions plugin <= 3.0.4 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57348"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-53358",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00196,
      "epss_percentile": 0.09645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53358"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-13252",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeisle",
      "product": "RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator",
      "cwe": "CWE-79",
      "title": "RSS Aggregator by Feedzy <= 5.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'aspectRatio' Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13252"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-11781",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00189,
      "epss_percentile": 0.08868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Adminify",
      "cwe": null,
      "title": "Adminify < 4.2.10 - Contributor+ Sensitive Information Disclosure via Global Search AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11781"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-27426",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themesuite",
      "product": "Automotive Car Dealership Business",
      "cwe": "CWE-79",
      "title": "WordPress Automotive Car Dealership Business theme <= 13.3.3 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27426"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-27430",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tranmautritam",
      "product": "TheFox",
      "cwe": "CWE-79",
      "title": "WordPress TheFox theme <= 3.9.76 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27430"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-57343",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Contempoinc",
      "product": "Real Estate 7",
      "cwe": "CWE-79",
      "title": "WordPress Real Estate 7 theme <= 3.5.9 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57343"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-57344",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.0849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RadiusTheme",
      "product": "Classified Listing",
      "cwe": "CWE-79",
      "title": "WordPress Classified Listing plugin <= 5.4.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57344"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-57345",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webraketen",
      "product": "Internal Links Manager",
      "cwe": "CWE-79",
      "title": "WordPress Internal Links Manager plugin <= 3.0.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57345"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-57349",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "etruel",
      "product": "WPeMatico RSS Feed Fetcher",
      "cwe": "CWE-79",
      "title": "WordPress WPeMatico RSS Feed Fetcher plugin <= 2.8.17 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57349"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-57350",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Andy Fragen",
      "product": "WP Debugging",
      "cwe": "CWE-79",
      "title": "WordPress WP Debugging plugin <= 2.12.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57350"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-57351",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Haktan Suren",
      "product": "HandL UTM Grabber",
      "cwe": "CWE-79",
      "title": "WordPress HandL UTM Grabber plugin <= 2.9.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57351"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-57356",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Moreconvert Team",
      "product": "MC Woocommerce Wishlist",
      "cwe": "CWE-79",
      "title": "WordPress MC Woocommerce Wishlist plugin <= 1.9.19 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57356"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-57357",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Search Atlas Group",
      "product": "Search Atlas SEO",
      "cwe": "CWE-79",
      "title": "WordPress Search Atlas SEO plugin <= 2.6.6 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57357"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-57358",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SysBasics",
      "product": "Customize My Account for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Customize My Account for WooCommerce plugin <= 4.3.9 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57358"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-57359",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ReviewX",
      "product": "ReviewX",
      "cwe": "CWE-79",
      "title": "WordPress ReviewX plugin <= 2.3.10 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57359"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-57360",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "impleCode",
      "product": "eCommerce Product Catalog",
      "cwe": "CWE-79",
      "title": "WordPress eCommerce Product Catalog plugin <= 3.5.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57360"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-57361",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ays Pro",
      "product": "Survey Maker",
      "cwe": "CWE-79",
      "title": "WordPress Survey Maker plugin <= 5.2.2.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57361"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-57362",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuantumCloud",
      "product": "ChatBot",
      "cwe": "CWE-79",
      "title": "WordPress ChatBot plugin <= 8.3.2 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57362"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-57366",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Greg Winiarski",
      "product": "WPAdverts",
      "cwe": "CWE-79",
      "title": "WordPress WPAdverts plugin <= 2.3.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57366"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-57426",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chill Media Labs S.R.L.",
      "product": "Modula - PRO",
      "cwe": "CWE-79",
      "title": "WordPress Modula - PRO plugin <= 2.10.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57426"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-57670",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Codepeople",
      "product": "Google Maps CP",
      "cwe": "CWE-79",
      "title": "WordPress Google Maps CP plugin <= 1.2.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57670"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-57671",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Perfmatters",
      "product": "perfmatters",
