{
  "day": "2026-07-07",
  "boundary": "UTC calendar day",
  "published_count": 170,
  "by_severity": {
    "CRITICAL": 25,
    "HIGH": 70,
    "MEDIUM": 64,
    "LOW": 11
  },
  "kev_count": 4,
  "exploit_reference_count": 7,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-48282",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.99241,
      "epss_percentile": 0.99933,
      "kev": true,
      "kev_due_at": "2026-07-10",
      "vendor": "Adobe",
      "product": "ColdFusion",
      "cwe": "CWE-22",
      "title": "ColdFusion | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48282"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-48908",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.8813,
      "epss_percentile": 0.99754,
      "kev": true,
      "kev_due_at": "2026-07-10",
      "vendor": "joomshaper.net",
      "product": "SP Page Builder extension for Joomla",
      "cwe": "CWE-434",
      "title": "Joomla Extension - joomshaper.com - Remote Code Execution in SP Pagebuilder extension for Joomla < 6.6.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48908"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-56290",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.83254,
      "epss_percentile": 0.99654,
      "kev": true,
      "kev_due_at": "2026-07-10",
      "vendor": "joomlack.fr",
      "product": "JoomlaCK.fr Page Builder CK extension for Joomla",
      "cwe": "CWE-434",
      "title": "Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56290"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-55255",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.29052,
      "epss_percentile": 0.9801,
      "kev": true,
      "kev_due_at": "2026-07-10",
      "vendor": "langflow-ai",
      "product": "langflow",
      "cwe": "CWE-639",
      "title": "Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55255"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-44454",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01354,
      "epss_percentile": 0.69358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coder",
      "product": "coder",
      "cwe": "CWE-78",
      "title": "Coder vulnerable to workspace auto-creation via crafted URL parameters without user consent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44454"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-59800",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01338,
      "epss_percentile": 0.69,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9router",
      "cwe": "CWE-78",
      "title": "9Router < 0.4.44 - OS Command Injection via sudoPassword Parameter in Tailscale Install Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59800"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-53479",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.01143,
      "epss_percentile": 0.64145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect Data Domain",
      "cwe": "CWE-78",
      "title": "Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper neutralization of special elements used in an OS command ('OS command Injection') vulnerability. A remote high privileged attacker could potentially exploit this vulnerability, leading to protection mechanism bypass. This is a Critical vulnerability as it allows an attacker to invoke arbitrary command execution with root privileges; so Dell recommends customers to upgrade at the earliest opportunity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53479"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-23697",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01073,
      "epss_percentile": 0.62266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Vtiger",
      "product": "Vtiger CRM",
      "cwe": "CWE-434",
      "title": "Vtiger CRM < 8.4.0 Authenticated File Upload RCE via Documents Module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23697"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-33264",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00992,
      "epss_percentile": 0.59821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-502",
      "title": "Apache Airflow: DAG author RCE on webserver via unrestricted import_string() in BaseSerialization.deserialize()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33264"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-55490",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00987,
      "epss_percentile": 0.59655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openwrt",
      "product": "openwrt",
      "cwe": "CWE-191",
      "title": "OpenWrt: EAD Integer Underflow → Pre-Auth Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55490"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-23698",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00867,
      "epss_percentile": 0.55892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Vtiger",
      "product": "Vtiger CRM",
      "cwe": "CWE-434",
      "title": "Vtiger CRM 8.4.0 Authenticated RCE via Module Import File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23698"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-14345",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00745,
      "epss_percentile": 0.51968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getwpfunnels",
      "product": "WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell",
      "cwe": "CWE-434",
      "title": "WPFunnels <= 3.12.7 - Unauthenticated Remote Code Execution via 'postData' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14345"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-14476",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00669,
      "epss_percentile": 0.49171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-23",
      "title": "Sssd: sssd: gpo cache path traversal via unsanitized gpcfilesyspath allows kerberos authentication bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14476"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-6101",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00628,
      "epss_percentile": 0.47385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mohammed_kaludi",
      "product": "AMP for WP – Accelerated Mobile Pages",
      "cwe": "CWE-73",
      "title": "AMP for WP <= 1.1.12 - Authenticated (Author+) Arbitrary File Write via Role-Based Access Configuration with Local Font Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6101"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-11610",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00627,
      "epss_percentile": 0.47352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "389ds",
      "product": "389-ds-base",
      "cwe": "CWE-122",
      "title": "389-ds-base: 389-ds-base: heap buffer overflow in sasl_io_recv() via padded sasl unbind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11610"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-34048",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00576,
      "epss_percentile": 0.44952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-285",
      "title": "Coolify: Missing authorization on terminal websocket bootstrap routes allows low-privileged members to execute commands on team servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34048"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-14474",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00568,
      "epss_percentile": 0.44562,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-1188",
      "title": "Sssd: sssd: sudo ldap provider searches entire directory tree for sudorole objects by default, enabling privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14474"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-42200",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00542,
      "epss_percentile": 0.43233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-22",
