{
  "day": "2026-07-09",
  "boundary": "UTC calendar day",
  "published_count": 276,
  "by_severity": {
    "CRITICAL": 33,
    "HIGH": 103,
    "MEDIUM": 115,
    "LOW": 24
  },
  "kev_count": 0,
  "exploit_reference_count": 16,
  "awaiting_enrichment_count": 1,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-58459",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.01796,
      "epss_percentile": 0.7667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ntpsec",
      "product": "gpsd",
      "cwe": "CWE-78",
      "title": "gpsd gpsprof Command Injection via gnuplot plot title subtype field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58459"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-0286",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01159,
      "epss_percentile": 0.64584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cloud NGFW",
      "cwe": "CWE-78",
      "title": "PAN-OS: Authenticated Command Injection in CLI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0286"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-58123",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00928,
      "epss_percentile": 0.57731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nesquena",
      "product": "hermes-webui",
      "cwe": "CWE-306",
      "title": "Hermes WebUI < 0.51.788 Unauthenticated RCE via Terminal API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58123"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-14261",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00847,
      "epss_percentile": 0.55239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xerte",
      "product": "Xerte Online Tools",
      "cwe": null,
      "title": "CVE-2026-14261",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14261"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-61343",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0084,
      "epss_percentile": 0.55031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LibreBooking",
      "product": "LibreBooking",
      "cwe": "CWE-23",
      "title": "LibreBooking path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61343"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-59827",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00792,
      "epss_percentile": 0.53489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "metabase",
      "product": "metabase",
      "cwe": "CWE-502",
      "title": "Metabase: Unsafe Deserialization of H2 Query Results",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59827"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-13080",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0069,
      "epss_percentile": 0.4998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getwpfunnels",
      "product": "WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell",
      "cwe": "CWE-98",
      "title": "WPFunnels <= 3.12.7 - Authenticated (Administrator+) Local File Inclusion via 'logKey' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13080"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-15193",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00683,
      "epss_percentile": 0.49709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AidanPark",
      "product": "openclaw-android",
      "cwe": "CWE-77",
      "title": "AidanPark openclaw-android Android WebView Bridge JsBridge.kt os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15193"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-14372",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00671,
      "epss_percentile": 0.49228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bitpressadmin",
      "product": "Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder",
      "cwe": "CWE-22",
      "title": "Bit Form <= 3.1.1 - Authenticated (Subscriber+) Arbitrary File Deletion via '_old' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14372"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-8848",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0064,
      "epss_percentile": 0.47911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danieliser",
      "product": "Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder",
      "cwe": "CWE-862",
      "title": "Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder <= 1.22.0 - Missing Authorization to Authenticated (Editor+) Arbitrary Plugin Installation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8848"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-54769",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00638,
      "epss_percentile": 0.47856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langroid",
      "product": "langroid",
      "cwe": "CWE-94",
      "title": "Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54769"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-15308",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00637,
      "epss_percentile": 0.47782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Software Foundation",
      "product": "CPython",
      "cwe": "CWE-400",
      "title": "Incremental HTMLParser feed() allows CPU-exhaustion DoS via repeated unterminated markup declarations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15308"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-15158",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00611,
      "epss_percentile": 0.46595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "creativethemeshq",
      "product": "Blocksy Companion",
      "cwe": "CWE-434",
      "title": "Blocksy Companion <= 2.1.46 - Unauthenticated Arbitrary File Upload via 'blc-review-images[]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15158"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-14245",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00586,
      "epss_percentile": 0.45461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cyberlord92",
      "product": "miniOrange OTP Login, Verification and SMS Notifications",
      "cwe": "CWE-862",
      "title": "miniOrange OTP Login, Verification and SMS Notifications <= 5.5.1 - Authentication Bypass to Administrator Account Takeover via 'username_b' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14245"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-59692",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00577,
      "epss_percentile": 0.45027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-121",
      "title": "Gstreamer: gstreamer: dtls certificate subject dn stack buffer overflow in openssl_verify_callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59692"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-15192",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00572,
      "epss_percentile": 0.44766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mettle",
      "product": "sendportal",
      "cwe": "CWE-287",
      "title": "mettle sendportal APIv1 Webhooks mailjet missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15192"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-50180",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00568,
      "epss_percentile": 0.44571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langroid",
      "product": "langroid",
      "cwe": "CWE-22",
      "title": "Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50180"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-12116",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00566,
      "epss_percentile": 0.4449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xerte",
      "product": "Xerte Online Tools",
      "cwe": null,
      "title": "CVE-2026-12116",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12116"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-54760",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00558,
      "epss_percentile": 0.44077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langroid",
      "product": "langroid",
      "cwe": "CWE-22",
      "title": "Langroid: SQLChatAgent dangerous-function blocklist can be bypassed with quoted or schema-qualified pg_read_file calls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54760"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-39246",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00556,
      "epss_percentile": 0.43965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-59",
      "title": "decompress before 4.2.2 allows arbitrary symlink creation during archive extraction. When processing symlink entries (type === 'symlink'), the x.linkname field from the archive is passed directly to fs.symlink() without validation (index.js line 121). The preventWritingThroughSymlink check on line 98 only applies to file entries, not symlink creation. An attacker can craft an archive with symlink entries pointing to sensitive files outside the extraction directory (e.g., /etc/passwd), enabling information disclosure when the application reads the extracted contents.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39246"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-54003",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00545,
      "epss_percentile": 0.43383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkirby",
