{
  "day": "2026-07-08",
  "boundary": "UTC calendar day",
  "published_count": 362,
  "by_severity": {
    "CRITICAL": 26,
    "HIGH": 170,
    "MEDIUM": 148,
    "LOW": 18
  },
  "kev_count": 0,
  "exploit_reference_count": 45,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-58480",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0195,
      "epss_percentile": 0.78614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Creative Themes",
      "product": "Blocksy Companion",
      "cwe": "CWE-434",
      "title": "Blocksy Companion Pro < 2.1.47 Unauthenticated File Upload via save_attachments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58480"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-60102",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01761,
      "epss_percentile": 0.76197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "horde",
      "product": "Vfs",
      "cwe": "CWE-78",
      "title": "Horde VFS < 3.0.1 OS Command Injection via Horde_Vfs_Smb Driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60102"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-15035",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.01545,
      "epss_percentile": 0.72977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bentoml",
      "product": "OpenLLM",
      "cwe": "CWE-78",
      "title": "bentoml OpenLLM Model Repository Directory Name common.py async_run_command command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15035"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-24700",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.01522,
      "epss_percentile": 0.72577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "An OS command injection vulnerability exists in the start_lltd() function of the \"rc\" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The machine_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24700"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-44024",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01092,
      "epss_percentile": 0.62766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fluent",
      "product": "fluentd",
      "cwe": "CWE-22",
      "title": "Fluentd: Remote Code Execution (RCE) via Arbitrary File Write in `${tag}` Placeholder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44024"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-15033",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01067,
      "epss_percentile": 0.62116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "christopherthielen",
      "product": "check-peer-dependencies",
      "cwe": "CWE-77",
      "title": "christopherthielen check-peer-dependencies peerDependencies packageUtils.js shelljs.exec os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15033"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-0288",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00958,
      "epss_percentile": 0.58695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cloud NGFW",
      "cwe": "CWE-787",
      "title": "PAN-OS: Buffer Overflow Vulnerabilities in User-ID Terminal Server Agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0288"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-24697",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00957,
      "epss_percentile": 0.58686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "An OS command injection vulnerability exists in the start_bonjour() function of the \"rc\" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The wan_hostname configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24697"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-24698",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00957,
      "epss_percentile": 0.58686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "An OS command injection vulnerability exists in the save_syslog_to_file() function of the \"httpd\" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The model_name configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24698"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-24699",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00957,
      "epss_percentile": 0.58685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "An OS command injection vulnerability exists in the sub_34984() function of the \"rc\" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W routers with firmware 1.2.2.5 / 1.2.2.8. The lan_ipv6_prefixlen configuration parameter is not properly sanitized, which could allow an authenticated remote attacker to execute arbitrary OS commands with root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24699"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-6854",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00953,
      "epss_percentile": 0.58576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joedolson",
      "product": "My Calendar – Accessible Event Manager",
      "cwe": "CWE-89",
      "title": "My Calendar <= 3.7.8 - Unauthenticated SQL Injection via 'mc_auth' and 'mc_host' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6854"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-14487",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00742,
      "epss_percentile": 0.51861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tombgtn",
      "product": "Simple Coherent Form",
      "cwe": "CWE-22",
      "title": "Simple Coherent Form <= 2.4.13 - Unauthenticated Arbitrary File Deletion via 'id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14487"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-14244",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00692,
      "epss_percentile": 0.50049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jssor",
      "product": "Jssor Slider by jssor.com",
      "cwe": "CWE-22",
      "title": "Jssor Slider by jssor.com <= 3.1.24 - Unauthenticated Arbitrary File Read via 'url' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14244"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-52200",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0068,
      "epss_percentile": 0.4958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax web management API endpoint in MifiService.apk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52200"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-29009",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00557,
      "epss_percentile": 0.44027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "u-boot",
      "product": "u-boot",
      "cwe": "CWE-120",
      "title": "U-Boot < 2026.07-rc2 Buffer Overflow in nfs_readlink_reply() via NFS READLINK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29009"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-29008",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00552,
      "epss_percentile": 0.43753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "u-boot",
      "product": "u-boot",
      "cwe": "CWE-191",
      "title": "U-Boot 2026.04-rc3 Integer Underflow DoS via tcp_rx_state_machine()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29008"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-29007",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00548,
      "epss_percentile": 0.43552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "u-boot",
      "product": "u-boot",
      "cwe": "CWE-125",
      "title": "U-Boot 2026.04-rc3 Out-of-Bounds Read in tcp_rx_state_machine via tcp.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29007"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-14489",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00545,
      "epss_percentile": 0.43365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "globalprogramming",
      "product": "WHMCS Bridge",
      "cwe": "CWE-434",
      "title": "WHMCS Bridge <= 6.9 - Unauthenticated Arbitrary File Upload via 'ccce' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14489"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-58210",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00505,
      "epss_percentile": 0.4106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nats-io",
      "product": "nats-server",
      "cwe": "CWE-400",
      "title": "NATS Server: MQTT partial CONNECT packets can exhaust pre-auth memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58210"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-58250",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00505,
      "epss_percentile": 0.41061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nats-io",
      "product": "nats-server",
      "cwe": "CWE-476",
      "title": "NATS Server: Pre-auth server crash via double INFO in leafnode handshake",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58250"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-14158",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00501,
      "epss_percentile": 0.40811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "totalbounty",
      "product": "Widget Logic Visual",
      "cwe": "CWE-434",
      "title": "Widget Logic Visual <= 1.52 - Authenticated (Subscriber+) Remote Code Execution via 'nwlv[cod-tag]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14158"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-10698",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00496,
      "epss_percentile": 0.4052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress",
      "product": "MOVEit Transfer",
      "cwe": "CWE-943",
      "title": "Table scope bypass vulnerability in custom reports",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10698"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-60105",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00474,
      "epss_percentile": 0.39148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Monsta Limited of New Zealand",
      "product": "Monsta FTP",
      "cwe": "CWE-918",
      "title": "Monsta FTP < 2.14.5 SSRF via IPv4-Mapped IPv6 Address Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60105"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-54772",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0047,
      "epss_percentile": 0.38846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CoreWCF",
      "product": "CoreWCF",
      "cwe": "CWE-400",
      "title": "CoreWCF: Pre-authentication infinite-loop CPU exhaustion in CoreWCF net.tcp / net.pipe / net.uds framing handshake",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54772"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-59892",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00455,
      "epss_percentile": 0.37936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-js",
      "cwe": "CWE-248",
      "title": "OpenTelemetry JavaScript: Denial of service in `JaegerPropagator` via unhandled exception on a malformed header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59892"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-55470",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00445,
      "epss_percentile": 0.37188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hapifhir",
      "product": "org.hl7.fhir.core",
      "cwe": "CWE-1333",
      "title": "HAPI FHIR: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55470"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-49866",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libp2p",
      "product": "js-libp2p",
      "cwe": "CWE-770",
      "title": "libp2p: CPU DoS via oversized IHAVE and IWANT control message arrays",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49866"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-60000",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-770",
      "title": "sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60000"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-31309",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0044,
      "epss_percentile": 0.36803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-862",
      "title": "Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to arbitrarily overwrite the node's configuration and achieve a full node takeover via a crafted POST request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31309"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-59879",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "immutable-js",
      "product": "immutable-js",
      "cwe": "CWE-190",
      "title": "Immutable.js `List` 32-bit trie overflow → unrecoverable DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59879"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-14495",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00434,
      "epss_percentile": 0.36342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdo5ea",
      "product": "DoLogin Security",
      "cwe": "CWE-338",
      "title": "DoLogin Security <= 4.3 - Unauthenticated Authentication Bypass via Insufficient Randomness via 'dologin' Parameter Weak PRNG Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14495"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-59880",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "immutable-js",
      "product": "immutable-js",
      "cwe": "CWE-407",
      "title": "Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59880"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-56002",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00428,
      "epss_percentile": 0.35863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "X.Org",
      "product": "libXfont2",
      "cwe": "CWE-122",
      "title": "libXfont2 PCF Font Parsing Heap Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56002"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-59873",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00424,
      "epss_percentile": 0.35575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "isaacs",
      "product": "node-tar",
      "cwe": "CWE-770",
      "title": "node-tar: Decompression/parse DoS via unlimited input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59873"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-59869",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodeca",
      "product": "js-yaml",
      "cwe": "CWE-407",
      "title": "js-yaml: YAML merge-key chains can force quadratic CPU consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59869"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-59874",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00418,
      "epss_percentile": 0.35041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "isaacs",
      "product": "node-tar",
      "cwe": "CWE-835",
      "title": "node-tar: Negative tar entry size causes infinite loop in archive replace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59874"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-59922",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00418,
      "epss_percentile": 0.3504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lepture",
      "product": "mistune",
      "cwe": "CWE-407",
      "title": "Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59922"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-55760",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00415,
      "epss_percentile": 0.34749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jknack",
      "product": "handlebars.java",
