{
  "day": "2026-07-06",
  "boundary": "UTC calendar day",
  "published_count": 196,
  "by_severity": {
    "CRITICAL": 30,
    "HIGH": 80,
    "MEDIUM": 60,
    "LOW": 26
  },
  "kev_count": 0,
  "exploit_reference_count": 20,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-43825",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.08796,
      "epss_percentile": 0.9475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache OpenNLP :: Core :: ML :: LibSVM",
      "cwe": "CWE-502",
      "title": "Apache OpenNLP :: Core :: ML :: LibSVM: Unsafe Java Deserialization in SvmDoccatModel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43825"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-40047",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0178,
      "epss_percentile": 0.76466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-88",
      "title": "Apache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40047"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-34038",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0175,
      "epss_percentile": 0.76039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify authenticated remote command injection leading to RCE and secret exfiltration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34038"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-11405",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01616,
      "epss_percentile": 0.74061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "firmware",
      "cwe": null,
      "title": "Hidden backdoor authentication mechanism in multiple versions of Tenda firmware allows admin access to web management interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11405"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-48316",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01601,
      "epss_percentile": 0.73839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-20",
      "title": "ColdFusion | Improper Input Validation (CWE-20)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48316"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-34599",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01351,
      "epss_percentile": 0.69295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify: Authenticated Remote Code Execution in GetLogs Livewire Component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34599"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-14802",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01324,
      "epss_percentile": 0.68635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "react",
      "product": "create-react-app",
      "cwe": "CWE-77",
      "title": "react create-react-app react-dev-utils openBrowser.js startBrowserProcess os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14802"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-43865",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00972,
      "epss_percentile": 0.59187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-502",
      "title": "Apache Camel: Camel-Hazelcast: Unsafe Java deserialization in default-configured managed Hazelcast instances enables remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43865"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-9181",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00944,
      "epss_percentile": 0.58287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esri",
      "product": "ArcGIS Server",
      "cwe": "CWE-22",
      "title": "Directory Traversal in ArcGIS Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9181"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-6382",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00902,
      "epss_percentile": 0.56952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "FileOrganizer",
      "cwe": null,
      "title": "Multiple elFinder Plugins - Authenticated OS Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6382"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-43867",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00893,
      "epss_percentile": 0.5666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-502",
      "title": "Apache Camel: Camel-PQC: The AWS Secrets Manager key-lifecycle manager deserializes persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43867"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-40859",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00879,
      "epss_percentile": 0.56271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-502",
      "title": "Apache Camel: Camel-Vertx-Http: Unsafe Java deserialization of HTTP response bodies via a raw ObjectInputStream when transferException is enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40859"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-46726",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00783,
      "epss_percentile": 0.53201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel Vertx Websocket",
      "cwe": "CWE-20",
      "title": "Apache Camel Vertx Websocket: The inbound consumer maps externally-supplied WebSocket query and path parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46726"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-55993",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00783,
      "epss_percentile": 0.53201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel Atmosphere Websocket",
      "cwe": "CWE-20",
      "title": "Apache Camel Atmosphere Websocket: The inbound consumer maps externally-supplied WebSocket query parameters into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling influencing internal behaviour",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55993"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-53913",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00746,
      "epss_percentile": 0.51991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel Keycloak",
      "cwe": "CWE-287",
      "title": "Apache Camel Keycloak: KeycloakSecurityPolicy verifies the bearer access token only inside its role and permission checks, so in the default configuration the token is never verified and any non-null bearer value is accepted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53913"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-46590",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00714,
      "epss_percentile": 0.5085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-502",
      "title": "Apache Camel: Camel-PQC: The HashiCorp Vault and AWS Secrets Manager key-lifecycle managers deserialize persisted key metadata with java.io.ObjectInputStream and no ObjectInputFilter (incomplete remediation of CVE-2026-40048)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46590"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-46454",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00706,
      "epss_percentile": 0.50578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-20",
      "title": "Apache Camel: Camel-Cometd: Inbound Bayeux message headers are mapped into the Exchange without a HeaderFilterStrategy, allowing unauthenticated clients to inject Camel control headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46454"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-49297",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00697,
      "epss_percentile": 0.50231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow Google provider",
      "cwe": "CWE-22",
      "title": "Apache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49297"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-24012",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00678,
      "epss_percentile": 0.49517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache IoTDB",
      "cwe": "CWE-400",
      "title": "Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24012"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-40139",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00674,
      "epss_percentile": 0.49357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BeyondTrust",
      "product": "Remote Support",
      "cwe": "CWE-287",
      "title": "Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40139"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-46456",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00641,
      "epss_percentile": 0.47959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-20",
      "title": "Apache Camel: Camel-AWS2-SQS: Inbound message attributes are mapped into the Exchange without an inbound HeaderFilterStrategy, allowing a message sender to inject Camel control headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46456"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-42527",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00625,
      "epss_percentile": 0.47272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-502",
      "title": "Apache Camel: Permissive default ObjectInputFilter pattern admits java.net.** and enables DNS-based information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42527"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-55994",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00621,