      "title": "Coolify: PostgreSQL Init Script Path Traversal Leads to Arbitrary File Write and Root RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42200"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-56812",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00507,
      "epss_percentile": 0.41179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phoenixframework",
      "product": "phoenix",
      "cwe": "CWE-754",
      "title": "Phoenix JavaScript presence client crashes on presence keys colliding with Object.prototype members in Presence.syncState/syncDiff",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56812"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-55633",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00501,
      "epss_percentile": 0.40849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-434",
      "title": "DataEase H2 RCE via Zip Protocol & File Dropper Fix bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55633"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-59705",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00498,
      "epss_percentile": 0.40635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mem0",
      "product": "mem0",
      "cwe": "CWE-306",
      "title": "mem0 - OpenMemory API Unauthenticated Access via Memory Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59705"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-14380",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00479,
      "epss_percentile": 0.39513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HMBRAND",
      "product": "DBI",
      "cwe": "CWE-95",
      "title": "DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14380"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-34047",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00448,
      "epss_percentile": 0.37454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-863",
      "title": "Coolify: WebSocket Endpoint Access Control Flaw Leading to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34047"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2011-10043",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00447,
      "epss_percentile": 0.3739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BINGOS",
      "product": "Module::Load",
      "cwe": "CWE-145",
      "title": "Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded",
      "url": "https://www.cve.org/CVERecord?id=CVE-2011-10043"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-53481",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00443,
      "epss_percentile": 0.37064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect Data Domain",
      "cwe": "CWE-22",
      "title": "Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to the system. This is a critical severity vulnerability as it allows an attacker to take complete control of system; so Dell recommends customers to upgrade at the earliest opportunity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53481"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-42143",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify: OS Command Injection via Persistent Volume Names - Root RCE on Managed Servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42143"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-13019",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00434,
      "epss_percentile": 0.36298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esri",
      "product": "Portal for ArcGIS",
      "cwe": "CWE-640",
      "title": "Missing Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13019"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-56811",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0042,
      "epss_percentile": 0.3522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phoenixframework",
      "product": "phoenix",
      "cwe": "CWE-770",
      "title": "Phoenix transports do not limit channel joins per connection, enabling process-exhaustion denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56811"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-48828",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0041,
      "epss_percentile": 0.34303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-200",
      "title": "Apache Airflow: Bulk JSON Variables bypass should_hide_value_for_key - redact() called without the key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48828"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-48892",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0041,
      "epss_percentile": 0.34302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-200",
      "title": "Apache Airflow: Config API leaks per-key secrets backend kwargs - masker bypass on synthetic options",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48892"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-49487",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0041,
      "epss_percentile": 0.34302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-200",
      "title": "Apache Airflow: Task-instance API exposes secrets in deferred trigger kwargs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49487"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-34034",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify: Host RCE via Sentinel token injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34034"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-34168",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33693,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify: Command injection via unsanitized persistent storage name in docker volume commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34168"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-49296",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00399,
      "epss_percentile": 0.33259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-639",
      "title": "Apache Airflow: Per-DAG read bypass discloses co-located DAGs' source via GET /api/v2/dagSources/{dag_id}",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49296"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-53751",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-94",
      "title": "DataEase: H2 JDBC URL Filter Bypass Leads to Remote Code Execution (RCE)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53751"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-48891",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00393,
      "epss_percentile": 0.32579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow",
      "cwe": "CWE-200",
      "title": "Apache Airflow: /ui/dependencies scheduling graph leaks unreadable Dag identifiers via trigger/sensor dep.source/dep.target",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48891"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-14739",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00391,
      "epss_percentile": 0.32445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HMBRAND",
      "product": "DBI",
      "cwe": "CWE-787",
      "title": "DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14739"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-53729",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00391,
      "epss_percentile": 0.32414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-639",
      "title": "DataEase ExportCenter IDOR allows cross-user export task access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53729"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-14740",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00387,
      "epss_percentile": 0.32004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HMBRAND",
      "product": "DBI",
      "cwe": "CWE-125",
      "title": "DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14740"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-14895",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00387,