      "cwe": "CWE-22",
      "title": "handlebars.java FileTemplateLoader Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55760"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-44025",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00414,
      "epss_percentile": 0.3468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fluent",
      "product": "fluentd",
      "cwe": "CWE-306",
      "title": "Fluentd: Exposure of Sensitive Information via Monitor Agent API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44025"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-59928",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00413,
      "epss_percentile": 0.34571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lepture",
      "product": "mistune",
      "cwe": "CWE-407",
      "title": "Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59928"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-55404",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00412,
      "epss_percentile": 0.34562,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yt-dlp",
      "product": "yt-dlp",
      "cwe": "CWE-74",
      "title": "yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55404"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-44332",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00411,
      "epss_percentile": 0.34392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gofiber",
      "product": "fiber",
      "cwe": "CWE-203",
      "title": "Fiber: Username Enumeration via Timing Oracle in BasicAuth Default Authorizer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44332"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-59868",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodeca",
      "product": "js-yaml",
      "cwe": "CWE-770",
      "title": "js-yaml: YAML merge-key chains can force quadratic CPU consumption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59868"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-59870",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodeca",
      "product": "js-yaml",
      "cwe": "CWE-770",
      "title": "js-yaml quadratic-complexity denial of service via YAML11_SCHEMA !!omap parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59870"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-59871",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "isaacs",
      "product": "node-tar",
      "cwe": "CWE-704",
      "title": "node-tar: Process crash via PAX numeric path type confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59871"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-59925",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lepture",
      "product": "mistune",
      "cwe": "CWE-407",
      "title": "inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59925"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-59939",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "httplib2",
      "product": "httplib2",
      "cwe": "CWE-409",
      "title": "httplib2: Decompression Bomb Denial of Service via Unbounded gzip/deflate Response Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59939"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-59803",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00408,
      "epss_percentile": 0.34154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smallnest",
      "product": "rpcx",
      "cwe": "CWE-409",
      "title": "rpcx - Denial of Service via Gzip Decompression Bomb in Wire Protocol",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59803"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-55778",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00406,
      "epss_percentile": 0.33999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "parse-community",
      "product": "parse-server",
      "cwe": "CWE-434",
      "title": "Parse Server: Stored XSS via non-standard file extension bypassing file upload extension blocklist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55778"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-59890",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.33906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pypa",
      "product": "setuptools",
      "cwe": "CWE-176",
      "title": "setuptools: MANIFEST.in exclusion bypass in sdist via Unicode normalization collision (NFC/NFD) on macOS APFS/HFS+",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59890"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-15053",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33707,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tanium",
      "product": "Tanium Server",
      "cwe": "CWE-789",
      "title": "Tanium addressed a denial of service vulnerability in Tanium Server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15053"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-15112",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00401,
      "epss_percentile": 0.33476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15112"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-59924",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00399,
      "epss_percentile": 0.33357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lepture",
      "product": "mistune",
      "cwe": "CWE-22",
      "title": "Mistune: Arbitrary File Read via Include directive path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59924"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-58207",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00397,
      "epss_percentile": 0.33077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nats-io",
      "product": "nats-server",
      "cwe": "CWE-190",
      "title": "NATS Server: Remote crash via integer overflow in Connz pagination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58207"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-12378",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00389,
      "epss_percentile": 0.32231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Appointment Booking Calendar Plugin and Scheduling Plugin",
      "cwe": null,
      "title": "BookingPress <= 1.1.28 - Unauthenticated PHP Object Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12378"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-6896",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00389,
      "epss_percentile": 0.32209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-79",
      "title": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6896"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-54061",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00388,
      "epss_percentile": 0.32109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dgraph-io",
      "product": "dgraph",
      "cwe": "CWE-306",
      "title": "Dgraph Alpha group stores can be replaced via unauthenticated external snapshot import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54061"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-59703",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "repomix",
      "product": "repomix",
      "cwe": "CWE-552",
      "title": "repomix - Local File Inclusion via file:// URL Scheme in Git Clone Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59703"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-57481",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00386,
      "epss_percentile": 0.31962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "parse-community",
      "product": "parse-server",
      "cwe": "CWE-200",
      "title": "Parse Server: LiveQuery discloses object data to a subscriber across an ACL read-access change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57481"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-12153",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00385,
      "epss_percentile": 0.31847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabilal",
      "product": "WP Learn Manager",
      "cwe": "CWE-862",
      "title": "WP Learn Manager <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation and Activation via jslearnmanager_ajax AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12153"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-55575",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "harttle",
      "product": "liquidjs",
      "cwe": "CWE-770",
      "title": "LiquidJS: `pop` filter bypasses `memoryLimit` accounting that its array-filter siblings enforce",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55575"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-42505",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00382,
      "epss_percentile": 0.31529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Go standard library",
      "product": "crypto/tls",
      "cwe": "CWE-201",
      "title": "Invoking Encrypted Client Hello privacy leak in crypto/tls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42505"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-56001",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00381,
      "epss_percentile": 0.31365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "X.Org",
      "product": "libXfont2",
      "cwe": "CWE-122",
      "title": "libXfont2 BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56001"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-55471",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hapifhir",
      "product": "org.hl7.fhir.core",
      "cwe": "CWE-611",
      "title": "HAPI FHIR: XXE in XsltUtilities.saxonTransform via unhardened Saxon TransformerFactory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55471"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-10706",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.30888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adalo No-Code App Builder",
      "product": "App Builder",
      "cwe": null,
      "title": "Exposure of Sensitive Information to an Unauthorized attacker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10706"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-49146",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.30764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PETDANCE",
      "product": "App::Ack",
      "cwe": "CWE-770",
      "title": "App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49146"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-14454",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00374,
      "epss_percentile": 0.30703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TONYC",
      "product": "Imager",
      "cwe": "CWE-196",
      "title": "Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14454"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-56003",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.30608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "X.Org",
      "product": "libXfont2",
      "cwe": "CWE-122",
      "title": "libXfont2 computeProps Property Buffer Heap Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56003"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-53482",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.30459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect Data Domain",
      "cwe": "CWE-190",
      "title": "Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53482"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-15067",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Snowflake",
      "product": "Terraform Provider for Snowflake",
      "cwe": "CWE-89",
      "title": "Multiple Security Vulnerabilities in Terraform Provider for Snowflake Could Allow Privilege Escalation and Unauthorized Snowflake Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15067"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-58525",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30288,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-284",
      "title": "Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58525"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-59877",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "protobufjs",
      "product": "protobuf.js",
      "cwe": "CWE-835",
      "title": "protobufjs: Denial of Service via infinite loop in .proto option parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59877"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-35211",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0037,
      "epss_percentile": 0.30267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenCTI-Platform",
      "product": "opencti",
      "cwe": "CWE-94",
      "title": "OpenCTI: Elasticsearch Painless Script Injection via GraphQL `script` filter operator allows authenticated user to exfiltrate data and cause DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35211"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-44840",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00368,
      "epss_percentile": 0.30052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dgraph-io",
      "product": "dgraph",
      "cwe": "CWE-943",
      "title": "Dgraph Vulnerable to DQL Injection via checkUserPassword GraphQL Query",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44840"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-59935",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00367,
      "epss_percentile": 0.29968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-835",
      "title": "pypdf: Possible infinite loop for not terminated inline images (ASCII85 and ASCIIHex filter)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59935"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-15129",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.29833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15129"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-8650",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress",
      "product": "MOVEit Transfer",
      "cwe": "CWE-23",
      "title": "Authenticated Path Traversal allows MOVEit admins to view arbitrary system files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8650"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-56843",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00364,
      "epss_percentile": 0.2965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webpros",
      "product": "Plesk",
      "cwe": "CWE-522",
      "title": "Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because ownership is enforced only for certain lookup filters and schema validation is bypassed for legacy protocol versions. This results in cross-tenant disclosure of other tenants' FTP credentials stored in cleartext, which can be leveraged to execute code as another tenant's system user.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56843"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-45045",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00363,
      "epss_percentile": 0.29574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gofiber",
      "product": "fiber",
      "cwe": "CWE-290",
      "title": "Fiber: X-Real-IP Spoofing via Header.Add() in BalancerForward",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45045"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-54527",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00361,
      "epss_percentile": 0.29342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyterlab",