      "epss_percentile": 0.47103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel Iggy",
      "cwe": "CWE-20",
      "title": "Apache Camel Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling control over internal behaviour",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55994"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-43866",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00617,
      "epss_percentile": 0.46888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-502",
      "title": "Apache Camel, Apache Camel: Camel JMS - CVE-2026-40860 fix bypass via DefaultExchangeHolder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43866"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-57571",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00596,
      "epss_percentile": 0.45888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "unclecode",
      "product": "crawl4ai",
      "cwe": "CWE-22",
      "title": "Crawl4AI arbitrary file write via download filename path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57571"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-24014",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00583,
      "epss_percentile": 0.45326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache IoTDB",
      "cwe": "CWE-284",
      "title": "Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24014"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-46453",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00577,
      "epss_percentile": 0.45028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-639",
      "title": "Apache Camel: Camel-Elasticsearch-Rest-Client: Exchange header constants without the Camel prefix bypass inbound HTTP header filtering, allowing untrusted clients to override the Elasticsearch query and operation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46453"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-40140",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00575,
      "epss_percentile": 0.44933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BeyondTrust",
      "product": "Remote Support",
      "cwe": "CWE-400",
      "title": "High-Severity Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40140"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-49097",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00561,
      "epss_percentile": 0.44253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-20",
      "title": "Apache Camel: Camel-IRC: The irc.sendTo (and other irc.*) Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to redirect outgoing IRC messages to arbitrary channels or users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49097"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-57572",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00534,
      "epss_percentile": 0.42795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "unclecode",
      "product": "crawl4ai",
      "cwe": "CWE-88",
      "title": "Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57572"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-49098",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00532,
      "epss_percentile": 0.42685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-20",
      "title": "Apache Camel: Camel-Kafka: The kafka.OVERRIDE_TOPIC (and other kafka.*) Exchange header constants used non-Camel-prefixed names that bypass the upstream HTTP header filter, allowing an HTTP client to redirect Kafka messages to an arbitrary topic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49098"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-56139",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0053,
      "epss_percentile": 0.42582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel Undertow",
      "cwe": "CWE-209",
      "title": "Apache Camel Undertow: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56139"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-46587",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00524,
      "epss_percentile": 0.42265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-20",
      "title": "Apache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46587"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-46588",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00524,
      "epss_percentile": 0.42265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-20",
      "title": "Apache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46588"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-49042",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00524,
      "epss_percentile": 0.42266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-20",
      "title": "Apache Camel: langchain4j-tools: filter tool argument headers against declared parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49042"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-24013",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00521,
      "epss_percentile": 0.42057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache IoTDB",
      "cwe": "CWE-290",
      "title": "Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24013"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-49365",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00501,
      "epss_percentile": 0.40854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-209",
      "title": "Apache Camel: Camel-Netty-HTTP: The muteException consumer option defaulted to false, so a processing error returned the full Java stack trace in the HTTP response body, disclosing sensitive internal information to unauthenticated clients",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49365"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-40141",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00494,
      "epss_percentile": 0.40446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BeyondTrust",
      "product": "Remote Support",
      "cwe": "CWE-943",
      "title": "High-Severity Vulnerability In Web Application Component of BeyondTrust Remote Support and Privileged Remote Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40141"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-14808",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00472,
      "epss_percentile": 0.39028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PROG MIS",
      "product": "Prog Management System",
      "cwe": "CWE-497",
      "title": "PROG MIS｜Prog Management System - Exposure of Sensitive Information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14808"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-48204",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00452,
      "epss_percentile": 0.37679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-20",
      "title": "Apache Camel: Camel-MongoDB-GridFS: The gridfs.* control headers used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to switch the GridFS operation - including destructive file deletion - in the default configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48204"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-38976",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.37274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "mrubyc through 3.4.1 was found to contain a NULL pointer dereference in src/vm.c in op_super() / OP_SUPER due to a missing runtime guard for top-level super.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38976"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-40138",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00441,
      "epss_percentile": 0.3692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BeyondTrust",
      "product": "Remote Support",
      "cwe": "CWE-287",
      "title": "Critical Pre-Authentication Vulnerability in BeyondTrust Remote Support and Privileged Remote Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40138"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-58226",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.3665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-mint",
      "product": "hpax",
      "cwe": "CWE-407",
      "title": "Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58226"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-11962",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "FileOrganizer",
      "cwe": null,
      "title": "FileOrganizer < 1.2.0 - Authenticated Arbitrary File Upload via elFinder File Operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11962"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-14807",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00432,
      "epss_percentile": 0.36151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PROG MIS",
      "product": "ERP App",
      "cwe": "CWE-798",
      "title": "PROG MIS｜ERP App - Use of Hard-coded Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14807"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-56140",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00427,
      "epss_percentile": 0.35777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel AWS2 SNS",
      "cwe": "CWE-20",