      "epss_percentile": 0.32071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BAKERSCOT",
      "product": "String::Util",
      "cwe": "CWE-1333",
      "title": "String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14895"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-14904",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00381,
      "epss_percentile": 0.3145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "res",
      "cwe": "CWE-59",
      "title": "RES Auth.GetUserPrivateKey Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14904"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-37270",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00374,
      "epss_percentile": 0.30722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-287",
      "title": "Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence of hard-coded credentials in the firmware.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37270"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-57867",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00374,
      "epss_percentile": 0.30694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MicroRealEstate",
      "product": "MicroRealEstate",
      "cwe": "CWE-288",
      "title": "MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit adversaries targeting MicroRealEstate deployments to brute-force One-Time Passwords (OTP) to log in as any user. This issue affects MicroRealEstate: through 1.0.0-alpha3.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57867"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-37271",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00373,
      "epss_percentile": 0.30568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-287",
      "title": "Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request commands without sufficient authentication or strong session validation. Under specific conditions, previously captured BLE packets can be replayed from a nearby device to trigger functionality on the smartwatch.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-37271"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-53483",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.30499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect Data Domain",
      "cwe": "CWE-287",
      "title": "Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 an improper authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access. This is a critical severity vulnerability as it allows an attacker to take complete control of system; so Dell recommends customers to upgrade at the earliest opportunity.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53483"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-58473",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.30489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "topoteretes",
      "product": "cognee",
      "cwe": "CWE-306",
      "title": "Cognee < 1.2.0 Unauthorized LLM Configuration Overwrite via /api/v1/settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58473"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-34152",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.3046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify: Command Injection via Newline in Pre/Post Deployment Commands (Heredoc Transport)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34152"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-57871",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MicroRealEstate",
      "product": "MicroRealEstate",
      "cwe": "CWE-23",
      "title": "Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overwrite system files. This issue affects MicroRealEstate: through 1.0.0-alpha3.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57871"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-48588",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00361,
      "epss_percentile": 0.29342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djangoproject",
      "product": "Django",
      "cwe": "CWE-524",
      "title": "Potential exposure of private data via cached Set-Cookie response",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48588"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-59707",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0036,
      "epss_percentile": 0.29283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LocalAI",
      "product": "LocalAI",
      "cwe": "CWE-918",
      "title": "LocalAI - Server-Side Request Forgery via POST /models/apply",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59707"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-44938",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.29047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUSE",
      "product": "Rancher",
      "cwe": "CWE-522",
      "title": "Fleet has PSS Bypass through addLabelsFromOptions in Fleet Agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44938"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-13696",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.28749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HAVELSAN Inc.",
      "product": "Liman MYS",
      "cwe": "CWE-90",
      "title": "LDAP Injection in HAVELSAN's Liman MYS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13696"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-34158",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify: Command injection via single-quote breakout in Docker Compose custom commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34158"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-34058",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify: OS Command Injection via Unmanaged Container Operations - Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34058"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-58469",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gnuwget",
      "product": "wget",
      "cwe": "CWE-125",
      "title": "GNU Wget 1.25.0 Heap Buffer Underread via Metalink URL Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58469"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-51937",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.2816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-306",
      "title": "An issue in Oneblog V2.3.9 allows a remote attacker to obtain sensitive information via the RestApiController.java, JsApiTicketComponent.java, and the GetAccessTokenComponent.java component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51937"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-34057",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify: Authenticated Remote Code Execution via Command Injection in Database Import Container Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34057"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-59708",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ghostfolio",
      "product": "ghostfolio",
      "cwe": "CWE-862",
      "title": "Ghostfolio - Unauthorized Portfolio Data Exposure via Public Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59708"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-34035",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify: Host RCE via Log Drain secret/env command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34035"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-55078",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00338,
      "epss_percentile": 0.26834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coder",
      "product": "coder",
      "cwe": "CWE-409",
      "title": "Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55078"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-55077",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00336,