      "product": "jupyterlab-git",
      "cwe": "CWE-79",
      "title": "JupyterLab Git: Stored XSS leading to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54527"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-56297",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-362",
      "title": "FreeRDP - Use-After-Free via Race Condition in DRDYNVC Channel Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56297"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-44160",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.29235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fluent",
      "product": "fluentd",
      "cwe": "CWE-409",
      "title": "Fluentd: Denial of Service (DoS) via Gzip Decompression Bomb in `in_http` and `in_forward`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44160"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-56669",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.29004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elysiajs",
      "product": "elysia",
      "cwe": "CWE-407",
      "title": "Elysia: Inefficient Algorithmic Complexity and Interpretation Conflict",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56669"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-59821",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00355,
      "epss_percentile": 0.28753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BerriAI",
      "product": "litellm",
      "cwe": "CWE-94",
      "title": "LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59821"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-59725",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.2865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "socketio",
      "product": "socket.io",
      "cwe": "CWE-404",
      "title": "Socket.IO: Engine.IO Polling Transport Connection Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59725"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-59927",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00352,
      "epss_percentile": 0.28364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lepture",
      "product": "mistune",
      "cwe": "CWE-674",
      "title": "Mistune directives/include: mutual `.. include::` recursion crashes the renderer with `RecursionError`, denial of service via two attacker-controlled markdown files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59927"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-54528",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.28204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyterlab",
      "product": "jupyterlab-git",
      "cwe": "CWE-178",
      "title": "jupyterlab-git excluded_paths Case-Sensitivity Bypass Allows Reading Excluded Directories",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54528"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-8801",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00345,
      "epss_percentile": 0.27605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress",
      "product": "MOVEit Transfer",
      "cwe": "CWE-46",
      "title": "File Extension Restriction Bypass in MOVEit Transfer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8801"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-9695",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00345,
      "epss_percentile": 0.27599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dassault Systèmes",
      "product": "DELMIA Apriso",
      "cwe": "CWE-287",
      "title": "Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9695"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-58192",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "appium",
      "product": "appium",
      "cwe": "CWE-22",
      "title": "Appium: Unauthenticated arbitrary file/directory deletion in @appium/storage-plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58192"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-54499",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stanfordnlp",
      "product": "stanza",
      "cwe": "CWE-502",
      "title": "Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54499"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-59887",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "markdown-it",
      "product": "linkify-it",
      "cwe": "CWE-407",
      "title": "linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59887"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-58252",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00341,
      "epss_percentile": 0.2718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nats-io",
      "product": "nats-server",
      "cwe": "CWE-285",
      "title": "NATS Server: Subscribe Authz Bypass via Wildcard-Overlap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58252"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-59936",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.2717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-400",
      "title": "pypdf: Possible infinite loop for not terminated inline images",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59936"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-10699",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress",
      "product": "MOVEit Transfer",
      "cwe": "CWE-401",
      "title": "Memory leak in SFTP service can result in a denial of service in MOVEit Transfer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10699"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-59937",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0034,
      "epss_percentile": 0.2717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-400",
      "title": "pypdf: Possible long runtimes for repeated malformed cross-reference entries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59937"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-58251",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0034,
      "epss_percentile": 0.27055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nats-io",
      "product": "nats-server",
      "cwe": "CWE-285",
      "title": "NATS Server: Queue Subscribe Authz Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58251"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-59724",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "socketio",
      "product": "socket.io",
      "cwe": "CWE-20",
      "title": "Socket.IO: Engine.IO WebTransport SID DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59724"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-58208",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nats-io",
      "product": "nats-server",
      "cwe": "CWE-248",
      "title": "NATS Server: MQTT-over-WebSocket Path Can Crash WebSocket-Only JetStream Servers Before MQTT Is Enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58208"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-54775",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.26638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CoreWCF",
      "product": "CoreWCF",
      "cwe": "CWE-248",
      "title": "CoreWCF: Kafka consume pump halts permanently on a Kafka tombstone (null-value record), causing persistent endpoint denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54775"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-57480",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "parse-community",
      "product": "parse-server",
      "cwe": "CWE-407",
      "title": "Parse Server: Denial of service via exponential-time processing of deeply nested query operators",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57480"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-14500",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00333,
      "epss_percentile": 0.26261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sayantandas20",
      "product": "Bulk Order Update for WooCommerce",
      "cwe": "CWE-22",
      "title": "Bulk Order Update for WooCommerce <= 1.6 - Unauthenticated Arbitrary File Read via 'csv_url' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14500"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-15132",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15132"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-13320",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00332,
      "epss_percentile": 0.26186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-79",
      "title": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13320"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-36027",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.26136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-1313",
      "title": "An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proximate attacker to execute arbitrary code via the USB debugging (ADB) and Android Debug Bridge components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36027"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-56273",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0033,
      "epss_percentile": 0.25977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-22",
      "title": "Flowise - Path Traversal in Vector Store basePath Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56273"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-49145",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PETDANCE",
      "product": "App::Ack",
      "cwe": "CWE-73",
      "title": "App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49145"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-49147",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PETDANCE",
      "product": "App::Ack",
      "cwe": "CWE-150",
      "title": "App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49147"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-55874",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seaweedfs",
      "product": "seaweedfs",
      "cwe": "CWE-22",
      "title": "SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55874"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-59702",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00324,
      "epss_percentile": 0.25318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "repomix",
      "product": "repomix",
      "cwe": "CWE-918",
      "title": "repomix - Server-Side Request Forgery via Unvalidated Repository URLs in POST /api/pack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59702"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-58213",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nats-io",
      "product": "nats-server",
      "cwe": "CWE-74",
      "title": "NATS Server: MQTT SUBSCRIBE Protocol Injection via Leaf Node/Route Forwarding allows arbitrary NATS command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58213"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-59818",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "etcd-io",
      "product": "etcd",
      "cwe": "CWE-295",
      "title": "etcd: gRPC client listener does not enforce `--client-crl-file` certificate revocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59818"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-14482",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shen2",
      "product": "多说社会化评论框",
      "cwe": "CWE-269",
      "title": "多说社会化评论框 <= 1.2 - Unauthenticated Privilege Escalation via api.php 'option'/'value' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14482"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-14891",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Nomad",
      "cwe": "CWE-59",
      "title": "Nomad vulnerable to sandbox escape in Docker task driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14891"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-56086",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.2424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect Data Domain",
      "cwe": "CWE-863",
      "title": "Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56086"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-59257",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.24268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-89",
      "title": "n8n - SQL Injection in MySQL v1 executeQuery Operation via Expression Interpolation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59257"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-54591",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.2411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ronf",
      "product": "asyncssh",
      "cwe": "CWE-22",
      "title": "AsyncSSH: SCP Path Traversal to Arbitrary File Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54591"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-59820",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BerriAI",
      "product": "litellm",
      "cwe": "CWE-22",
      "title": "LiteLLM: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59820"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-44161",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00306,
      "epss_percentile": 0.23307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fluent",
      "product": "fluentd",
      "cwe": "CWE-918",
      "title": "Fluentd: Server-Side Request Forgery (SSRF) via Placeholder Expansion in `out_http`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44161"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-15133",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in InterestGroups in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15133"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-59822",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BerriAI",
      "product": "litellm",
      "cwe": "CWE-287",
      "title": "LiteLLM: MCP Authentication Bypass via OAuth2 Passthrough Fallback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59822"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-59938",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00303,
      "epss_percentile": 0.23003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "py-pdf",
      "product": "pypdf",
      "cwe": "CWE-789",
      "title": "pypdf: Possible large memory usage for wrong image dimensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59938"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-15154",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.22886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 2.25",
      "cwe": "CWE-1333",
      "title": "Guardrails-detectors: guardrails-detectors: unauthenticated regular-expression denial of service (redos) via detector_params.regex",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15154"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-60002",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.003,
      "epss_percentile": 0.22618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-416",
      "title": "ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60002"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-15041",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.003,
      "epss_percentile": 0.22641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11",
      "cwe": "CWE-208",