      "product": "kirby",
      "cwe": "CWE-454",
      "title": "Kirby: External Initialization of the Panel on reverse proxy setups with the `Forwarded` header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54003"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-59826",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0054,
      "epss_percentile": 0.43102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "metabase",
      "product": "metabase",
      "cwe": "CWE-94",
      "title": "Metabase: Arbitrary Code Execution via Database Connection Detail Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59826"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-59734",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00524,
      "epss_percentile": 0.42232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "coolify",
      "cwe": "CWE-78",
      "title": "Coolify: OS Command Injection in Health Check Configuration Allows Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59734"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-59721",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00518,
      "epss_percentile": 0.4189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hoppscotch",
      "product": "hoppscotch",
      "cwe": "CWE-77",
      "title": "Hoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59721"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-13492",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0051,
      "epss_percentile": 0.41364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stiofansisland",
      "product": "UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP",
      "cwe": "CWE-22",
      "title": "UsersWP <= 1.2.65 - Authenticated (Subscriber+) Arbitrary File Deletion via File Upload Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13492"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-60109",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00502,
      "epss_percentile": 0.40877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zeek",
      "product": "zeek",
      "cwe": "CWE-476",
      "title": "Zeek < 8.0.9 Null Pointer Dereference DoS via Kerberos KRB_ERROR Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60109"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-53963",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00498,
      "epss_percentile": 0.40692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-79",
      "title": "Discourse: Stored-XSS in 2FA delete confirmation modal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53963"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-15204",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00488,
      "epss_percentile": 0.40074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "X5000R",
      "cwe": "CWE-22",
      "title": "TOTOLINK X5000R OpenVPN Export cstecgi.cgi exportOvpn path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15204"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-59726",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00478,
      "epss_percentile": 0.39449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ruvnet",
      "product": "ruflo",
      "cwe": "CWE-78",
      "title": "Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59726"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-45788",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00465,
      "epss_percentile": 0.38551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-200",
      "title": "Discourse: Secure uploads exposed by hotlinked image copying",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45788"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-60095",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00463,
      "epss_percentile": 0.38446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Vinchin",
      "product": "Backup & Recovery 9.0",
      "cwe": "CWE-121",
      "title": "Vinchin Backup & Recovery 9.0.0.86562 Stack Buffer Overflow via ModuleHandShake",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60095"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-15270",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00443,
      "epss_percentile": 0.37025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-link",
      "product": "DIR-823G",
      "cwe": "CWE-266",
      "title": "D-link DIR-823G Web boa.conf least privilege violation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15270"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-60108",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00436,
      "epss_percentile": 0.36524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zeek",
      "product": "zeek",
      "cwe": "CWE-770",
      "title": "Zeek < 8.0.9 Uncontrolled Memory Consumption DoS via FTP Analyzer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60108"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-51599",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00433,
      "epss_percentile": 0.36229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-20",
      "title": "An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated remote attacker to render an individual TCP connection temporarily unusable via sending an RTSP request with a Content-Length header but no corresponding message body. The affected RTSP parser enters a body-waiting state instead of rejecting the malformed request, causing all subsequent data on the connection to be silently consumed as body content until a server-side timeout closes the connection.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51599"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-38076",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-190",
      "title": "An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38076"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-13461",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00429,
      "epss_percentile": 0.35969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PayRange",
      "product": "PayRange",
      "cwe": null,
      "title": "PayRange version 7.0.7 contains a JavaScript injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13461"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-55605",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00429,
      "epss_percentile": 0.35977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "arikusi",
      "product": "deepseek-mcp-server",
      "cwe": "CWE-306",
      "title": "@arikusi/deepseek-mcp-server Missing Authentication on Self-Hosted HTTP MCP Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55605"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-12597",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00422,
      "epss_percentile": 0.35409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LoginPress",
      "product": "LoginPress Pro",
      "cwe": "CWE-287",
      "title": "LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via GitHub OAuth Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12597"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-51603",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34412,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted second SETUP request. After completing the OPTIONS, DESCRIBE, and a legitimate first SETUP request to obtain a valid session ID, the RTSP service's second-stage URL routing parser fails to validate the length of the URL field in the subsequent SETUP request. By supplying a URL consisting of exactly four consecutive repetitions of a valid RTSP URL, an attacker can bypass first-stage format validation and trigger a stack buffer overflow, causing an immediate crash of the RTSP service process and rendering the device inaccessible to all clients on the local network.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51603"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-60094",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00411,
      "epss_percentile": 0.34421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Vinchin",
      "product": "Backup & Recovery 9.0",
      "cwe": "CWE-787",
      "title": "Vinchin Backup & Recovery 9.0.0.86562 Heap Buffer Overflow via agentlink_server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60094"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-51601",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. The device fails to validate the length of the clock= value in the Range header field when processing a PLAY request. An unauthenticated remote attacker who has completed a standard RTSP session handshake can send a PLAY request with an excessively long clock= value to cause the RTSP service to crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51601"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-51604",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.3432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted PLAY request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51604"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-51605",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unauthenticated remote attacker to cause a denial of service via a crafted TEARDOWN request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51605"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-54002",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00409,