      "epss_percentile": 0.2665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coder",
      "product": "coder",
      "cwe": "CWE-285",
      "title": "Coder: User-admin role can reset owner account password",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55077"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-55079",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.26604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coder",
      "product": "coder",
      "cwe": "CWE-789",
      "title": "Coder's unbounded memory allocation in provisioner file upload allows authenticated denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55079"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-45796",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00335,
      "epss_percentile": 0.26525,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coder",
      "product": "coder",
      "cwe": "CWE-918",
      "title": "Coder vulnerable to unauthenticated SSRF via Azure Instance Identity Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45796"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-55631",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.24092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-22",
      "title": "DataEase: Path Traversal Leading to Arbitrary File Deletion via Font Management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55631"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-55076",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coder",
      "product": "coder",
      "cwe": "CWE-287",
      "title": "Coder's OIDC email_verified type coercion bypass enables account takeover via unverified email linking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55076"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-55434",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.23393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coder",
      "product": "coder",
      "cwe": "CWE-770",
      "title": "Coder vulnerable to denial of service via unbounded request body in AI Bridge provider endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55434"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-12375",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.23005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "uncanny-automator-pro",
      "cwe": null,
      "title": "Uncanny Automator Pro 7.3.0.5 - Backdoor via Compromised Vendor Update Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12375"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-54607",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "labring",
      "product": "FastGPT",
      "cwe": "CWE-918",
      "title": "FastGPT: SSRF in HTTP-tool OpenAPI schema importer via SwaggerParser $ref (bypasses the isInternalAddress guard)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54607"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-55418",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00299,
      "epss_percentile": 0.22516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "labring",
      "product": "FastGPT",
      "cwe": "CWE-639",
      "title": "FastGPT: S3 presign/read handlers do not bind the object key to the caller's team (cross-team file disclosure)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55418"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-34037",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00297,
      "epss_percentile": 0.22334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-639",
      "title": "Cross-Tenant Resource Cloning via Broken Object-Level Authorization in cloneTo()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34037"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-14940",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11",
      "cwe": "CWE-122",
      "title": "389-ds-base: 389-ds-base: heap-buffer-overflow in dn normalization via quoted multivalued rdn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14940"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-49471",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oraios",
      "product": "serena",
      "cwe": "CWE-306",
      "title": "Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49471"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-57172",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-321",
      "title": "DataEase: Hardcoded JWT Signing Secret in ShareLink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57172"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-12277",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Frontend File Manager Plugin",
      "cwe": null,
      "title": "Frontend File Manager Plugin <= 23.6 - Unauthenticated Arbitrary File Deletion via Saved File Metadata Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12277"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-50529",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.21092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-863",
      "title": "DataEase: Link Token Leakage Prior to Share Password/Ticket Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50529"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-55075",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.21065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coder",
      "product": "coder",
      "cwe": "CWE-287",
      "title": "Coder vulnerable to OIDC account takeover via email-based user matching and email_verified bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55075"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-53877",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djangoproject",
      "product": "Django",
      "cwe": "CWE-805",
      "title": "Heap buffer over-read in GDALRaster",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53877"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-50811",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-125",
      "title": "An out-of-bounds read vulnerability exists in FreeType 2.14.3 and versions before commit 5a280ecde6f324de0d226261036e736e0cb49a71 in src/truetype/ttgxvar.c, in the TT_Get_Var_Design implementation used by FT_Get_Var_Design_Coordinates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50811"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-44877",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hewlett Packard Enterprise (HPE)",
      "product": "HPE Networking Instant On",
      "cwe": "CWE-200",
      "title": "Unauthenticated Remote Disclosure of Cryptographic Secrets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44877"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-55647",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-79",
      "title": "DataEase: authenticated stored XSS in the dashboard text components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55647"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-12948",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Digi International",
      "product": "Digi PortServer TS",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12948"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-13020",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00266,
      "epss_percentile": 0.18622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Esri",
      "product": "Portal for ArcGIS",
      "cwe": "CWE-640",
      "title": "Weak Password Recovery Mechanism in Portal for ArcGIS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13020"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-55635",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-89",
      "title": "DataEase: Authenticated SQL Injection in Chart Quota Filters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55635"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-55427",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coder",