      "title": "389-ds-base: 389-ds-base: non-constant-time comparison in pbkdf2-sha256 password verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15041"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-15107",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15107"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-15116",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15116"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-15118",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15118"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-15121",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15121"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-15126",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15126"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-59875",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "isaacs",
      "product": "node-tar",
      "cwe": "CWE-248",
      "title": "node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59875"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-55761",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.2165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "portainer",
      "product": "portainer",
      "cwe": "CWE-287",
      "title": "Portainer: Unauthenticated Restore Endpoint Allows Admin Takeover on Uninitialised Portainer Instances",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55761"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-60001",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-770",
      "title": "sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60001"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-14966",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00291,
      "epss_percentile": 0.2171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Black Lantern Security",
      "product": "BBOT",
      "cwe": "CWE-59",
      "title": "Symlink guard bypass in unarchive module allows planting symlinks during extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14966"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-59807",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ComposioHQ",
      "product": "composio",
      "cwe": "CWE-73",
      "title": "Composio SDK < 0.2.32-beta.283 - Sensitive File Upload via tool-file-uploads.ts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59807"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-15125",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-863",
      "title": "Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15125"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-55429",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coder",
      "product": "coder",
      "cwe": "CWE-639",
      "title": "Coder's workspace app upsert allows cross-workspace agent rebinding via user-controlled app ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55429"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-54590",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.21136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ronf",
      "product": "asyncssh",
      "cwe": "CWE-22",
      "title": "AsyncSSH AuthorizedKeysFile username substitution bypass through ~ and environment expansion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54590"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-15062",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00285,
      "epss_percentile": 0.21059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Snowflake",
      "product": "Snowpark Python SDK",
      "cwe": "CWE-89",
      "title": "SQL Injection in Snowflake Snowpark Python SDK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15062"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-41042",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00285,
      "epss_percentile": 0.21093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Gravitino",
      "cwe": "CWE-20",
      "title": "Apache Gravitino: Unauthenticated callers can supply a malicious H2 JDBC URL through the testConnection API, which executes arbitrary Java code on the server via H2's INIT parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41042"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-8472",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.2112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-862",
      "title": "Missing Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8472"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-9701",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00282,
      "epss_percentile": 0.20792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joe007",
      "product": "Eventer",
      "cwe": "CWE-289",
      "title": "Eventer <= 4.4.2 - Insecure Password Reset Mechanism to Unauthenticated Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9701"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-9074",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00281,
      "epss_percentile": 0.20696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "API Connect",
      "cwe": "CWE-89",
      "title": "IBM API Connect SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9074"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-11903",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress",
      "product": "MOVEit Transfer",
      "cwe": "CWE-79",
      "title": "Stored XSS in MOVEit Transfer Ad Hoc module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11903"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-51535",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "In OpENer 2.3.0 (commit 76b95cf), a resource exhaustion (Denial of Service) vulnerability exists in its network processing loop.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51535"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-35552",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-862",
      "title": "In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. Due to missing authorization checks, this allows the attacker to deactivate the application's license.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35552"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-47646",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.19839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Dynamics 365 Customer Voice",
      "cwe": "CWE-79",
      "title": "Dynamics 365 Customer Voice Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47646"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-6230",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tainacan",
      "product": "Tainacan",
      "cwe": "CWE-89",
      "title": "Tainacan <= 1.0.3 - Unauthenticated SQL Injection via 'geoquery' REST API Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6230"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-9700",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joe007",
      "product": "Eventer",
      "cwe": "CWE-89",
      "title": "Eventer <= 4.4.2 - Unauthenticated SQL Injection via 'code' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9700"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-15109",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15109"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-58656",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.1959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-598",
      "title": "Grav API Plugin - Cross-Origin Admin Account Takeover via CORS Wildcard and JWT Query Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58656"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-55999",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "X.Org",
      "product": "xorg-server",
      "cwe": "CWE-122",
      "title": "xorg-server / xwayland glamor font atlas Heap Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55999"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-55668",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-22",
      "title": "File Browser: ScopedFs follows a dangling symlink on write, letting a scoped user create files outside their scope",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55668"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-15135",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Online Food Order System",
      "cwe": "CWE-74",
      "title": "code-projects Online Food Order System edit_food_items.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15135"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-54779",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CoreWCF",
      "product": "CoreWCF",
      "cwe": "CWE-294",
      "title": "CoreWCF: SAML token replay protection is inoperative",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54779"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-59731",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "withastro",
      "product": "astro",
      "cwe": "CWE-647",
      "title": "Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59731"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-58501",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00267,
      "epss_percentile": 0.18968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mvantellingen",
      "product": "python-zeep",
      "cwe": "CWE-918",
      "title": "Zeep SSRF because Settings.forbid_external is not enforced",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58501"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-8307",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00266,
      "epss_percentile": 0.18599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webbeyaz Web Design",
      "product": "Mediküm Web",
      "cwe": "CWE-89",
      "title": "SQLi in Webbeyaz's Mediküm Web",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8307"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-12936",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "devitemsllc",
      "product": "Recurio – Ultimate Subscription for WooCommerce",
      "cwe": "CWE-89",
      "title": "Recurio <= 1.1.3 - Authenticated (Shop Manager+) SQL Injection via 'data' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12936"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-15105",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00265,
      "epss_percentile": 0.18548,
      "kev": false,
      "kev_due_at": null,
      "vendor": "davenardella",
      "product": "snap7",
      "cwe": "CWE-119",
      "title": "davenardella snap7 ReadVar Request s7_server.cpp PerformFunctionRead out-of-bounds write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15105"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-6352",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00264,
      "epss_percentile": 0.18435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6352"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-15134",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Simple Online Leave Management System",
      "cwe": "CWE-74",
      "title": "CodeAstro Simple Online Leave Management System index.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15134"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-53480",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.18237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect Data Domain",
      "cwe": "CWE-22",
      "title": "Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an improper limitation of a pathname to a restricted directory ('path traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized file modification.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53480"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-58654",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grav",
      "product": "Grav",
      "cwe": "CWE-434",
      "title": "Grav - Arbitrary File Upload via Avatar Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58654"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2025-3110",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "Access Server",
      "cwe": "CWE-444",
      "title": "OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-3110"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-8649",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00258,
      "epss_percentile": 0.17722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress",
      "product": "MOVEit Transfer",
      "cwe": "CWE-943",
      "title": "Institution scope bypass vulnerability in custom reports",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8649"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-56250",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-862",
      "title": "Capgo - Arbitrary R2 Object Deletion via Mutable r2_path in app_versions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56250"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-59819",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00258,
      "epss_percentile": 0.17689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BerriAI",
      "product": "litellm",
      "cwe": "CWE-73",
      "title": "LiteLLM: Local file read via request-supplied OIDC file references",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59819"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-35210",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenCTI-Platform",
      "product": "opencti",
      "cwe": "CWE-639",
      "title": "OpenCTI: Authorization Bypass via `synchronized-upsert` HTTP Header Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35210"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-9842",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pixelgrade",
      "product": "Backstage – Customizer Demo Access",
      "cwe": "CWE-269",
      "title": "Backstage <= 1.4.2 - Unauthenticated Privilege Escalation via Permissive Demo Role Capabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9842"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-11827",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-522",
      "title": "Insufficiently Protected Credentials in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11827"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-58214",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nats-io",
      "product": "nats-server",
      "cwe": "CWE-863",
      "title": "NATS Server: MQTT subscribe ACL bypass via $MQTT.deliver.pubrel prefix (incomplete fix for CVE-2026-33217)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58214"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-15113",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00255,
      "epss_percentile": 0.17293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15113"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-15123",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15123"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-56226",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.1723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo",
      "cwe": "CWE-200",
      "title": "Capgo - Unauthenticated Organization Data Disclosure via get_orgs_v6 RPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56226"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-12097",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "saadiqbal",
      "product": "User Management",
      "cwe": "CWE-862",
      "title": "User Management <= 1.2 - Missing Authorization to Unauthenticated Plugin Settings Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12097"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-7492",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-862",