      "cwe": "CWE-79",
      "title": "WordPress perfmatters plugin <= 2.6.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57671"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-57672",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Melograno Venture Studio",
      "product": "wpDataTables",
      "cwe": "CWE-79",
      "title": "WordPress wpDataTables plugin <= 6.5.1.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57672"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-57673",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Optimole",
      "product": "Optimole",
      "cwe": "CWE-79",
      "title": "WordPress Optimole plugin <= 4.2.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57673"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-57674",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arraytics",
      "product": "Timetics",
      "cwe": "CWE-79",
      "title": "WordPress Timetics plugin <= 1.0.58 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57674"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-57675",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jacob N. Breetvelt",
      "product": "WP Photo Album Plus",
      "cwe": "CWE-79",
      "title": "WordPress WP Photo Album Plus plugin <= 9.2.02.004 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57675"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-57682",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuantumCloud",
      "product": "Simple Link Directory",
      "cwe": "CWE-79",
      "title": "WordPress Simple Link Directory plugin <= 15.0.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57682"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-57686",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPXPO",
      "product": "WowAddons",
      "cwe": "CWE-79",
      "title": "WordPress WowAddons plugin <= 1.6.14 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57686"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-8079",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.08067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Flowmon",
      "cwe": "CWE-863",
      "title": "Unintended limited set of actions with elevated privileges may be performed during PDF generation in Progress Flowmon",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8079"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-58579",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "infiniflow",
      "product": "ragflow",
      "cwe": "CWE-79",
      "title": "RAGFlow < 0.26.3 - Stored Cross-Site Scripting via Agent Pipeline Node Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58579"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-38972",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.07958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-427",
      "title": "Notepad3 through 6.25.822.1 contains a DLL search-order hijacking vulnerability in the About-dialog code path in src/Notepad3.c. The application calls LoadLibrary(L\"MSFTEDIT.DLL\") with a bare DLL name, which allows a local attacker to place a malicious MSFTEDIT.DLL in the application directory or another preferred DLL search location and achieve arbitrary code execution in the context of the user when the About dialog is opened.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38972"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-59100",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0018,
      "epss_percentile": 0.07939,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lobehub",
      "product": "lobehub",
      "cwe": "CWE-639",
      "title": "LobeChat 2.2.9 - Broken Object Level Authorization via Chat-Group Agent Operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59100"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-57750",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Keksdieb",
      "product": "ez Form Calculator Premium",
      "cwe": "CWE-862",
      "title": "WordPress ez Form Calculator Premium plugin <= 2.14.1.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57750"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-57760",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sendcloud",
      "product": "Sendcloud Shipping",
      "cwe": "CWE-862",
      "title": "WordPress Sendcloud Shipping plugin <= 1.0.29 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57760"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2025-69152",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeGoods",
      "product": "Artale | Wedding Photography WordPress",
      "cwe": "CWE-79",
      "title": "WordPress Artale | Wedding Photography WordPress theme <= 2.2.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69152"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2025-69153",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "designthemes",
      "product": "Trendy Travel",
      "cwe": "CWE-79",
      "title": "WordPress Trendy Travel theme <= 6.7 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69153"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2025-69154",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "designthemes",
      "product": "SpaLab | Beauty Salon WordPress Theme",
      "cwe": "CWE-79",
      "title": "WordPress SpaLab | Beauty Salon WordPress Theme theme <= 6.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69154"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2025-69155",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Designthemes",
      "product": "Fitness Zone WordPress Theme",
      "cwe": "CWE-79",
      "title": "WordPress Fitness Zone WordPress Theme theme <= 5.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69155"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2025-69156",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Design themes",
      "product": "Kids Zone - Children WordPress Theme",
      "cwe": "CWE-79",
      "title": "WordPress Kids Zone - Children WordPress Theme theme <= 5.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69156"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-27402",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Designthemes",
      "product": "Kids Life | Children School WordPress",
      "cwe": "CWE-79",
      "title": "WordPress Kids Life | Children School WordPress theme <= 5.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27402"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-27404",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Designthemes",
      "product": "LMS",
      "cwe": "CWE-79",
      "title": "WordPress LMS theme <= 9.7 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27404"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-27408",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "imithemes",