      "product": "coder",
      "cwe": "CWE-74",
      "title": "Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55427"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-48958",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.18114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260712] - Incorrect Access Control in com_fields webservice endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48958"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-46354",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coder",
      "product": "coder",
      "cwe": "CWE-347",
      "title": "Coder: PKCS#7 signature bypass in Azure instance identity allows unauthenticated agent token theft",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46354"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-59706",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00259,
      "epss_percentile": 0.17793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mem0",
      "product": "mem0",
      "cwe": "CWE-306",
      "title": "mem0 - Unauthenticated Config API Exposure and SSRF via ollama_base_url",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59706"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-12352",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Digi International",
      "product": "PortServer TS 1/2/4",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12352"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-58384",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 9",
      "cwe": "CWE-190",
      "title": "Gimp: gimp: integer overflow in read_rle_channel()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58384"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-7017",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.1756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HAARG",
      "product": "HTTP::Tiny",
      "cwe": "CWE-522",
      "title": "HTTP::Tiny versions before 0.095 for Perl forward credential headers to cross-origin redirect targets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7017"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-42147",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-918",
      "title": "Coolify: SSRF via S3 Storage Endpoint in testConnection()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42147"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-55592",
      "cvss_base": 3.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00255,
      "epss_percentile": 0.1727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lissy93",
      "product": "dashy",
      "cwe": "CWE-79",
      "title": "Dashy: XSS in workspace url parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55592"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-49229",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "actualbudget",
      "product": "actual",
      "cwe": "CWE-613",
      "title": "Actual: Disabled OpenID users keep access through existing session tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49229"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-5799",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Idvlabs Software and Consulting Services Inc.",
      "product": "Ontime",
      "cwe": "CWE-639",
      "title": "IDOR in Idvlabs' Ontime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5799"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-42145",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0025,
      "epss_percentile": 0.16632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-434",
      "title": "Coolify: File Upload Without Type or Size Validation in Database Backup Restore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42145"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-55417",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chevereto",
      "product": "chevereto",
      "cwe": "CWE-862",
      "title": "Chevereto private profile setting leaks username on /json endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55417"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-4375",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00248,
      "epss_percentile": 0.16445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "DoLeads Integrator",
      "cwe": null,
      "title": "DoLeads Integrator <= 1.2.2 & wp2epub <= 0.65 - Unauthenticated RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4375"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-58470",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gnuwget",
      "product": "wget",
      "cwe": "CWE-190",
      "title": "GNU Wget 1.25.0 Integer Overflow via Content-Range Header Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58470"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2025-12799",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat JBoss Enterprise Application Platform 8.1.7.GA",
      "cwe": "CWE-79",
      "title": "Jastow: jastow cross-site scripting attack due to unsanitized uri",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12799"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-55428",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coder",
      "product": "coder",
      "cwe": "CWE-285",
      "title": "Coder: Route hijacking through lack of validation of agent-supplied AllowedIPs in tailnet coordinator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55428"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-5730",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Idvlabs Software and Consulting Services Inc.",
      "product": "Ontime",
      "cwe": "CWE-639",
      "title": "IDOR in Idvlabs' Ontime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5730"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-50007",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "actualbudget",
      "product": "actual",
      "cwe": "CWE-862",
      "title": "Actual: Shared users can perform owner-only file management actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50007"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-54601",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.1618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "labring",
      "product": "FastGPT",
      "cwe": "CWE-915",
      "title": "FastGPT: reTrainingCollection allows server-owned datasetId override causing cross-tenant authorization confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54601"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-34044",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.15865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-639",
      "title": "Coolify: Cross-team IDOR in logs component (resource lookup not team-scoped)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34044"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-48948",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260702] - Incorrect Access Control in com_contact vcf download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48948"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-48957",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260711] - Incorrect Access Control in com_privacy webservice endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48957"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-50530",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-639",
      "title": "DataEase: Token with Overly Broad Privileges in Share Mode: Access to Unshared Datasets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50530"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-53730",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-862",
      "title": "DataEase: Unauthorized Access to Engine Database via previewSql Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53730"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-57868",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MicroRealEstate",