      "title": "Missing Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7492"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-58191",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "appium",
      "product": "appium",
      "cwe": "CWE-79",
      "title": "Appium: Reflected XSS / arbitrary JS in @appium/base-driver /test/guinea-pig* routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58191"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-14362",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Shared library",
      "cwe": "CWE-770",
      "title": "Denial of service via crafted push/pull gossip message in memberlist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14362"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-58209",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.1676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nats-io",
      "product": "nats-server",
      "cwe": "CWE-863",
      "title": "NATS Server: MQTT retained and QoS replay bypass subscribe deny filters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58209"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-59995",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-23",
      "title": "sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when \"sftp server:/path .\" is used with an attacker-controlled server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59995"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-59996",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-23",
      "title": "scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59996"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-14373",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Nomad",
      "cwe": "CWE-862",
      "title": "Nomad Docker driver Linux host namespace bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14373"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-59806",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gradio-app",
      "product": "gradio",
      "cwe": "CWE-601",
      "title": "Gradio < 6.20.0 - Open Redirect and SSRF via /gradio_api/file= endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59806"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-54782",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00246,
      "epss_percentile": 0.16216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CoreWCF",
      "product": "CoreWCF",
      "cwe": "CWE-290",
      "title": "CoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54782"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-15122",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15122"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-55596",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15573,
      "kev": false,
      "kev_due_at": null,
      "vendor": "udecode",
      "product": "plate",
      "cwe": "CWE-79",
      "title": "Plate: Media embed provider metadata can bypass URL sanitization and execute iframe JavaScript",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55596"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-59923",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.1518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lepture",
      "product": "mistune",
      "cwe": "CWE-79",
      "title": "Mistune: XSS via percent-encoded javascript URI bypass in safe_url()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59923"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-59262",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "affine",
      "product": "monorepo",
      "cwe": "CWE-862",
      "title": "AFFiNE - Unauthorized Document Edit History Access via GraphQL histories Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59262"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-54773",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CoreWCF",
      "product": "CoreWCF",
      "cwe": "CWE-347",
      "title": "CoreWCF: WS-Security signature substitution via document-wide Signature lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54773"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-15036",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00238,
      "epss_percentile": 0.1514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Harness",
      "cwe": "CWE-285",
      "title": "Harness gitspaces Endpoint list_all.go getAuthorizedSpaces authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15036"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-36028",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-288",
      "title": "A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass kiosk restrictions via a factory reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36028"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-6818",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e4jvikwp",
      "product": "VikBooking Hotel Booking Engine & PMS",
      "cwe": "CWE-79",
      "title": "VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross-Site Scripting via 'special_requests' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6818"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-15114",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15114"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-3144",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.14564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "API Connect",
      "cwe": "CWE-1392",
      "title": "IBM API Connect Default Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3144"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-5922",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc.",
      "product": "Poly CCX",
      "cwe": "CWE-79",
      "title": "Poly Voice – Potential Unauthorized Modification of WebUI using XSS Attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5922"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-39822",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Go standard library",
      "product": "os",
      "cwe": "CWE-61",
      "title": "Root escape via symlink plus trailing slash in os",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39822"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-15120",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15120"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-54652",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "blakeblackshear",
      "product": "frigate",
      "cwe": "CWE-269",
      "title": "Frigate viewer can read logs exposing admin and camera credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54652"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-15111",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15111"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-15117",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Payments in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15117"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-6820",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.1391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e4jvikwp",
      "product": "VikBooking Hotel Booking Engine & PMS",
      "cwe": "CWE-79",
      "title": "VikBooking Hotel Booking Engine & PMS <= 1.8.8 - Unauthenticated Stored Cross-Site Scripting via Booking Form Email Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6820"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-6280",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NOMYSOFT Informatics Education and Consulting Inc.",
      "product": "Nomysem",
      "cwe": "CWE-213",
      "title": "Improper Access Control in Nomysoft Informatics' Nomysem",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6280"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-48492",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.1369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-862",
      "title": "Snipe-IT's selectlist visibility is too permissive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48492"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-58253",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nats-io",
      "product": "nats-server",
      "cwe": "CWE-287",
      "title": "NATS Server: Route API Auth Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58253"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-55830",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zopefoundation",
      "product": "RestrictedPython",
      "cwe": "CWE-184",
      "title": "RestrictedPython guard hooks can be shadowed via positional-only arguments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55830"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-60104",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00225,
      "epss_percentile": 0.13456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bitwarden",
      "product": "server",
      "cwe": "CWE-639",
      "title": "Bitwarden Server < 2026.6.0 Authorization Bypass via Admin Auth Request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60104"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-15169",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15169"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-59929",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lepture",
      "product": "mistune",
      "cwe": "CWE-79",
      "title": "Mistune renderers/html.safe_url: HARMFUL_PROTOCOLS list misses legacy and chained schemes that historically chain to `javascript:` execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59929"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-55433",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coder",
      "product": "coder",
      "cwe": "CWE-862",
      "title": "Coder: Devcontainer recreate endpoint missing write authorization allows read-only roles to destroy containers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55433"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-56246",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00223,
      "epss_percentile": 0.13143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-285",
      "title": "Capgo - Cross-Organization Authorization Bypass via Scoped API Key Privilege Inheritance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56246"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-56000",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00222,
      "epss_percentile": 0.13028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "X.Org",
      "product": "xorg-x11-server",
      "cwe": "CWE-416",
      "title": "xorg-x11-server / xwayland GLX contextTags Use-After-Free in CommonMakeCurrent()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56000"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-41122",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.12994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect Data Domain",
      "cwe": "CWE-79",
      "title": "Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain a stored cross-site scripting vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability. Exploitation may lead to information disclosure, session theft, or client-side request forgery.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41122"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-15034",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00222,
      "epss_percentile": 0.13046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flask-dashboard",
      "product": "Flask-MonitoringDashboard",
      "cwe": "CWE-352",
      "title": "flask-dashboard Flask-MonitoringDashboard cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15034"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-59805",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.12862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "antiwork",
      "product": "gumroad",
      "cwe": "CWE-862",
      "title": "Gumroad < 2026.07.06.2 - Insecure Direct Object Reference in PurchasesController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59805"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-60124",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-862",
      "title": "MISP importModule missing authorization allows read-only users to modify events via misp_standard imports",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60124"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-59876",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.1272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "protobufjs",
      "product": "protobuf.js",
      "cwe": "CWE-1321",
      "title": "protobufjs: Text Format string map parsing can mutate returned map object prototype",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59876"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-57259",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-611",
      "title": "Foxit PDF Editor/Reader XDP XFA XXE arbitrary local file read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57259"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-58657",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grav",
      "product": "Grav",
      "cwe": "CWE-79",
      "title": "Grav - Stored CSS Injection via Markdown Image resize() Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58657"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-15130",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15130"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-15131",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.1241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15131"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-3688",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00216,
      "epss_percentile": 0.12358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wclovers",
      "product": "WCFM Membership – WooCommerce Memberships for Multivendor Marketplace",
      "cwe": "CWE-639",
      "title": "WCFM - WooCommerce Multivendor Membership <= 2.11.10 - Insecure Direct Object Reference to Limited Privilege Escalation via User Role Overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3688"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-8651",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress",
      "product": "MOVEit Transfer",
      "cwe": "CWE-290",
      "title": "IPv6 Loopback Spoof via Trusted Host Header Bypasses Origin Check in MOVEit Transfer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8651"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-56217",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-284",
      "title": "Capgo - Encrypted Bundle Policy Bypass via Direct PostgREST Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56217"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-56284",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo",
      "cwe": "CWE-200",
      "title": "Capgo - Unauthenticated Metrics Disclosure via get_total_metrics RPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56284"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-59804",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.11921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "web-infra-dev",
      "product": "midscene",
      "cwe": "CWE-306",