      "epss_percentile": 0.34285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkirby",
      "product": "kirby",
      "cwe": "CWE-79",
      "title": "Kirby: Cross-site scripting (XSS) from incomplete HTML/XML sanitization in `Dom::sanitize()`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54002"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-13450",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00408,
      "epss_percentile": 0.34196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rubengc",
      "product": "GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress",
      "cwe": "CWE-639",
      "title": "GamiPress <= 7.9.4 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'access' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13450"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-15271",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00407,
      "epss_percentile": 0.34094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOTOLINK",
      "product": "A3000RU",
      "cwe": "CWE-266",
      "title": "TOTOLINK EX200 Web boa.conf least privilege violation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15271"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-51600",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00404,
      "epss_percentile": 0.33794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY methods). When a request carrying a Content-Length header is received without a corresponding message body, the RTSP parser enters a persistent body-awaiting state, causing the affected TCP connection to become permanently non-functional. The device does not actively close the connection, resulting in a TCP resource leak. This issue can be exploited by an unauthenticated remote attacker to cause a denial-of-service condition.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51600"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-51602",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00402,
      "epss_percentile": 0.33613,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of service via a crafted SETUP request. The RTSP service's second-stage URL routing parser fails to validate the length of the URL field in the first SETUP request. By supplying a URL consisting of exactly four consecutive repetitions of a valid RTSP URL, an attacker can bypass first-stage format validation and trigger a stack buffer overflow, causing an immediate crash of the RTSP service process and rendering the device inaccessible to all clients on the local network.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51602"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-59833",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00388,
      "epss_percentile": 0.32142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan: Stored XSS to RCE in SiYuan via a per-attribute URL-scheme sanitizer gap in Lute (form action / SVG xlink:href)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59833"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-55615",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.31627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langroid",
      "product": "langroid",
      "cwe": "CWE-74",
      "title": "Langroid: Neo4jChatAgent executes LLM-generated Cypher without validation (prompt-to-Cypher injection; config-conditional RCE), mirroring the SQLChatAgent bug fixed in CVE-2026-25879",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55615"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-51923",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.31462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-639",
      "title": "An Insecure Direct Object Reference (IDOR) vulnerability exists in docuForm GmbH Client v.11.11c allowing a remote attacker to execute arbitrary code via the user settings component, and modify or retrieve sensitive data associated with other users’ accounts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51923"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-59834",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-89",
      "title": "SiYuan: SQL Query in Block Search Exposes Hidden Published Document Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59834"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-59206",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-1321",
      "title": "n8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59206"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2025-45422",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.30754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in Proximus b-box v8c.725A allows authenticated attackers to bypass normal restrictions and make arbitrary changes to port forwarding rules.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-45422"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-49256",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00373,
      "epss_percentile": 0.30542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-200",
      "title": "Discourse: Hidden tag names leaked via category serializers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49256"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-51597",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.30474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-294",
      "title": "MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. An adjacent network attacker can capture a legitimate authentication exchange and replay the nonce and response values in a new connection to bypass authentication without knowledge of the device credentials, gaining unauthorized access to the live video stream.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51597"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-59220",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00372,
      "epss_percentile": 0.30528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-1333",
      "title": "Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59220"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-54695",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00369,
      "epss_percentile": 0.30125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pipecat-ai",
      "product": "pipecat",
      "cwe": "CWE-862",
      "title": "Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54695"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-46413",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00366,
      "epss_percentile": 0.29866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-862",
      "title": "Discourse: Regular users can route multipart uploads into the admin backup store",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46413"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-45780",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00364,
      "epss_percentile": 0.29676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-200",
      "title": "Discourse: Private event sample invitees are serialized to non-invited event viewers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45780"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-59221",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-22",
      "title": "open-webui terminal proxy path traversal guard bypass via 9x encoded traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59221"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-51926",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.29198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-203",
      "title": "An issue in docuForm GmbH FSM Client v.11.11c allows a remote attacker to obtain sensitive information via the login.php component. A vulnerability was identified in the authentication mechanism that allows user enumeration through the login interface. An attacker can differentiate between valid and invalid usernames based on variations in server responses. This information can be leveraged to identify existing accounts and facilitate further attacks, including brute-force or credential stuffing.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51926"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-55207",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.28208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pimcore",
      "product": "pimcore",
      "cwe": "CWE-640",
      "title": "Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55207"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-55420",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-78",
      "title": "Discourse: Remote code execution via pdf uploads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55420"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-11404",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cesanta",
      "product": "Mongoose",
      "cwe": "CWE-125",
      "title": "Cesanta Mongoose Out-of-Bounds Read in MG_TLS_BUILTIN ClientHello Session ID Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11404"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-12595",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LoginPress",