      "title": "Apache Camel AWS2 SNS: An inbound Camel-namespace filter was added to Sns2HeaderFilterStrategy to align it with sibling components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56140"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-46455",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00426,
      "epss_percentile": 0.35704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-613",
      "title": "Apache Camel: Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46455"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-49086",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00426,
      "epss_percentile": 0.35724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel Dapr",
      "cwe": "CWE-20",
      "title": "Apache Camel Dapr: Pub/Sub consumer copied the inbound CloudEvent's pub/sub-name and topic into producer-direction routing headers, allowing an actor who can publish to the subscribed topic to influence internal behaviour",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49086"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-46457",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.3547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-20",
      "title": "Apache Camel: Camel-NATS: Inbound NATS message headers are mapped into the Exchange without a configured HeaderFilterStrategy, allowing a client that can publish to the subject to inject Camel control headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46457"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-55379",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00421,
      "epss_percentile": 0.35375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "python-pillow",
      "product": "Pillow",
      "cwe": "CWE-789",
      "title": "Pillow BdfFontFile`: `Image.new()` called without `_decompression_bomb_check()` — bomb protection bypass via font loading",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55379"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-5268",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0042,
      "epss_percentile": 0.35216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CIENA",
      "product": "6500 S-Series",
      "cwe": "CWE-288",
      "title": "SFTP Server Authentication Weakness",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5268"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-53647",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0042,
      "epss_percentile": 0.35211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-200",
      "title": "FOSSBilling vulnerable to unauthenticated API key configuration disclosure via guest Serviceapikey get_info endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53647"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-14809",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00419,
      "epss_percentile": 0.35114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PROG MIS",
      "product": "Prog Management System",
      "cwe": "CWE-89",
      "title": "PROG MIS｜Prog Management System - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14809"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-54060",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00418,
      "epss_percentile": 0.35041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "python-pillow",
      "product": "Pillow",
      "cwe": "CWE-789",
      "title": "Pillow: `FontFile.compile()`: `Image.new()` called without `_decompression_bomb_check()`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54060"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-55380",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00418,
      "epss_percentile": 0.35041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "python-pillow",
      "product": "Pillow",
      "cwe": "CWE-789",
      "title": "Pillow GdImageFile decompression bomb protection bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55380"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-54059",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "python-pillow",
      "product": "Pillow",
      "cwe": "CWE-789",
      "title": "Pillow: PcfFontFile._load_bitmaps()`: `Image.frombytes()` called without `_decompression_bomb_check()` — bomb protection bypass via PCF font loading",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54059"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-34153",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33693,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify LocalFileVolume fs_path command injection enables RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34153"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-46585",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00399,
      "epss_percentile": 0.33291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel Lucene",
      "cwe": "CWE-20",
      "title": "Apache Camel Lucene: The query control headers used non-Camel-prefixed names (QUERY, RETURN_LUCENE_DOCS) that bypass the HTTP header filter, allowing an HTTP client to inject the full-text search query",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46585"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-13753",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.32918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc.",
      "product": "HP 2800 Printer Series",
      "cwe": null,
      "title": "CVE-2026-13753",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13753"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-46592",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.32945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-20",
      "title": "Apache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46592"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-46584",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00391,
      "epss_percentile": 0.32435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel Mail",
      "cwe": "CWE-20",
      "title": "Apache Camel Mail: The mail producer applied attacker-supplied message headers as JavaMail session properties, allowing an attacker to influence SMTP parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46584"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-44937",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.31532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-918",
      "title": "SUSE Rancher Fleet had an Unauthenticated Webhook: Regex Injection via Unsanitized Repository URL Components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44937"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-13708",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.30764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TONYC",
      "product": "Imager::File::JPEG",
      "cwe": "CWE-401",
      "title": "Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13708"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-48203",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0037,
      "epss_percentile": 0.30222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-20",
      "title": "Apache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48203"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-48205",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0037,
      "epss_percentile": 0.30222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel DNS",
      "cwe": "CWE-20",
      "title": "Apache Camel DNS: The dns.* and term Exchange header constants used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48205"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-55514",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-617",
      "title": "vLLM denial of service via prompt embeds on M-RoPE models",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55514"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-14792",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00366,
      "epss_percentile": 0.29856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Formbricks",
      "cwe": "CWE-266",
      "title": "Formbricks Survey actions.ts access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14792"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-54234",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.29498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-20",
      "title": "vLLM: Remote DoS in vLLM via Invalid Recovered Token Reinjection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54234"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2025-53827",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00362,
      "epss_percentile": 0.29414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "owncloud",
      "product": "ownCloud Core",
      "cwe": "CWE-749",
      "title": "ownCloud Core: Updater has an exposed dangerous method or function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53827"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-42153",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00359,
      "epss_percentile": 0.29151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify: PostgreSQL Healthcheck Command Injection Allows Root Code Execution in Container",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42153"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-42204",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00359,