      "product": "MicroRealEstate",
      "cwe": "CWE-639",
      "title": "MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects MicroRealEstate: through 1.0.0-alpha3.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57868"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-11328",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "timstrifler",
      "product": "Exclusive Addons for Elementor",
      "cwe": "CWE-79",
      "title": "Exclusive Addons for Elementor <= 2.7.9.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11328"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-54602",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "labring",
      "product": "FastGPT",
      "cwe": "CWE-639",
      "title": "FastGPT: Cross-team LLM request/response disclosure (IDOR) via /api/core/ai/record/getRecord",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54602"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-27790",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.13712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gallagher",
      "product": "T-20 Readers",
      "cwe": "CWE-248",
      "title": "Uncaught Exception (CWE-248) in the T20 Readers allows an authenticated and authorized operator to trigger a restart by sending specific requests, resulting in a temporary denial of service. Version of Command Centre affected: * 9.50 prior to vCR9.50.260616a (distributed in 9.50.1587(MR1)) * 9.40 prior to vCR9.40.260616a (distributed in 9.40.3130(MR3)) * 9.30 prior to vCR9.30.260616a (distributed in 9.30.3983(MR5)) * 9.20 prior to vCR9.20.260616a (distributed in 9.20.4349(MR7)) * all versions of 9.10 and prior.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27790"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-27844",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00227,
      "epss_percentile": 0.13713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gallagher",
      "product": "Controller 7000 and 6000",
      "cwe": "CWE-248",
      "title": "Uncaught Exception (CWE-248) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authenticated and authorized operator to trigger a Controller restart by sending specific requests, resulting in a temporary denial of service. Version of Command Centre affected: * 9.50 prior to vCR9.50.260616a (distributed in 9.50.1587(MR1)) * 9.40 prior to vCR9.40.260616a (distributed in 9.40.3130(MR3)) * 9.30 prior to vCR9.30.260616a (distributed in 9.30.3983(MR5)) * 9.20 prior to vCR9.20.260616a (distributed in 9.20.4349(MR7)) * all versions of 9.10 and prior.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27844"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-58471",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gnuwget",
      "product": "wget",
      "cwe": "CWE-122",
      "title": "GNU Wget 1.25.0 Heap Buffer Overflow via convert_fname() in url.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58471"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-58472",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gnuwget",
      "product": "wget",
      "cwe": "CWE-190",
      "title": "GNU Wget 1.25.0 Heap Buffer Overflow via HTML Attribute Encoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58472"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-34149",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00221,
      "epss_percentile": 0.12954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify: Authenticated Host-Level RCE via Unescaped Database Credentials in Backup Jobs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34149"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-59704",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00216,
      "epss_percentile": 0.12363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap",
      "product": "Cap",
      "cwe": "CWE-862",
      "title": "Cap - Missing Access Control in Video AI Metadata Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59704"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-57869",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.1221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MicroRealEstate",
      "product": "MicroRealEstate",
      "cwe": "CWE-639",
      "title": "Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access documents uploaded by landlords or tenants without authorization. This issue affects MicroRealEstate: through 1.0.0-alpha3.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57869"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-57870",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.1221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MicroRealEstate",
      "product": "MicroRealEstate",
      "cwe": "CWE-639",
      "title": "Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations without authorization. This issue affects MicroRealEstate: through 1.0.0-alpha3.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57870"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-53935",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cilium",
      "product": "cilium",
      "cwe": "CWE-863",
      "title": "CiliumLocalRedirectPolicy addressMatcher allows cross-namespace service traffic hijacking and can break service translation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53935"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-48955",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260709] - Incorrect Access Control in com_workflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48955"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-53878",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.11015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "djangoproject",
      "product": "Django",
      "cwe": "CWE-144",
      "title": "Header injection possibility since DomainNameValidator accepted newlines in input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53878"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-59709",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ghostfolio",
      "product": "Ghostfolio",
      "cwe": "CWE-862",
      "title": "Ghostfolio - Unauthorized Portfolio Holding Tag Modification via Missing Permission Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59709"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-58468",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocobase",
      "product": "nocobase",
      "cwe": "CWE-918",
      "title": "NocoBase 2.1.20 Server-Side Request Forgery via serverRequest wrapper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58468"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-46700",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "actualbudget",
      "product": "actual",
      "cwe": "CWE-285",
      "title": "Actual: Missing authorization on GET /secret/:name allows non-admin OpenID users to enumerate admin-configured bank-sync secrets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46700"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-8377",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00198,
      "epss_percentile": 0.09943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Armiya Information Technologies Ltd. Co.",
      "product": "Access Control System (GKS)",
      "cwe": "CWE-862",
      "title": "Improper Authorization in Armiya Technologies' Access Control System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8377"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-48947",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260701] - Incorrect Access Control in com_media webservice endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48947"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-55435",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coder",
      "product": "coder",
      "cwe": "CWE-863",