      "product": "LoginPress Pro",
      "cwe": "CWE-287",
      "title": "LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email via Discord OAuth Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12595"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-12598",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LoginPress",
      "product": "LoginPress Pro",
      "cwe": "CWE-287",
      "title": "LoginPress Pro <= 6.2.3 - Unauthenticated Authentication Bypass via Unverified OAuth Email in Spotify OAuth Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12598"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-15138",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00347,
      "epss_percentile": 0.27829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tumf",
      "product": "mcp-text-editor",
      "cwe": "CWE-22",
      "title": "tumf mcp-text-editor text_editor.py _validate_file_path path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15138"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-47826",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CloudFoundry Foundation",
      "product": "BOSH CLI tool",
      "cwe": "CWE-22",
      "title": "blobs.yaml Path Traversal Allows File Writes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47826"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-53987",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tag plugin",
      "product": "GLPI 11",
      "cwe": "CWE-79",
      "title": "GLPI 11 before 2.14.4 Tag Plugin Stored Cross-Site Scripting in Kanban Badge Rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53987"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-54801",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "CPCI85 Central Processing/Communication",
      "cwe": "CWE-620",
      "title": "A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains insufficient validation of authentication credentials when processing administrative account modifications through the web API. This could allow an authenticated attacker to bypass security controls and gain unauthorized elevated privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54801"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-15000",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rnzo",
      "product": "Connect Contact Form 7 and Mailchimp",
      "cwe": "CWE-79",
      "title": "Connect Contact Form 7 and Mailchimp <= 0.9.78.06 - Unauthenticated Stored Cross-Site Scripting via Mailchimp Merge Field Values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15000"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-39245",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0034,
      "epss_percentile": 0.2712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "decompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file write. The safeMakeDir function (index.js line 29) and the extraction path validation (index.js line 106) use String.indexOf() to verify the resolved path is within the output directory: realDestinationDir.indexOf(realOutputPath) !== 0. This check is flawed because it does not enforce a path separator boundary. For example, \"/tmp/app_config\".indexOf(\"/tmp/app\") returns 0, incorrectly passing the check even though /tmp/app_config is outside /tmp/app. Combined with the unvalidated symlink creation in the same package, an attacker can write arbitrary files to directories adjacent to the extraction target. This is a bypass of the fix for CVE-2020-12265. The correct check requires appending a path separator: realParentPath.indexOf(realOutputPath + path.sep) !== 0.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39245"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-59720",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00336,
      "epss_percentile": 0.26645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hoppscotch",
      "product": "hoppscotch",
      "cwe": "CWE-200",
      "title": "Hoppscotch: Insecure Default Configuration Allows Public Exposure of Private Collection Data via Mock Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59720"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-57021",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.26586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS",
      "cwe": "CWE-787",
      "title": "Junos OS: SRX Series: If VPN compliance-check is configured an attacker can cause http-gk process crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57021"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-0279",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00335,
      "epss_percentile": 0.2648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cloud NGFW",
      "cwe": "CWE-79",
      "title": "PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0279"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-57023",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00331,
      "epss_percentile": 0.26114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS",
      "cwe": "CWE-1284",
      "title": "Junos OS: MX with SPC3, SRX Series: A specifically malformed TCP packet causes a flowd crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57023"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-57026",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00331,
      "epss_percentile": 0.26114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS",
      "cwe": "CWE-1286",
      "title": "Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57026"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-51924",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.25971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-639",
      "title": "An issue in docuForm GmbH Client v.11.11c allows a remote attacker to execute arbitrary code via the file upload and report.php component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51924"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-59149",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0033,
      "epss_percentile": 0.2598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mockoon",
      "product": "mockoon",
      "cwe": "CWE-22",
      "title": "Mockoon: Path traversal in templated `filePath` lets a request escape the served directory (prefix-only base check)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59149"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-59212",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0033,
      "epss_percentile": 0.25978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-863",
      "title": "Open WebUI: Model meta.knowledge read-only file access can be upgraded to file write/delete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59212"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-15190",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SourceCodester",
      "product": "Simple and Nice Shopping Cart Script",
      "cwe": "CWE-74",
      "title": "SourceCodester Simple and Nice Shopping Cart Script login.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15190"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-39243",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-59",
      "title": "decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. When processing hardlink entries (type === 'link'), the x.linkname field from the archive is passed directly to fs.link() without validation (index.js line 113). An attacker can craft an archive with a hardlink entry whose linkname is an absolute path to any file on the same filesystem. This creates a hardlink inside the extraction directory that shares the same inode as the target file, enabling both reading and overwriting the original file's content. Hardlinks are limited to files on the same filesystem and cannot target directories.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39243"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-59691",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.25541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-787",
      "title": "Gstreamer: gstreamer: rfbsrc/librfb hextile heap out-of-bounds write with 16bpp framebuffer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59691"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-51606",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-20",
      "title": "An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the TCP connection with a RST packet when a request containing an oversized field value is received, without returning any RFC 2326-compliant error response. This behavior affects the request-line URL field and header field values across multiple RTSP request types.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51606"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-0287",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.25174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cloud NGFW",
      "cwe": "CWE-754",
      "title": "PAN-OS: Denial of Service Vulnerabilities in Network Traffic Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0287"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-12406",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.25239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wedevs",