      "epss_percentile": 0.2915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify: Authenticated RCE via SHELL_SAFE_COMMAND_PATTERN regression → host root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42204"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-9182",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00352,
      "epss_percentile": 0.28451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esri",
      "product": "ArcGIS Server",
      "cwe": "CWE-434",
      "title": "Unvalidated File Upload vulnerability in ArcGIS Server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9182"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-48206",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00349,
      "epss_percentile": 0.28117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel JIRA",
      "cwe": "CWE-20",
      "title": "Apache Camel JIRA: A set of non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to drive arbitrary JIRA issue operations using the endpoint's configured credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48206"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-56810",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-mint",
      "product": "mint",
      "cwe": "CWE-770",
      "title": "mint buffers an entire chunked response chunk in memory in Mint.HTTP1.decode_body/5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56810"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-49099",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00341,
      "epss_percentile": 0.27237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel Salesforce",
      "cwe": "CWE-74",
      "title": "Apache Camel Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49099"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-4249",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 Universal Gateway",
      "cwe": "CWE-707",
      "title": "Denial of Service via Malicious JSON Payloads in Throttling Events in Multiple WSO2 Products Causing Persistent Service Disruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4249"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2025-53829",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.2648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "owncloud",
      "product": "ownCloud 10",
      "cwe": "CWE-23",
      "title": "ownCloud 10 is vulnerable to Relative Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53829"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-14803",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.26083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SRI",
      "product": "Mojo::JSON",
      "cwe": "CWE-674",
      "title": "Mojo::JSON versions before 9.47 for Perl allow memory exhaustion via unbounded recursion in the pure-Perl decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14803"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-48614",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0033,
      "epss_percentile": 0.25989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "Plesk",
      "cwe": "CWE-94",
      "title": "An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in arbitrary file write as root and full privilege escalation on the underlying server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48614"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-44936",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0033,
      "epss_percentile": 0.26016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-918",
      "title": "Rancher Fleet SSRF in Bundle Reader via Unvalidated Helm Repository URL in fleet.yaml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44936"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-46591",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Camel",
      "cwe": "CWE-943",
      "title": "Apache Camel: Camel-Neo4j: JSON property names from the CamelNeo4jMatchProperties header are interpolated into the Cypher WHERE clause without validation, allowing Cypher injection (incomplete remediation of CVE-2025-66169)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46591"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-14471",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "MCP Gateway & Registry",
      "cwe": "CWE-89",
      "title": "Authenticated SQL injection in the metrics-service retention policy subsystem of mcp-gateway-registry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14471"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-55574",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-1333",
      "title": "vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55574"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-14898",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00324,
      "epss_percentile": 0.25304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenAI",
      "product": "Codex desktop app for macOS",
      "cwe": "CWE-200",
      "title": "The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could place an indirect prompt injection in content processed by Codex, such as a connected-tool result or another untrusted source, could induce the model to construct a remote image URL containing sensitive data. The app automatically fetched that URL when rendering the response, sending the embedded data to an attacker-controlled server without a separate user click. Successful exploitation could exfiltrate secrets and other information accessible in the Codex session, including API keys, source code, and data returned by connected tools. No direct integrity or availability impact was demonstrated, and there is no known exploitation in the wild.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14898"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2024-6228",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Notifications for Forms & WordPress Actions",
      "cwe": null,
      "title": "WANotifier < 2.6 - Subscriber+ LFI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-6228"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-58403",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.24662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gohugoio",
      "product": "hugo",
      "cwe": "CWE-59",
      "title": "Hugo symlink confinement bypass in os.ReadFile",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58403"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-13698",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.24189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "OpenVPN",
      "cwe": "CWE-401",
      "title": "A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13698"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-9165",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Security 4.9",
      "cwe": "CWE-400",
      "title": "Stackrox: stackrox: unbounded graphql query depth allows authenticated denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9165"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-12686",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00309,
      "epss_percentile": 0.23648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adiss",
      "product": "Biloop",
      "cwe": "CWE-639",
      "title": "Incorrect authorisation in Adiss’s Biloop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12686"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-41899",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.003,
      "epss_percentile": 0.22614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-306",
      "title": "Coolify unauthenticated feedback endpoint allows Discord webhook abuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41899"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-43925",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00298,
      "epss_percentile": 0.22465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-915",
      "title": "FOSSBilling: Mass assignment of group_id in guest client registration allows unauthorized promo code use",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43925"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-12083",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Admin and Site Enhancements (ASE)",
      "cwe": null,
      "title": "Admin and Site Enhancements < 8.8.4 - Unauthenticated Administrator-Role Restoration via reset-for Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12083"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-14468",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Terraform Enterprise",
      "cwe": "CWE-22",
      "title": "Path traversal allows arbitrary file read in Terraform Enterprise container",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14468"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-13122",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.21988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Openvpn",
      "product": "OpenVPN",
      "cwe": "CWE-617",