      "title": "Midscene Bridge Server - Session Hijack via Unauthenticated WebSocket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59804"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-15124",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15124"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-8800",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress",
      "product": "MOVEit Transfer",
      "cwe": "CWE-863",
      "title": "Cross-Org External Token Metadata accessible to AuditUser role",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8800"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-55195",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.1149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miurahr",
      "product": "py7zr",
      "cwe": "CWE-409",
      "title": "py7zr: Decompression bomb (zip bomb) denial of service via unchecked extraction size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55195"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-55206",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.1149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miurahr",
      "product": "py7zr",
      "cwe": "CWE-407",
      "title": "py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55206"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-5356",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "latepoint",
      "product": "LatePoint – Calendar Booking Plugin for Appointments and Events",
      "cwe": "CWE-862",
      "title": "LatePoint - Calendar Booking Plugin for Appointments and Events <= 5.4.0 - Unauthenticated Stripe PaymentIntent Amount-Binding Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5356"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-14250",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themehunk",
      "product": "TH Login Registration",
      "cwe": "CWE-269",
      "title": "Themehunk Login Registration <= 1.0.2 - Unauthenticated Privilege Escalation via 'role' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14250"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-58211",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nats-io",
      "product": "nats-server",
      "cwe": "CWE-863",
      "title": "NATS Server: `no_auth_user` pre-CONNECT fast path bypasses user connection restrictions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58211"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-60125",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-863",
      "title": "importModule function in MISP ignores per-organisation import module restrictions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60125"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-11798",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "the_champ",
      "product": "Social Share, Social Login and Social Comments Plugin – Super Socializer",
      "cwe": "CWE-79",
      "title": "Social Share, Social Login and Social Comments Plugin <= 7.14.5 - Reflected Cross-Site Scripting via 'heateor_mastodon_share' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11798"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-56220",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-863",
      "title": "Capgo - Unauthorized Manifest Insertion via Read-Only Org Member",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56220"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-60092",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AVideo",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "AVideo - Stored Cross-Site Scripting via Unescaped User-Agent in Participants Panel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60092"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-55873",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seaweedfs",
      "product": "seaweedfs",
      "cwe": "CWE-863",
      "title": "SeaweedFS: Improper authorization in the S3Tables / Iceberg REST management API lets a low-privileged S3 user enumerate administrator-owned table buckets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55873"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-59895",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "hono",
      "cwe": "CWE-79",
      "title": "Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59895"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-14967",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00198,
      "epss_percentile": 0.10002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Black Lantern Security",
      "product": "BBOT",
      "cwe": "CWE-22",
      "title": "Path traversal in github_workflows allows writing artifacts outside output directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14967"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-10708",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00196,
      "epss_percentile": 0.09728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adalo No-Code App Builder",
      "product": "App Builder",
      "cwe": null,
      "title": "Insufficiently Protected Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10708"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-12041",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chatra",
      "product": "Chatra Live Chat + ChatBot + Cart Saver",
      "cwe": "CWE-79",
      "title": "Chatra Live Chat + ChatBot + Cart Saver <= 1.0.12 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'chatra-code' Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12041"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-59261",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00192,
      "epss_percentile": 0.09265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-522",
      "title": "OpenClaw < 2026.5.28 - Credential Override via Workspace Dotenv Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59261"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-59802",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PasswordPusher",
      "product": "PasswordPusher",
      "cwe": "CWE-183",
      "title": "PasswordPusher < 2.8.1 - Redirect-Based XSS via data URI in URL Push Payload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59802"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-59896",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "hono",
      "cwe": "CWE-362",
      "title": "hono/jsx does not isolate context per request, leading to cross-request data disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59896"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-55877",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "symfony",
      "product": "ux",
      "cwe": "CWE-79",
      "title": "Symfony UX: XSS in symfony/ux-icons via unsanitized SVG content in local files and Iconify on-demand responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55877"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-15119",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.0907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15119"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-53951",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "copier-org",
      "product": "copier",
      "cwe": "CWE-22",
      "title": "Copier: trust-prefix bypass via path traversal runs tasks unprompted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53951"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-59926",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lepture",
      "product": "mistune",
      "cwe": "CWE-79",
      "title": "Mistune: XSS via unescaped class option in Admonition directive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59926"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-56362",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00189,
      "epss_percentile": 0.08843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-125",
      "title": "ImageMagick - Heap-buffer-overflow Read in GetPixelIndex via OpenPixelCache Metadata Desynchronization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56362"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-56298",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-200",
      "title": "Capgo - EXIF Metadata Exposure in App Information Image Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56298"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2025-12506",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-706",
      "title": "Use of Incorrectly-Resolved Name or Reference in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-12506"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-59882",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guzzle",
      "product": "psr7",
      "cwe": "CWE-436",
      "title": "guzzlehttp/psr7: Host Confusion via Weak URI Host Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59882"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-56360",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-290",
      "title": "n8n - Webhook Forgery via Unsigned POST Requests in ZendeskTrigger",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56360"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-15163",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.08348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-835",
      "title": "Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15163"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-15063",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.0836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI (RHOAI)",
      "cwe": "CWE-306",
      "title": "Trustyai-service-operator: trustyai service operator: gorch port bypass when auth is enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15063"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-15110",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00183,
      "epss_percentile": 0.08186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15110"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-55431",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coder",
      "product": "coder",
      "cwe": "CWE-522",
      "title": "Coder's session token leaked to arbitrary hosts via `coder open app` for external workspace apps",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55431"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-44512",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "onnx",
      "product": "onnx",
      "cwe": "CWE-476",
      "title": "ONNX: Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44512"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-5459",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wedevs",
      "product": "User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration",
      "cwe": "CWE-639",
      "title": "User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.1 - Unauthenticated Insecure Direct Object Reference to Arbitrary User Subscription Overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5459"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-6459",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.0805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevteam",
      "product": "Essential Addons for Elementor – Popular Elementor Templates & Widgets",
      "cwe": "CWE-79",
      "title": "Essential Addons for Elementor <= 6.6.2 - Authenticated (Author+) Stored Cross-Site Scripting via Event Calendar Widget Popup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6459"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-10570",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.08047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "idocoh",
      "product": "Sympl Repeater for ACF and Elementor",
      "cwe": "CWE-79",
      "title": "Sympl Repeater for ACF and Elementor <= 2.3 - Authenticated (Author+) Stored Cross-Site Scripting via ACF Repeater Field Values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10570"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-55432",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.08044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coder",
      "product": "coder",
      "cwe": "CWE-862",
      "title": "Coder's sub-agent app registration bypasses template port-sharing policy enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55432"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-59998",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.0781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-573",
      "title": "sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59998"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-58254",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nats-io",
      "product": "nats-server",
      "cwe": "CWE-863",
      "title": "NATS Server: Incomplete fix for CVE-2026-33249: Leaf node connections bypass Nats-Trace-Dest permission check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58254"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-55437",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coder",
      "product": "coder",
      "cwe": "CWE-79",
      "title": "Coder vulnerable to stored HTML injection via workspace agent logs in AgentLogLine component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55437"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-54781",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00178,
      "epss_percentile": 0.07678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CoreWCF",
      "product": "CoreWCF",
      "cwe": "CWE-287",
      "title": "CoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforced",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54781"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-53624",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gofiber",
      "product": "fiber",
      "cwe": "CWE-319",
      "title": "Fiber: HSTS header never set in helmet middleware due to incorrect protocol check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53624"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-56775",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-863",
      "title": "n8n - Incorrect OAuth Scope Validation in Evaluation Test Runs Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56775"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-54784",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CoreWCF",
      "product": "CoreWCF",
      "cwe": "CWE-311",
      "title": "CoreWCF: SPNEGO SecurityContextToken proof key wrapped without confidentiality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54784"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-59997",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-1284",
      "title": "internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59997"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-56778",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-863",
      "title": "n8n - Authorization Bypass in Public API Execution Retry Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56778"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-15127",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15127"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-15128",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07035,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15128"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-55542",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00172,