      "product": "User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration",
      "cwe": "CWE-862",
      "title": "User Frontend <= 4.3.7 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'attach_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12406"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-51925",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-639",
      "title": "A Local File Inclusion (LFI) vulnerability exists in docuForm GmbH Client v.11.11c that allows a remote attacker to execute arbitrary code via the dfm-menu_report.php component. Attackers can exploit this flaw to read arbitrary files on the server, including sensitive configuration files, source code or system files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51925"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-59222",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.25104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-200",
      "title": "Open WebUI: /api/v1/channels/{id}/members exposes full user model including sensitive credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59222"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-59832",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-22",
      "title": "SiYuan: Authenticated path traversal in /snippets/ static handler (serveSnippets) leaks conf/conf.json secrets and siyuan.db",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59832"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-59208",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.24224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-346",
      "title": "n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59208"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-59828",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.24208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-200",
      "title": "Discourse: Hidden post revisions leak through adjacent visible diffs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59828"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-54004",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.24032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkirby",
      "product": "kirby",
      "cwe": "CWE-862",
      "title": "Kirby: Access to files of top-level drafts is not protected by permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54004"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-56292",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00311,
      "epss_percentile": 0.23916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "acymailing.com",
      "product": "acymailing.com AcyMailing extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - acymailing.com - SQL Injection in AcyMailing extension < 10.11.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56292"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-59216",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00308,
      "epss_percentile": 0.23568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-94",
      "title": "Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59216"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-59855",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-80",
      "title": "SiYuan: Store XSS To Rce via Asset.render",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59855"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-59219",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-613",
      "title": "Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59219"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-59226",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00303,
      "epss_percentile": 0.2306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-285",
      "title": "Open WebUI: Scheduled automations continue after pending-user deactivation and stored model ACL revocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59226"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-5523",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Divi Engine",
      "product": "Divi Form Builder",
      "cwe": "CWE-639",
      "title": "Divi Form Builder <= 5.1.8 - Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via User Profile Update Form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5523"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-55689",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openfga",
      "product": "openfga",
      "cwe": "CWE-287",
      "title": "OpenFGA: OIDC audience validation skipped when --authn-oidc-audience is unset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55689"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-55424",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00299,
      "epss_percentile": 0.2254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-79",
      "title": "Discourse: Topic featured link susceptible to stored XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55424"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-53962",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.2254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-79",
      "title": "Discourse: Insufficient SVG sanitization logic",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53962"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-9021",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00297,
      "epss_percentile": 0.22339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "matrixaddons",
      "product": "Easy Invoice – Invoice Generator, PDF Quotes & Payments",
      "cwe": "CWE-862",
      "title": "Easy Invoice <= 2.1.19 - Unauthenticated Arbitrary Quote Accept/Decline and Invoice Creation via easy_invoice_accept_quote / easy_invoice_decline_quote AJAX Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9021"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-59213",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00297,
      "epss_percentile": 0.22308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-524",
      "title": "Open WebUI: Cross-user model-list exposure via static cache key in get_all_models (aiocache key= vs key_builder= misuse)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59213"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-59209",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-200",
      "title": "n8n: Shared Credential Header Leak via HTTP Request Pagination Expression",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59209"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-58122",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00293,
      "epss_percentile": 0.21876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nesquena",
      "product": "hermes-webui",
      "cwe": "CWE-348",
      "title": "Hermes WebUI < 0.51.307 Authentication Bypass via X-Forwarded-For Header Spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58122"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-59217",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-862",
      "title": "Open WebUI: Upload `metadata.knowledge_id` bypasses the knowledge-base write-access check (read-only users can add files to KB)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59217"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-31984",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nozomi Networks",
      "product": "Guardian",
      "cwe": "CWE-770",
      "title": "DoS through oversized audit log entries in Guardian/CMC before 26.2.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31984"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-57022",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS",
      "cwe": "CWE-754",
      "title": "Junos OS: MX Series with SPC3, SRX Series: Specific packet in response to a TCP connection establishment by the affected device can crash the PFE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57022"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-50188",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.2162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkirby",
      "product": "kirby",
      "cwe": "CWE-93",
      "title": "Kirby: Request header injection in `Http\\Remote`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50188"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-57501",
      "cvss_base": 0,
      "cvss_severity": "NONE",
      "epss_score": 0.0029,
      "epss_percentile": 0.21542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zen-browser",
      "product": "desktop",
      "cwe": "CWE-266",
      "title": "Zen: Context-menu \"Open link in glance\" / \"Split link in new tab\" loads a page-controlled link with the System principal, bypassing the web-content scheme restriction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57501"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-49276",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkirby",
      "product": "kirby",
      "cwe": "CWE-83",