      "title": "OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13122"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-59196",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.21952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pnpm",
      "product": "pnpm",
      "cwe": "CWE-22",
      "title": "pnpm: hoisted install imports lockfile alias outside node_modules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59196"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-7185",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "T-Systems",
      "product": "Archivo",
      "cwe": "CWE-22",
      "title": "Unauthorized access to files in T-Systems products",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7185"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-55727",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Genetec Inc.",
      "product": "Genetec Security Center",
      "cwe": "CWE-287",
      "title": "A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14.178.18 may allow an unauthenticated attacker to access live video streams.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55727"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-55646",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.2146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vllm-project",
      "product": "vllm",
      "cwe": "CWE-400",
      "title": "vLLM speech-to-text endpoints allocate full upload before enforcing the audio file-size limit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55646"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-59195",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pnpm",
      "product": "pnpm",
      "cwe": "CWE-22",
      "title": "pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59195"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-59194",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pnpm",
      "product": "pnpm",
      "cwe": "CWE-22",
      "title": "pnpm: patch-remove could delete project-selected files outside the patches directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59194"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-53641",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.21158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-79",
      "title": "FOSSBilling has stored XSS in client email views via unescaped content in JavaScript template literal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53641"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-11855",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Simple Membership",
      "cwe": null,
      "title": "Simple Membership < 4.7.5 - Unauthenticated Stored XSS via Stripe Webhook API Version",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11855"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-54765",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.20157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-284",
      "title": "Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54765"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-43921",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-94",
      "title": "FOSSBilling vulnerable to arbitrary PHP code injection via unescaped config serialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43921"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-43928",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00274,
      "epss_percentile": 0.19831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-754",
      "title": "FOSSBilling: Payment amount not validated in PayPalEmail adapter allows invoice underpayment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43928"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-50135",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00271,
      "epss_percentile": 0.19443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gohugoio",
      "product": "hugo",
      "cwe": "CWE-59",
      "title": "Hugo: Symlink confinement bypass in resources.Get",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50135"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-53648",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-73",
      "title": "FOSSBilling: Downloadable product files can be overwritten through filename collisions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53648"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-57573",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "unclecode",
      "product": "crawl4ai",
      "cwe": "CWE-918",
      "title": "Crawl4AI unauthenticated SSRF in Docker streaming crawl endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57573"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2025-53830",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00257,
      "epss_percentile": 0.17522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "owncloud",
      "product": "Anti-Virus for ownCloud",
      "cwe": "CWE-918",
      "title": "Anti-Virus for ownCloud 10 is vulnerable to Server-Side Request Forgery (SSRF)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53830"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-58380",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 9",
      "cwe": "CWE-193",
      "title": "Gimp: gimp: stack buffer overflow in pnmscanner_gettoken()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58380"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-53644",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16804,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-639",
      "title": "FOSSBilling's missing order-state validation allows clients to read and reset API key secrets for non-active orders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53644"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-59712",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Leantime",
      "product": "Leantime",
      "cwe": "CWE-639",
      "title": "Leantime - JSON-RPC API Broken Access Control via users.getUser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59712"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-50134",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gohugoio",
      "product": "hugo",
      "cwe": "CWE-918",
      "title": "Hugo: security.http.urls allow-list bypass via HTTP redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50134"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-42331",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-306",
      "title": "FOSSBilling missing authorization in guest Invoice API endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42331"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-59089",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-190",
      "title": "Gimp: gimp: denial of service via integer overflow in playstation tim loader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59089"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-53645",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-269",
      "title": "FOSSBilling's missing self-edit prevention in staff permission management allows persistent privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53645"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-10830",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "AllCoach",
      "cwe": null,
      "title": "AllCoach < 1.0.2 - Unauthenticated Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10830"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-43918",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-613",
      "title": "Suspended or inactive FOSSBilling accounts can retain or regain access through existing sessions, API tokens, and password reset flows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43918"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-54764",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.14399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-345",
      "title": "ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54764"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2025-53828",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "owncloud",
      "product": "SharePoint",
      "cwe": "CWE-918",
      "title": "SharePoint for ownCloud 10 is vulnerable to Server-Side Request Forgery (SSRF)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53828"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-14536",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-863",
      "title": "Improper enforcement of a mandatory multi-factor authentication policy in Devolutions Server 2026.2.9.0 allows an attacker with valid user credentials to bypass the MFA Required policy and authenticate without completing multi-factor authentication. The problem occurs when DVLS encounters an invalid default MFA value.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14536"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-14784",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.1388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vxcontrol",
      "product": "PentAGI",
      "cwe": "CWE-264",
      "title": "vxcontrol PentAGI Docker API client.go sandbox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14784"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-53643",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.1359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-200",