      "title": "Suspended Coder users retain access to AI Bridge LLM proxy endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55435"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-11340",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00195,
      "epss_percentile": 0.09552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HAVELSAN Inc.",
      "product": "Liman MYS",
      "cwe": "CWE-862",
      "title": "Authorization Bypass in HAVELSAN's Open Source Project Liman MYS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11340"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-42201",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00195,
      "epss_percentile": 0.09603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify: OS Command Injection via Database Credential Fields in Docker Compose Service Commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42201"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-55408",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.0872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "koodo-reader",
      "product": "koodo-reader",
      "cwe": "CWE-94",
      "title": "Koodo Reader: Remote code execution via malicious epub file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55408"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-42172",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00188,
      "epss_percentile": 0.08768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-613",
      "title": "Coolify: Sanctum API Tokens Have No Expiration — Leaked Tokens Grant Permanent Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42172"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-11348",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.08436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HAVELSAN Inc.",
      "product": "Liman MYS",
      "cwe": "CWE-347",
      "title": "Authentication Bypass in HAVELSAN's Open Source Project Liman MYS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11348"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-59153",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00179,
      "epss_percentile": 0.07713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ankitects",
      "product": "anki",
      "cwe": "CWE-346",
      "title": "Anki's local HTTP server does not sufficiently validate requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59153"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-50179",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "actualbudget",
      "product": "actual",
      "cwe": "CWE-1236",
      "title": "Actual: CSV Formula Injection in Transaction Export via Imported Payee/Notes Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50179"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-54698",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hasura",
      "product": "graphql-engine",
      "cwe": "CWE-863",
      "title": "Hasura: Row-level authorization bypass on table computed fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54698"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-34170",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-918",
      "title": "Coolify: Server-Side Request Forgery via attacker-controlled GitHub App API URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34170"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-57851",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Micro-Star International (MSI)",
      "product": "KernCoreLib64.sys",
      "cwe": "CWE-782",
      "title": "MSI KernCoreLib64.sys Privilege Escalation via IOCTL Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57851"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-48956",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-284",
      "title": "Joomla! Core - [20260710] - Incorrect Access Control in com_modules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48956"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-58266",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.0637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ankitects",
      "product": "anki",
      "cwe": "CWE-346",
      "title": "Anki: User scripts in iframes have access to the internal Anki API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58266"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-26053",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.04949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gallagher",
      "product": "Command Centre Server",
      "cwe": "CWE-266",
      "title": "An Incorrect Privilege Assignment (CWE-266) vulnerability in the Command Centre Server allows an authenticated operator with limited privileges to perform some operations that they would not normally be authorized to perform. Version of Command Centre affected: 9.50 prior to vEL9.50.1587(MR1), 9.40 prior to vEL9.40.3130(MR3), 9.30 prior to vEL9.30.3983(MR5), 9.20 prior to vEL9.20.4349(MR7), all versions of 9.10.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26053"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-53511",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kovidgoyal",
      "product": "calibre",
      "cwe": "CWE-94",
      "title": "calibre: Arbitrary Code Execution in Template Formatter via Book Metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53511"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-14935",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.0015,
      "epss_percentile": 0.04756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-670",
      "title": "Gstreamer: gstreamer: webrtcbin accepts remote sdp without a=fingerprint due to inverted presence check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14935"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-7380",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Armiya Information Technologies Ltd. Co.",
      "product": "Access Control System (GKS)",
      "cwe": "CWE-80",
      "title": "HTML Injection in Armiya Technologies' Access Control System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7380"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-8306",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Armiya Information Technologies Ltd. Co.",
      "product": "Access Control System (GKS)",
      "cwe": "CWE-79",
      "title": "Stored XSS in Armiya Technologies' Access Control System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8306"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-48949",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-79",
      "title": "Joomla! Core - [20260703] - XSS in MFA method management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48949"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-48950",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-79",
      "title": "Joomla! Core - [20260704] - XSS in com_templates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48950"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-48951",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-79",
      "title": "Joomla! Core - [20260705] - XSS in various modalreturn layouts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48951"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-48952",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-79",
      "title": "Joomla! Core - [20260706] - XSS in com_installer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48952"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-48953",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-79",
      "title": "Joomla! Core - [20260707] - XSS in the generic image output layout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48953"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-48954",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Joomla! Project",
      "product": "Joomla! CMS",