      "title": "Kirby: Self cross-site scripting (self-XSS) in the writer field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49276"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-43752",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Claris",
      "product": "FileMaker Server",
      "cwe": "CWE-434",
      "title": "An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43752"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-9028",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "corvusinfo",
      "product": "CorvusPay WooCommerce Payment Gateway",
      "cwe": "CWE-862",
      "title": "CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Missing Authorization to Unauthenticated Arbitrary Order Cancellation via 'order_number' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9028"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-59214",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00286,
      "epss_percentile": 0.21128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-79",
      "title": "Open WebUI: Stored web worker XSS via Pyodide",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59214"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-59224",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-287",
      "title": "Open WebUI: Terminal proxy forwards a spoofable, integrity-unbound user identity to the upstream (X-User-Id header and ws_terminal session_id query injection)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59224"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-13462",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PayRange",
      "product": "PayRange",
      "cwe": null,
      "title": "PayRange for Android, version 7.0.7, contains an SSL bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13462"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-12593",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qt",
      "product": "Axivion",
      "cwe": "CWE-862",
      "title": "Privilege escalation via forged API token creation in Axivion Dashboard OIDC/OAuth2/SSO subsystem",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12593"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-0284",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cloud NGFW",
      "cwe": "CWE-74",
      "title": "PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0284"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-54771",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langroid",
      "product": "langroid",
      "cwe": "CWE-75",
      "title": "Langroid: handle_message() executes user-supplied tool JSON without sender verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54771"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-59854",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-693",
      "title": "SiYuan: Incomplete IsSensitivePath denylist: globalCopyFiles reads home-dir credential dotfiles into the workspace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59854"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-50644",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.20193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SOPlanning",
      "product": "SOPlanning",
      "cwe": "CWE-89",
      "title": "SQL Injection in SOPlanning Audit Retention Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50644"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-12428",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gamaup",
      "product": "Blocks for ACF Fields — Display Custom Fields in the Block Editor",
      "cwe": "CWE-862",
      "title": "Blocks for ACF Fields <= 1.6.2 - Missing Authorization to Authenticated (Author+) Arbitrary ACF Field Value Disclosure via 'id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12428"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-55590",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.20117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cakephp",
      "product": "authentication",
      "cwe": "CWE-601",
      "title": "CakePHP: Open redirect weakness via backslash bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55590"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-5955",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00275,
      "epss_percentile": 0.19978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Inrove Software and Internet Services",
      "product": "BiEticaret",
      "cwe": "CWE-89",
      "title": "SQLi in Inrove Software's BiEticaret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5955"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-49274",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkirby",
      "product": "kirby",
      "cwe": "CWE-862",
      "title": "Kirby: `pages.access` permission is not checked in the pages picker for parent pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49274"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-57030",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS",
      "cwe": "CWE-362",
      "title": "Junos OS: SRX Series: Flow sessions are not getting cleared leading to a DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57030"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-61344",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.1965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Superior Court of California, County of Los Angeles",
      "product": "Hearing Reminder Service",
      "cwe": "CWE-306",
      "title": "Superior Court of California Hearing Reminder Service unauthenticated information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61344"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-12590",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "body-parser",
      "product": "body-parser",
      "cwe": "CWE-770",
      "title": "body-parser vulnerable to denial of service when invalid limit value silently disables size enforcement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12590"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-57111",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Helix REST",
      "cwe": "CWE-1385",
      "title": "Apache Helix REST: Permissive CORS Configuration in REST API Allows Unrestricted Cross-Origin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57111"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-54005",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkirby",
      "product": "kirby",
      "cwe": "CWE-862",
      "title": "Kirby: `pages.access` permission is not checked in the `site/find` REST API route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54005"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-1365",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sayax Energy Technologies Inc.",
      "product": "OSOS",
      "cwe": "CWE-201",
      "title": "Information Disclosure in Sayax's OSOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1365"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-44787",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-269",
      "title": "Discourse: Signup-time primary_group_id assignment grants whisperer access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44787"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-14342",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getwpfunnels",
      "product": "Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails",
      "cwe": "CWE-89",
      "title": "Mail Mint <= 1.24.2 - Authenticated (Administrator+) SQL Injection via 'contact_ids' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14342"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-33655",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.18575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuantumNous",
      "product": "new-api",
      "cwe": "CWE-918",
      "title": "New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33655"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-59207",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-693",
      "title": "n8n: \"Allowed HTTP Request Domains\" Restriction Bypass via AI Agents MCP Connector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59207"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-15137",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Interview Management System",
      "cwe": "CWE-74",
      "title": "code-projects Interview Management System View.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15137"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-15202",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.18341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "YzmCMS",
      "cwe": "CWE-79",
      "title": "YzmCMS Header yzmphp.php get_url cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15202"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-8996",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.18128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "revmakx",
      "product": "Backup and Staging by WP Time Capsule",
      "cwe": "CWE-862",
      "title": "Backup and Staging by WP Time Capsule <= 1.22.26 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via download_recent_decrypted_file_wptc Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8996"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-7558",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.18147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tokenoftrust",