      "title": "FOSSBilling allows low-privileged staff accounts to perform unauthorized actions via admin API endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53643"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-11766",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ultimate Member",
      "cwe": null,
      "title": "Ultimate Member < 2.12.0 - Subscriber+ Stored XSS via Custom Textarea Profile Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11766"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-53642",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.1359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-863",
      "title": "FOSSBilling: Unverified clients can access client-area pages when email confirmation is required",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53642"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-53640",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00226,
      "epss_percentile": 0.13589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-200",
      "title": "FOSSBilling missing authorization checks on read-only admin API endpoints expose sensitive staff, client, and redirect data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53640"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-14793",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Craft",
      "product": "CMS",
      "cwe": "CWE-285",
      "title": "Craft CMS reorder-sets Endpoint GlobalsController.php actionReorderSets authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14793"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-14794",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Craft",
      "product": "CMS",
      "cwe": "CWE-266",
      "title": "Craft CMS Charts Endpoint ChartsController.php actionGetNewUsersData improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14794"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-43927",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-367",
      "title": "FOSSBilling has race condition in cart checkout that bypasses promo code usage limits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43927"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-33734",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-89",
      "title": "FOSSBilling has improper SQL neutralization in `Massmailer` recipient filters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33734"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-53646",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-640",
      "title": "FOSSBilling: Client password reset token reuse allows persistent account takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53646"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-32718",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-863",
      "title": "Coolify read-scoped API tokens can perform state-changing validation operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32718"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-34050",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-862",
      "title": "Coolify Settings/Updates Livewire component missing instance administrator authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34050"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-54763",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00208,
      "epss_percentile": 0.11187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-178",
      "title": "Traefik: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54763"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-1433",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NT-ware",
      "product": "uniFLOW ULM (Universal Login Manager) Standalone",
      "cwe": "CWE-522",
      "title": "uniFLOW Universal Login Manager (ULM) Standalone Improper Protection of Sensitive Information Leads to Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1433"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-58404",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gohugoio",
      "product": "hugo",
      "cwe": "CWE-918",
      "title": "Hugo security.http.urls deny rules bypassed by alternate IPv4 encodings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58404"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-14796",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.10765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Apartment Visitor Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Apartment Visitor Management System report.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14796"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-14799",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.10765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Ecommerce Website",
      "cwe": "CWE-74",
      "title": "CodeAstro Ecommerce Website my_account.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14799"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-54291",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgjdbc",
      "product": "pgjdbc",
      "cwe": "CWE-636",
      "title": "Silent channel-binding authentication downgrade via unsupported certificate algorithms",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54291"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-14791",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00203,
      "epss_percentile": 0.1058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crater-invoice-inc",
      "product": "crater",
      "cwe": "CWE-79",
      "title": "crater-invoice-inc crater Invoice Note InvoicesRequest.php getFormattedString cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14791"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-38979",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-1021",
      "title": "ajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. In ajenti-core/aj/http.py, the core HTTP response path initializes an empty header list, forwards handler-added headers verbatim, and finalizes responses through WSGI start_response() without adding anti-framing protections such as X-Frame-Options or a Content-Security-Policy frame-ancestors restriction.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38979"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-14795",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.1025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Apartment Visitor Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Apartment Visitor Management System action-visitor.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14795"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-14797",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Apartment Visitor Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Apartment Visitor Management System edit-apartment.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14797"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-14798",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Apartment Visitor Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Apartment Visitor Management System visitor-entry.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14798"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-34167",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-639",
      "title": "Coolify: Cross-tenant activity log disclosure via unlocked Livewire property in ActivityMonitor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34167"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-59710",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.0994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "showdown",
      "product": "showdown",
      "cwe": "CWE-79",
      "title": "showdown - Stored XSS via Unescaped Table Header ID Attribute Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59710"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-34049",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00195,
      "epss_percentile": 0.09603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify: Command Injection via unsanitized MongoDB collection names in database backup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34049"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-14789",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0019,
      "epss_percentile": 0.08995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "radareorg",
      "product": "radare2",
      "cwe": "CWE-119",
      "title": "radareorg radare2 Memory64ListStream mdmp.c stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14789"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-12154",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "widgetpack",
      "product": "Reviews Widgets for Google, TripAdvisor, Yelp & Recommendations",
      "cwe": "CWE-79",
      "title": "Reviews Widgets for Google, Yelp & TripAdvisor <= 2.7.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'page_id' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12154"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-59711",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "showdown",