      "epss_percentile": 0.06933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-862",
      "title": "Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55542"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-15167",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-121",
      "title": "Stack-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15167"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-54344",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ToolJet",
      "product": "ToolJet",
      "cwe": "CWE-78",
      "title": "ToolJet GitHub Actions comment body shell injection exposes deployment secrets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54344"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-22927",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Omnissa",
      "product": "Omnissa Workspace ONE® Tunnel for Windows",
      "cwe": "CWE-22",
      "title": "Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22927"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-57239",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-427",
      "title": "Foxit PDF Editor/Reader Local Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57239"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-57260",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-787",
      "title": "Security vulnerability in Foxit PDF Editor/Reader — U3D Adobe Mesh Decompression (Type Confusion / Invalid Pointer Dereference)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57260"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-15044",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI (RHOAI)",
      "cwe": "CWE-200",
      "title": "Trustyai-service-operator: trustyai service operator: unauthenticated access to ai guardrails and orchestrator apis",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15044"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-59253",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-639",
      "title": "n8n - Improper Authorization in Workflow Assignment to Folders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59253"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-13126",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13126"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-55849",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00161,
      "epss_percentile": 0.05791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CycloneDX",
      "product": "cyclonedx-node-npm",
      "cwe": "CWE-78",
      "title": "@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized `--workspace` Argument",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55849"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-56776",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-863",
      "title": "n8n - Incorrect OAuth Scope Validation in Workflow Test Run Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56776"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-55436",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coder",
      "product": "coder",
      "cwe": "CWE-295",
      "title": "Coder's AI Bridge Proxy skips TLS certificate verification in default configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55436"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-14896",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Nomad",
      "cwe": "CWE-863",
      "title": "Nomad vulnerable to cross-namespace host volume claim deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14896"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-59999",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenBSD",
      "product": "OpenSSH",
      "cwe": "CWE-348",
      "title": "In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59999"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-39178",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the search parameter of the allContactSearch endpoint.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39178"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-39179",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "A SQL injection vulnerability in SOGo before 5.12.7 allows authenticated users to execute arbitrary SQL statements via the newPassword parameter in the password change functionality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39179"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-15165",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15165"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-15166",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.0537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-121",
      "title": "Stack-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15166"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-15170",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15170"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-56374",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.0542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-125",
      "title": "ImageMagick - Heap Buffer Overflow in FTXT Encoder via format Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56374"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-54780",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00157,
      "epss_percentile": 0.05396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CoreWCF",
      "product": "CoreWCF",
      "cwe": "CWE-327",
      "title": "CoreWCF: WS-Security Reference DigestMethod Algorithm-Suite Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54780"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2025-14785",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "seedprod",
      "product": "Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode",
      "cwe": "CWE-79",
      "title": "Website Builder by SeedProd - Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode <= 6.20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'seedprodnestedmenuwidget' Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14785"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-6740",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "posimyththemes",
      "product": "Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder",
      "cwe": "CWE-79",
      "title": "Nexter Blocks <= 4.7.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'commentIcon' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6740"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-6742",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mdempfle",
      "product": "Advanced iFrame",
      "cwe": "CWE-79",
      "title": "Advanced iFrame <= 2026.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Gutenberg Block 'additional' Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6742"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-54774",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CoreWCF",
      "product": "CoreWCF",
      "cwe": "CWE-345",
      "title": "CoreWCF: SamlSerializer skips SignatureValue verification when SAML signing token is not an X.509 certificate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54774"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-55438",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.04691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coder",
      "product": "coder",
      "cwe": "CWE-346",
      "title": "Coder's workspace app CORS origin check can be bypassed via UUID-based subdomain spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55438"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-8310",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webbeyaz Web Design",
      "product": "Mediküm Web",
      "cwe": "CWE-79",
      "title": "Reflected XSS in Webbeyaz's Mediküm Web",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8310"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-57246",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-120",
      "title": "Foxit PDF Editor/Reader Signature Buffer Overflow Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57246"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-6371",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Limatek System Inc.",
      "product": "LimRAD NAC",
      "cwe": "CWE-79",
      "title": "Stored XSS in Limatek's LimRAD NAC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6371"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-15108",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted Chrome Extension. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15108"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-57248",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00147,
      "epss_percentile": 0.04489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-763",
      "title": "Foxit PDF Editor/Reader Annotation Improper Release Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57248"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-55878",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "symfony",
      "product": "ux",
      "cwe": "CWE-22",
      "title": "Symfony: Path Traversal in symfony/ux-toolkit Allows Arbitrary File Write and Read via Crafted Recipe Manifest",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55878"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-59723",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cline",
      "product": "cline",
      "cwe": "CWE-346",
      "title": "Cline: Cross-Origin WebSocket Hijacking in Cline Hub Dashboard (`/browser` endpoint)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59723"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-54783",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00143,
      "epss_percentile": 0.04084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CoreWCF",
      "product": "CoreWCF",
      "cwe": "CWE-294",
      "title": "CoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54783"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-56293",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-285",
      "title": "Capgo - Stale Cross-Organization Authorization via Incomplete deploy_history Update in transfer_app()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56293"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-59946",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.04005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "composer",
      "product": "composer",
      "cwe": "CWE-22",
      "title": "Composer: Path traversal in package bin field lets dependencies chmod arbitrary host files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59946"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-56359",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-79",
      "title": "n8n - Cross-Site Scripting in Credential Management OAuth2 Authorization URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56359"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-55430",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coder",
      "product": "coder",
      "cwe": "CWE-345",
      "title": "Coder's subdomain workspace app routing trusts unauthenticated X-Forwarded-Host header, enabling cross-app data access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55430"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-5923",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc.",
      "product": "Poly CCX",
      "cwe": "CWE-352",
      "title": "Poly Voice – Potential Unauthorized Modification of WebUI using CSRF Attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5923"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-59948",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00138,
      "epss_percentile": 0.03633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "composer",
      "product": "composer",
      "cwe": "CWE-22",
      "title": "Composer: Arbitrary file write outside vendor via malicious transitive package name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59948"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-56283",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-79",
      "title": "Capgo - HTML Injection Leading to Open Redirection in Organization Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56283"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-59930",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lepture",
      "product": "mistune",
      "cwe": "CWE-345",
      "title": "Mistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id=\"toc_N\"` content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59930"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-56437",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fuji Electric Co.,Ltd.",
      "product": "Pupsman",
      "cwe": "CWE-427",
      "title": "Uncontrolled search path element issue exists in Pupsman versions prior to 3.9.0. If a crafted DLL file is placed in the same folder as the affected installer and the installer is executed, arbitrary code may be executed with SYSTEM privilege.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56437"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-8315",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webbeyaz Web Design",
      "product": "Mediküm Web",
      "cwe": "CWE-79",
      "title": "Stored XSS in Webbeyaz's Mediküm Web",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8315"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-57240",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader Form Field Use-After-Free Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57240"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-9731",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpkuf",
      "product": "Wp Js Detect",
      "cwe": "CWE-352",
      "title": "Wp Js Detect <= 1.0.9 - Cross-Site Request Forgery to Plugin Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9731"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-15168",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00128,
      "epss_percentile": 0.02917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-457",
      "title": "Use of Uninitialized Variable in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15168"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-57256",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit Editor/Reader List Box Format Use-After-Free Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57256"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-59897",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.0268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "honojs",
      "product": "hono",
      "cwe": "CWE-348",
      "title": "Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59897"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-15164",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "ciscodump",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in ciscodump",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15164"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-15171",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-476",
      "title": "NULL Pointer Dereference in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15171"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-15172",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-606",