      "product": "Age Verification & Identity Verification by Token of Trust",
      "cwe": "CWE-862",
      "title": "Age Verification & Identity Verification by Token of Trust <= 4.0.2 - Missing Authorization to Unauthenticated Information Exposure via 'tot_export_table' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7558"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-15195",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00262,
      "epss_percentile": 0.18123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apidevtools",
      "product": "json-schema-ref-parser",
      "cwe": "CWE-94",
      "title": "apidevtools json-schema-ref-parser pointer.ts Pointer.set prototype pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15195"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-13011",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wedevs",
      "product": "ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce",
      "cwe": "CWE-89",
      "title": "ERP: Complete HR, Accounting & CRM Suite with Recruitment and WooCommerce CRM Support <= 1.17.5 - Authenticated (HR Manager+) SQL Injection via 'orderby' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13011"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-12433",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.1808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themefic",
      "product": "Hydra Booking — Appointment Scheduling & Booking Calendar",
      "cwe": "CWE-639",
      "title": "Hydra Booking <= 1.2.1 - Authenticated (Custom+) Insecure Direct Object Reference to Sensitive Information Exposure via 'booking_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12433"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-55865",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jg-rp",
      "product": "liquid",
      "cwe": "CWE-835",
      "title": "Python Liquid: Infinite loop when parsing malformed `{% case %}` tags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55865"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-59227",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-862",
      "title": "Open WebUI: POST /api/v1/images/edit bypasses the global image-edit switch and the per-user image-generation permission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59227"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-59831",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cli",
      "product": "cli",
      "cwe": "CWE-829",
      "title": "GitHub CLI `gh codespace jupyter` could allow remote code execution when connecting to a malicious Codespace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59831"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-33803",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS Evolved",
      "cwe": "CWE-923",
      "title": "Junos OS Evolved: A port which has been inadvertently exposed can be reached by an attacker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33803"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-59817",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost",
      "cwe": "CWE-472",
      "title": "Ghost: Paid gift memberships obtainable at minimal cost via the donations feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59817"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-11571",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Everest Forms",
      "cwe": null,
      "title": "Everest Forms < 3.5.0 - Unauthenticated Sensitive Information Exposure via Residual CSV Artifacts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11571"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-59215",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00255,
      "epss_percentile": 0.17319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-639",
      "title": "Open WebUI: Private channel messages can be disclosed through cross-channel thread parent_id binding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59215"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-1989",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PAVO Financial Technology Solutions Inc.",
      "product": "PAVO Pay",
      "cwe": "CWE-639",
      "title": "IDOR in PAVO Inc.'s PAVO Pay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1989"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-55208",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pimcore",
      "product": "pimcore",
      "cwe": "CWE-89",
      "title": "Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55208"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-12170",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.1645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "acyba",
      "product": "AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress",
      "cwe": "CWE-79",
      "title": "AcyMailing <= 10.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'alignment' Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12170"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-15187",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00248,
      "epss_percentile": 0.16442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "enquirer",
      "cwe": "CWE-94",
      "title": "enquirer Public Package API Enquirer.set prototype pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15187"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-55170",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00248,
      "epss_percentile": 0.16452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openfga",
      "product": "openfga",
      "cwe": "CWE-178",
      "title": "OpenFGA MySQL backend: case-insensitive collation on identifier columns causes incorrect authorization decisions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55170"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-13441",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "metagauss",
      "product": "EventPrime – Events Calendar, Bookings and Tickets",
      "cwe": "CWE-79",
      "title": "EventPrime <= 4.3.4.2 - Unauthenticated Stored Cross-Site Scripting via 'new_event_type_background_color' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13441"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-57024",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS",
      "cwe": "CWE-694",
      "title": "Junos OS: MX with SPC3, SRX Series: Repeated VPN negotiation failures will eventually cause iked to crash continuously",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57024"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-11359",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "metagauss",
      "product": "Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration",
      "cwe": "CWE-862",
      "title": "Memberships and User Profiles for WooCommerce <= 3.4 - Missing Authorization to Authenticated (Subscriber+) ProfileGrid Plugin Installation and Activation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11359"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-31983",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nozomi Networks",
      "product": "Guardian",
      "cwe": "CWE-306",
      "title": "Missing authentication in SSH keys synchronization endpoint in Guardian/CMC before 26.2.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31983"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-61474",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-863",
      "title": "MISP: Improper sharing group authorization check when adding attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61474"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-12418",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wedevs",
      "product": "User Frontend: AI Powered Frontend Posting, User Directory, Profile Builder, Membership & User Registration",
      "cwe": "CWE-639",
      "title": "User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration <= 4.3.7 - Insecure Direct Object Reference to Unauthenticated Arbitrary Post Modification via 'wpuf_files_data' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12418"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-58378",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Allwinner",
      "product": "H616",
      "cwe": "CWE-489",
      "title": "Allwinner TV Box TV98 ADB exposed on network",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58378"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-54798",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "CPCI85 Central Processing/Communication",
      "cwe": "CWE-489",
      "title": "A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application includes a debugging interface that is accessible through HTTP endpoints. This could allow an authenticated attacker to disrupt the system by crashing the web process causing denial of service conditions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54798"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-57032",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS",
      "cwe": "CWE-236",