      "product": "showdown",
      "cwe": "CWE-79",
      "title": "showdown - Cross-Site Scripting via Unescaped Metadata Title in completeHTMLDocument",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59711"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-50133",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gohugoio",
      "product": "hugo",
      "cwe": "CWE-79",
      "title": "Hugo: XSS via text/html content files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50133"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-42341",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00184,
      "epss_percentile": 0.08287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FOSSBilling",
      "product": "FOSSBilling",
      "cwe": "CWE-306",
      "title": "FOSSBilling has an unauthenticated payment bypass via IPN callback forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42341"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-58203",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pydantic",
      "product": "pydantic-settings",
      "cwe": "CWE-22",
      "title": "NestedSecretsSettingsSource follows symlinks outside secrets_dir, enabling local file read and bypassing secrets_dir_max_size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58203"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-55798",
      "cvss_base": 4.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "python-pillow",
      "product": "Pillow",
      "cwe": "CWE-78",
      "title": "Pillow: WindowsViewer.get_command() OS command injection via unescaped shell path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55798"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-59152",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langchain-ai",
      "product": "langsmith-sdk",
      "cwe": "CWE-22",
      "title": "Arbitrary server-side file read in LangSmith SDK TracingMiddleware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59152"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-58402",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gohugoio",
      "product": "hugo",
      "cwe": "CWE-79",
      "title": "Hugo default code block renderer XSS via unescaped code-fence language",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58402"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-14787",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00168,
      "epss_percentile": 0.06485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "radareorg",
      "product": "radare2",
      "cwe": "CWE-189",
      "title": "radareorg radare2 pb Print cmd_print.inc cmd_print integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14787"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-14788",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00166,
      "epss_percentile": 0.06367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "radareorg",
      "product": "radare2",
      "cwe": "CWE-119",
      "title": "radareorg radare2 cfile.c r_core_bin_load use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14788"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2025-53831",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "owncloud",
      "product": "DrawIO for ownCloud",
      "cwe": "CWE-79",
      "title": "DrawIO for ownCloud 10 is vulnerable to Stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-53831"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2025-8591",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.0584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 Identity Server",
      "cwe": "CWE-79",
      "title": "Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-8591"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-14800",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00159,
      "epss_percentile": 0.05542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "imhamzaazam",
      "product": "ecommerceFlask",
      "cwe": "CWE-352",
      "title": "imhamzaazam ecommerceFlask cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14800"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-14786",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00159,
      "epss_percentile": 0.05632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "radareorg",
      "product": "radare2",
      "cwe": "CWE-189",
      "title": "radareorg radare2 str.c r_str_word_get0set integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14786"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-38973",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-125",
      "title": "mrubyc through release3.4.1 was found to contain an out-of-bounds read in builtin missing-method lookup inside mrbc_find_method().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38973"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-59713",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00153,
      "epss_percentile": 0.05029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Leantime",
      "product": "Leantime",
      "cwe": "CWE-352",
      "title": "Leantime - OIDC Login CSRF via Unconditional State Verification Stub",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59713"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-53763",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00149,
      "epss_percentile": 0.04657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OP-TEE",
      "product": "optee_os",
      "cwe": "CWE-190",
      "title": "OP-TEE has AES-GCM 32-bit integer overflow in length counters that breaks authentication guarantee",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53763"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-54893",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00143,
      "epss_percentile": 0.04066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "swoosh",
      "product": "swoosh",
      "cwe": "CWE-116",
      "title": "Email-derived URL path injection in the Swoosh Microsoft Graph adapter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54893"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-6900",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00142,
      "epss_percentile": 0.04051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "B&R Industrial Automation GmbH",
      "product": "APROL",
      "cwe": "CWE-295",
      "title": "Improper Certificate Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6900"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-48267",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "DNG SDK",
      "cwe": "CWE-476",
      "title": "DNG SDK | NULL Pointer Dereference (CWE-476)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48267"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-13705",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.03498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TONYC",
      "product": "Imager",
      "cwe": "CWE-125",
      "title": "Imager versions before 1.032 for Perl have a heap out-of-bounds read in the bundled Imager::File::SGI reader via a 16-bit RLE literal run in read_rgb_16_rle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13705"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-41516",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00133,
      "epss_percentile": 0.03301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OP-TEE",
      "product": "optee_os",
      "cwe": "CWE-208",
      "title": "OP-TEE: Hisilicon HPRE PKCS#1 v1.5 Decryption Padding Oracle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41516"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-13356",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Firefox for iOS",
      "cwe": "CWE-451",
      "title": "Interrupted navigation could allow address bar origin spoofing in Firefox for iOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13356"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2025-15668",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00124,
      "epss_percentile": 0.02591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC MP4Box box_code_base.c sgpd_del_entry heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15668"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-44362",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OP-TEE",
      "product": "optee_os",
      "cwe": "CWE-285",
      "title": "OP-TEE's subkey rollback protection can be bypassed with older subkey versions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44362"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-42148",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00121,
      "epss_percentile": 0.02226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify: Command Injection via Unescaped Version String in Docker Build",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42148"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-6901",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "B&R Industrial Automation GmbH",
      "product": "APROL",
      "cwe": "CWE-426",
      "title": "Untrusted Search Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6901"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-14790",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00115,