      "product": "NativeChurch",
      "cwe": "CWE-79",
      "title": "WordPress NativeChurch theme <= 4.8.8.2 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27408"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-27425",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themesuite",
      "product": "Automotive Listings",
      "cwe": "CWE-79",
      "title": "WordPress Automotive Listings plugin <= 18.6 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27425"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-12167",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Little Orbit",
      "product": "GameFirst Anti-Cheat",
      "cwe": null,
      "title": "CVE-2026-12167",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12167"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-13373",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-79",
      "title": "WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Tigerpaw Technology Integration Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13373"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-13374",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-79",
      "title": "WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in ConnectWise Technology Integration Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13374"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-13375",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-79",
      "title": "WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in Autotask Technology Integration Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13375"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-13376",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-79",
      "title": "WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in spamBlocker Module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13376"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-13377",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-79",
      "title": "WatchGuard Firebox Stored Cross-Site-Scripting (XSS) Vulnerability in SIP Proxy Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13377"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-11578",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00168,
      "epss_percentile": 0.06602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Fluent Forms",
      "cwe": null,
      "title": "Fluent Forms < 6.2.5 - Form Manager+ Cross-Form Submission Entry Deletion via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11578"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-57684",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tranmautritam",
      "product": "TheFox",
      "cwe": "CWE-79",
      "title": "WordPress TheFox theme <= 3.9.70 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57684"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-11965",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Registration & Membership",
      "cwe": null,
      "title": "User Registration & Membership < 5.2.0 - Unauthenticated Paid Membership Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11965"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-12168",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.05992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Little Orbit",
      "product": "GameFirst Anti-Cheat",
      "cwe": null,
      "title": "CVE-2026-12168",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12168"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-58653",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PraisonAI",
      "product": "PraisonAI",
      "cwe": "CWE-639",
      "title": "PraisonAI - Authorization Bypass via Unvalidated project_id in Issue Create/Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58653"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-58580",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.0512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lobehub",
      "product": "lobehub",
      "cwe": "CWE-639",
      "title": "LobeChat 2.2.9 - Broken Object-Level Authorization in Message Sub-Resource Writes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58580"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-57678",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemePunch",
      "product": "Slider Revolution",
      "cwe": "CWE-79",
      "title": "WordPress Slider Revolution plugin 7.0.0-7.0.16 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57678"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-55110",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ubiquiti Inc",
      "product": "UniFi OS Server",
      "cwe": "CWE-942",
      "title": "A malicious actor who lures an authenticated user to a malicious page could exploit a Cross-Origin Resource Sharing (CORS) misconfiguration found in UniFi OS to trigger actions in UniFi OS using that user's session.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55110"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-13728",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Fireware OS",
      "cwe": "CWE-798",
      "title": "WatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resource Credential Database",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13728"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-8482",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stormshield",
      "product": "Stormshield Network Security",
      "cwe": "CWE-532",
      "title": "Information leak in NSRPC client history",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8482"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-57762",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Andrew Fiebert",
      "product": "Simple URLs",
      "cwe": "CWE-79",
      "title": "WordPress Simple URLs plugin <= 151 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57762"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-57759",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.04038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Metagauss",
      "product": "ProfileGrid",
      "cwe": "CWE-352",
      "title": "WordPress ProfileGrid plugin <= 5.9.9.7 - CSRF to Account Takeover vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57759"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-57766",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.04038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XplodedThemes",
      "product": "WPIDE – File Manager & Code Editor",
      "cwe": "CWE-352",
      "title": "WordPress WPIDE – File Manager & Code Editor plugin <= 3.5.6 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57766"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-13079",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00141,