      "cwe": "CWE-79",
      "title": "Joomla! Core - [20260708] - XSS through language overrides",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48954"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-34171",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-352",
      "title": "Coolify: Account takeover via CSRF-able GET endpoint that resets password to attacker-known value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34171"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-10834",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.04043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Travel Engine",
      "cwe": null,
      "title": "WP Travel Engine < 6.8.1 - Subscriber+ Arbitrary Media File Move via user_profile_image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10834"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-36162",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbitrary Javascript or HTML via injecting a crafted payload into the Name parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36162"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-36163",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in the context of the victim's browser via the uploading of and user interaction with a crafted HTML file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36163"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-42953",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.03883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Labcenter",
      "product": "Proteus",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in Labcenter Proteus",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42953"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-34198",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-346",
      "title": "Coolify: Password reset link poisoning via X-Forwarded-Host header spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34198"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-28378",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00136,
      "epss_percentile": 0.03502,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana Enterprise",
      "cwe": "CWE-284",
      "title": "Cross-Organization Public Dashboard Deletion via Missing Org Isolation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28378"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-10659",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.03363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-476",
      "title": "NULL pointer dereference in Zephyr Dhara FTL disk driver on flash read error during journal resume",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10659"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-8309",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Armiya Information Technologies Ltd. Co.",
      "product": "Access Control System (GKS)",
      "cwe": "CWE-79",
      "title": "Reflected XSS in Armiya Technologies' Access Control System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8309"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-46672",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "actualbudget",
      "product": "actual",
      "cwe": "CWE-1236",
      "title": "Actual: CSV Formula Injection in `@actual-app/cli` `--format csv` Output via Custom `escapeCsv` Helper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46672"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-49033",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.03106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Labcenter",
      "product": "Proteus",
      "cwe": "CWE-121",
      "title": "Stack-Based Buffer Overflow in Labcenter Proteus",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49033"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-42958",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Labcenter",
      "product": "Proteus",
      "cwe": "CWE-416",
      "title": "Use After Free in Labcenter Proteus",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42958"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-50810",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in GPAC master HEAD before commit b35c61f104b85fbb16520ac2838d5d2ef70845b5 allows attackers to cause a denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50810"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-13199",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Raspberry Pi",
      "product": "Raspberry Pi 5 and Compute Module 5",
      "cwe": "CWE-331",
      "title": "Insufficient Entropy in Raspberry Pi 5 and Compute Module 5",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13199"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-58315",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SEIKO EPSON CORPORATION",
      "product": "Web Config",
      "cwe": "CWE-352",
      "title": "Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config. If a user views a malicious page while logged into Web Config, unintended operations may be performed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58315"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-58583",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00101,
      "epss_percentile": 0.01049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FluxInk",
      "product": "Color Management Driver",
      "cwe": "CWE-269",
      "title": "FluxInk Color Management Driver local privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58583"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-14867",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00092,
      "epss_percentile": 0.00598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "arcinfo",
      "product": "PcVue",
      "cwe": "CWE-256",
      "title": "Insecure password storage in User directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14867"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-14969",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00077,
      "epss_percentile": 0.00134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11",
      "cwe": "CWE-329",
      "title": "389-ds-base: 389-ds-base: static initialization vector in aes-cbc/3des-cbc attribute encryption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14969"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-14868",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0005,
      "epss_percentile": 0.00001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "arcinfo",
      "product": "PcVue",
      "cwe": "CWE-326",
      "title": "Weak encryption mechanism for User directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14868"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10659",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10659 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49471",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49471 (oraios serena). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55255",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55255 (langflow-ai langflow). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55490",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55490 (openwrt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56290",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56290 (JoomlaCK.fr Page Builder CK extension for Joomla). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56812",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56812 (phoenixframework phoenix). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58384",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58384 (Red Hat Enterprise Linux 9). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58583",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58583 (FluxInk Color Management Driver). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