      "epss_percentile": 0.01794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-404",
      "title": "GPAC Media File write_nhml.c nhmldump_send_frame null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14790"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-44934",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00114,
      "epss_percentile": 0.01758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-215",
      "title": "Exposed tokens in SUSE Rancher AI Agent logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44934"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-14801",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-369",
      "title": "GPAC TeXML File load_text.c txtin_probe_duration divide by zero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14801"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2025-15667",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00112,
      "epss_percentile": 0.01603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC MP4Box avc_ext.c gf_isom_nalu_sample_rewrite double free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15667"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2024-56141",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bixilon",
      "product": "Minosoft",
      "cwe": "CWE-329",
      "title": "Minosoft has IV equal to key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-56141"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-40257",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OP-TEE",
      "product": "optee_os",
      "cwe": "CWE-787",
      "title": "OP-TEE has SHA-3 accelerated finalize heap overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40257"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-42546",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00105,
      "epss_percentile": 0.01232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OP-TEE",
      "product": "optee_os",
      "cwe": "CWE-770",
      "title": "OP-TEE has missing OPTEE_MSG_ATTR_TYPE_MASK in cleanup_shm_refs() leaks mobj references",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42546"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-41434",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00105,
      "epss_percentile": 0.01236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OP-TEE",
      "product": "optee_os",
      "cwe": "CWE-121",
      "title": "OP-TEE has unbounded recursion in sanitize_client_object()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41434"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-41514",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00095,
      "epss_percentile": 0.00782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OP-TEE",
      "product": "optee_os",
      "cwe": "CWE-208",
      "title": "OP-TEE: RSA-OAEP padding oracle in Hisilicon HPRE driver enables plaintext recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41514"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-41515",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00094,
      "epss_percentile": 0.00677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OP-TEE",
      "product": "optee_os",
      "cwe": "CWE-208",
      "title": "OP-TEE: RSA-OAEP padding oracle in NXP CAAM driver enables plaintext recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41515"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-25268",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00072,
      "epss_percentile": 0.00058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-121",
      "title": "Stack-based Buffer Overflow in WLAN Host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25268"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-21379",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0007,
      "epss_percentile": 0.00045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-126",
      "title": "Buffer Over-read in Windows Compute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21379"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-21383",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00069,
      "epss_percentile": 0.00038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-323",
      "title": "Reusing a Nonce, Key Pair in Encryption in HLOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21383"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2025-59617",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00065,
      "epss_percentile": 0.00019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-416",
      "title": "Use After Free in Computer Vision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59617"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2025-59615",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00064,
      "epss_percentile": 0.00018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-416",
      "title": "Use After Free in Computer Vision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59615"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2025-59616",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00064,
      "epss_percentile": 0.00018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-416",
      "title": "Use After Free in Computer Vision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59616"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-21368",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0006,
      "epss_percentile": 0.00009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in Camera Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21368"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-21369",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0006,
      "epss_percentile": 0.00009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in Camera Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21369"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-21370",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0006,
      "epss_percentile": 0.00009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in Camera Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21370"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-21384",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00056,
      "epss_percentile": 0.00004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in Camera Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21384"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-25271",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00052,
      "epss_percentile": 0.00002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qualcomm, Inc.",
      "product": "Snapdragon",
      "cwe": "CWE-367",
      "title": "Time-of-check Time-of-use (TOCTOU) Race Condition in DSP Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25271"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41516",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41516 (OP-TEE optee_os). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44936",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44936 (SUSE Rancher). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49297",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49297 (Apache Software Foundation Apache Airflow Google provider). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54059",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54059 (python-pillow Pillow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54060",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54060 (python-pillow Pillow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54234",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54234 (vllm-project vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55379",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55379 (python-pillow Pillow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55380",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55380 (python-pillow Pillow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55798",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55798 (python-pillow Pillow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57571",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57571 (unclecode crawl4ai). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58203",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58203 (pydantic-settings). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58380",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58380 (Red Hat Enterprise Linux 9). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59089",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59089 (Red Hat Enterprise Linux 6). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59194",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59194 (pnpm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59195",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59195 (pnpm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59196",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59196 (pnpm). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