      "title": "Unchecked Input for Loop Condition in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15172"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-10037",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "Ubuntu",
      "cwe": "CWE-20",
      "title": "Sandbox Escape in Ubuntu OpenJDK Packages via xdg-desktop-portal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10037"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-59947",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "composer",
      "product": "composer",
      "cwe": "CWE-532",
      "title": "Composer: URL-embedded HTTP-Basic username leaks to verbose logs (GitHub PAT exposure)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59947"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-58494",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.0212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bytecodealliance",
      "product": "wasmtime",
      "cwe": "CWE-281",
      "title": "Wasmtime: WASI hard links bypass wasmtime-wasi's FilePerms for destination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58494"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-57251",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.0201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-129",
      "title": "Foxit PDF Editor/Reader Cloud Appearance Buffer Overflow Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57251"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-59883",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.01989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guzzle",
      "product": "guzzle",
      "cwe": "CWE-346",
      "title": "Guzzle: Cookie Disclosure and Injection via IP-Address Domains",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59883"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-13127",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13127"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-13128",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader Doc Object Use-After-Free Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13128"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-13129",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13129"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-57237",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57237"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-57238",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57238"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-57242",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01855,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader Page Use-After-Free Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57242"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-57244",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader Form Control Use-After-Free Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57244"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-57245",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01855,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader Signature Hyperlink Use-After-Free Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57245"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-57247",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader Field Use-After-Free Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57247"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-57249",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01889,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader Annotation Use-After-Free Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57249"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-57250",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader Form Field Use-After-Free Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57250"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-57252",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-416",
      "title": "Foxit PDF Editor/Reader AcroForm Use-After-Free Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57252"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-57254",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01855,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-843",
      "title": "Foxit PDF Editor/Reader Annotation Type Confusion Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57254"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-57258",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-125",
      "title": "Foxit PDF Editor/Reader Crash via Malformed PRC 3D Stream",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57258"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-50812",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-476",
      "title": "A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50812"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-57895",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fuji Electric Co.,Ltd.",
      "product": "Pupsman",
      "cwe": "CWE-276",
      "title": "Incorrect default permissions issue exists in Pupsman versions prior to 3.9.0. An attacker can place a malicious executable in the installation folder, which results in arbitrary code execution with SYSTEM privilege",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57895"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-50813",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0011,
      "epss_percentile": 0.01465,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-126",
      "title": "An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50813"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-57255",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-125",
      "title": "Security vulnerability in Foxit PDF Editor/Reader — OOB Read via NaN-Bypass Clamp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57255"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-54776",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CoreWCF",
      "product": "CoreWCF",
      "cwe": "CWE-306",
      "title": "CoreWCF: Unix Domain Socket PosixIdentity transport accepts connections that skip the security upgrade",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54776"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-57241",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-125",
      "title": "Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57241"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-57243",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-125",
      "title": "Foxit PDF Editor/Reader Page Out-of-bounds Read Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57243"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-57253",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-125",
      "title": "Foxit PDF Editor/Reader PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57253"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-57257",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Foxit Software Inc.",
      "product": "Foxit PDF Editor",
      "cwe": "CWE-125",
      "title": "Security vulnerability in Foxit PDF Editor/Reader — PRC 3D BRep Renderer Heap OOB Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57257"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-14361",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Tooling",
      "cwe": "CWE-59",
      "title": "Consul-template is vulnerable to path redirection in writeToFile through symlink attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14361"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-12002",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "Smash Balloon Social Photo Feed – Easy Social Feeds Plugin",
      "cwe": "CWE-352",
      "title": "Smash Balloon Social Photo Feed – Easy Social Feeds Plugin <= 6.11.1 - Cross-Site Request Forgery to oEmbed Access Token Overwrite via 'sbi_access_token' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12002"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-54778",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CoreWCF",
      "product": "CoreWCF",
      "cwe": "CWE-362",
      "title": "CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54778"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-15115",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00098,
      "epss_percentile": 0.00883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.115 allowed a local attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15115"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-57439",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.00712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gchq",
      "product": "CyberChef",
      "cwe": "CWE-79",
      "title": "CyberChef: Prototype pollution in Series Chart operation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57439"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-15174",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00092,
      "epss_percentile": 0.00595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15174"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-15173",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00089,
      "epss_percentile": 0.00505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wireshark Foundation",
      "product": "Wireshark",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in Wireshark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15173"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-54777",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00088,
      "epss_percentile": 0.00459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CoreWCF",
      "product": "CoreWCF",
      "cwe": "CWE-367",
      "title": "CoreWCF NetNamedPipe transport accepts attach to a pre-existing named pipe instance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54777"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15105",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15105 (davenardella snap7). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15164",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15164 (Wireshark Foundation ciscodump). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15165",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15165 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15166",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15166 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15167",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15167 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15168",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15168 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15169",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15169 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15170",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15170 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15171",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15171 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15172",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15172 (Wireshark Foundation Wireshark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-24700",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-24700. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44332",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44332 (gofiber fiber). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44512",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44512 (onnx). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45045",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45045 (gofiber fiber). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-53624",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-53624 (gofiber fiber). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54499",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54499 (stanfordnlp stanza). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54527",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54527 (jupyterlab-git). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54528",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54528 (jupyterlab-git). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55470",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55470 (hapifhir org.hl7.fhir.core). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55471",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55471 (hapifhir org.hl7.fhir.core). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55761",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55761 (portainer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56297",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56297 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58191",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58191 (appium). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59868",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59868 (nodeca js-yaml). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59869",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59869 (nodeca js-yaml). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59870",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59870 (nodeca js-yaml). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59871",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59871 (isaacs node-tar). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59873",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59873 (isaacs node-tar). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59874",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59874 (isaacs node-tar). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59879",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59879 (immutable-js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59880",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59880 (immutable-js). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59890",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59890 (pypa setuptools). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59922",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59922 (lepture mistune). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59923",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59923 (lepture mistune). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59924",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59924 (lepture mistune). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59925",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59925 (lepture mistune). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59927",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59927 (lepture mistune). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59928",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59928 (lepture mistune). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59929",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59929 (lepture mistune). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59930",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59930 (lepture mistune). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59939",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59939 (httplib2). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