      "epss_percentile": 0.03906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WatchGuard",
      "product": "Mobile VPN with SSL Client",
      "cwe": "CWE-732",
      "title": "WatchGuard Mobile VPN with SSL Windows Client Local Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13079"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-57751",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Heateor Support",
      "product": "Heateor Social Login",
      "cwe": "CWE-352",
      "title": "WordPress Heateor Social Login plugin <= 1.1.39 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57751"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-58460",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ajith-ab",
      "product": "react-native-receive-sharing-intent",
      "cwe": "CWE-22",
      "title": "react-native-receive-sharing-intent Path Traversal via _display_name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58460"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-57754",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Livemesh",
      "product": "Livemesh Addons for WPBakery Page Builder",
      "cwe": "CWE-79",
      "title": "WordPress Livemesh Addons for WPBakery Page Builder plugin <= 3.9.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57754"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-57755",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Misbah WP",
      "product": "Mosaic Gallery &#8211; Advanced Gallery",
      "cwe": "CWE-79",
      "title": "WordPress Mosaic Gallery &#8211; Advanced Gallery plugin <= 1.2.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57755"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-57763",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gordon Böhme",
      "product": "Structured Content",
      "cwe": "CWE-79",
      "title": "WordPress Structured Content plugin <= 1.7.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57763"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-57764",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Surbma",
      "product": "Surbma | Yoast SEO Breadcrumb Shortcode",
      "cwe": "CWE-79",
      "title": "WordPress Surbma | Yoast SEO Breadcrumb Shortcode plugin <= 1.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57764"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-54891",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-924",
      "title": "Plaintext APPLICATION_DATA injected during TLS handshake delivered to client application post-handshake in ssl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54891"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-4772",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TR7 Cyber ​​Defense Inc.",
      "product": "WAF-ASP",
      "cwe": "CWE-79",
      "title": "Stored XSS in TR7's WAF-ASP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4772"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-4770",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TR7 Cyber ​​Defense Inc.",
      "product": "WAF-ASP",
      "cwe": "CWE-79",
      "title": "DOM-Based XSS in TR7's WAF-ASP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4770"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-54431",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenIDC",
      "product": "liboauth2",
      "cwe": "CWE-358",
      "title": "Improper Data Validation in liboauth2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54431"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-57747",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeREX",
      "product": "Booked",
      "cwe": "CWE-352",
      "title": "WordPress Booked plugin <= 3.0.0 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57747"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-54430",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenIDC",
      "product": "liboauth2",
      "cwe": "CWE-918",
      "title": "Server-Site Request Forgery in liboauth2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54430"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-58381",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.01998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-415",
      "title": "Gimp: gimp: double-free in read_layer_block()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58381"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-57757",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ploudapp",
      "product": "pCloud WP Backup",
      "cwe": "CWE-352",
      "title": "WordPress pCloud WP Backup plugin <= 2.0.2 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57757"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-13743",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00116,
      "epss_percentile": 0.01888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CubeSpace",
      "product": "CW0057 Reaction Wheel",
      "cwe": "CWE-347",
      "title": "Improper verification of cryptographic signature in CubeSpace CW0057 Reaction Wheel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13743"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-57690",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.01172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fuelthemes",
      "product": "Werkstatt",
      "cwe": "CWE-352",
      "title": "WordPress Werkstatt theme <= 4.7.2 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57690"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-57758",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00094,
      "epss_percentile": 0.00715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BeRocket",
      "product": "Permalink Manager for WooCommerce",
      "cwe": "CWE-352",
      "title": "WordPress Permalink Manager for WooCommerce plugin <= 1.0.8.2 - CSRF to Stored XSS vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57758"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-57761",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00094,
      "epss_percentile": 0.00716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BlueAstralThemes",
      "product": "SEOWP",
      "cwe": "CWE-352",
      "title": "WordPress SEOWP theme <= 3.12.2 - CSRF to Stored XSS vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57761"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-38971",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-38971. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-38972",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-38972. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44941",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44941 (SUSE libzypp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-8147",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-8147 (mlflow/mlflow). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