      "title": "Junos OS: EX Series: Subscribing to an unsupported telemetry sensor path causes fxpc process crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57032"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-59218",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-208",
      "title": "Open WebUI: Account enumeration via observable login timing discrepancy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59218"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-15186",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00237,
      "epss_percentile": 0.14954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "macrozheng",
      "product": "mall",
      "cwe": "CWE-99",
      "title": "macrozheng mall Portal Endpoint create resource injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15186"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-33794",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS Evolved",
      "cwe": "CWE-754",
      "title": "Junos OS Evolved: PTX Series: Receipt of repeated ECMP routing updates results in PFE crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33794"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-59853",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan: Publish-mode Reader can exfiltrate private saved-search Criteria via /api/storage/getCriteria (missing publish-access filter)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59853"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-50181",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langroid",
      "product": "langroid",
      "cwe": "CWE-22",
      "title": "Langroid: Path traversal in the file tools allows read/write outside configured current directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50181"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-13771",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ivole",
      "product": "Customer Reviews for WooCommerce",
      "cwe": "CWE-79",
      "title": "Customer Reviews for WooCommerce <= 5.113.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'color' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13771"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-57054",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS",
      "cwe": "CWE-706",
      "title": "Junos OS: MX Series: Web filtering doesn't block specifically formatted URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57054"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-53961",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "discourse",
      "product": "discourse",
      "cwe": "CWE-345",
      "title": "Discourse: Forged AWS SNS bounce notifications can disable a targeted user's email (missing TopicArn binding)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53961"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-33799",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS",
      "cwe": "CWE-787",
      "title": "Junos OS and Junos OS Evolved: Receipt of a specific SNMPv3 request results in memory leak and eventual snmpd crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33799"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-0285",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cloud NGFW",
      "cwe": "CWE-918",
      "title": "PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0285"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-9237",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crewhrm",
      "product": "Employee, Leave and Recruitment Management System – Crew HRM",
      "cwe": "CWE-862",
      "title": "Employee, Leave and Recruitment Management System <= 1.2.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Job Deletion via crewhrm_singleJobAction AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9237"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-55604",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "arikusi",
      "product": "deepseek-mcp-server",
      "cwe": "CWE-639",
      "title": "@arikusi/deepseek-mcp-server has an Authorization Bypass Through User-Controlled Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55604"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-47829",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.1338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CloudFoundry Foundation",
      "product": "bosh-cli",
      "cwe": "CWE-88",
      "title": "Argument Injection in BOSH CLI Allows Local Command Execution on Operator Workstations via Compromised Director",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47829"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-56460",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "HCL DevOps Deploy / HCL Launch",
      "cwe": "CWE-201",
      "title": "HCL DevOps Deploy / HCL Launch is susceptible to an Insertion of Sensitive Information Into Sent Data vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56460"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-33390",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00223,
      "epss_percentile": 0.13143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nozomi Networks",
      "product": "Guardian",
      "cwe": "CWE-266",
      "title": "Incorrect privilege assignment for Arc sensors in Guardian/CMC before 26.2.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33390"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-59223",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-693",
      "title": "Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59223"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-59715",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-306",
      "title": "Open WebUI: Unauthenticated WebSocket Access to Collaborative Document Handlers (ydoc:awareness:update, ydoc:document:leave)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59715"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-9027",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "corvusinfo",
      "product": "CorvusPay WooCommerce Payment Gateway",
      "cwe": "CWE-347",
      "title": "CorvusPay WooCommerce Payment Gateway <= 2.7.4 - Unauthenticated Improper Verification of Cryptographic Signature to Payment Bypass via /wp-json/corvuspay/success/ REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9027"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-2342",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0022,
      "epss_percentile": 0.12863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OceanicSoft Informatics Systems Ltd.",
      "product": "ValeApp",
      "cwe": "CWE-79",
      "title": "XSS in Oceanicsoft's ValeApp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2342"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-15191",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0022,
      "epss_percentile": 0.12777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mettle",
      "product": "sendportal",
      "cwe": "CWE-285",
      "title": "mettle sendportal Campaign Creation Endpoint CampaignStoreRequest.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15191"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-59856",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00216,
      "epss_percentile": 0.12314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-94",
      "title": "Vim: Arbitrary Code Execution via PHP Omni-Completion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59856"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-13334",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kitae-park",
      "product": "Mang Board WP",
      "cwe": "CWE-79",
      "title": "Mang Board WP <= 2.3.4 - Reflected Cross-Site Scripting via 'stag' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13334"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-4256",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.11906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PEAKUP Technology Inc.",
      "product": "PassGate",
      "cwe": "CWE-90",
      "title": "LDAP Injection in PEAKUP's PassGate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4256"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-0283",
      "cvss_base": 4.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.1178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cloud NGFW",
      "cwe": "CWE-306",
      "title": "PAN-OS: Authentication Bypass Vulnerability in Large Scale VPN (LSVPN)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0283"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-59225",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-862",
      "title": "Open WebUI: Arena task endpoints can bypass underlying model access controls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59225"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-15189",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aerostackdev",
      "product": "aerostack-mcp",
      "cwe": "CWE-918",
      "title": "aerostackdev aerostack-mcp mcp-whatsapp upload_media server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15189"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-15188",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "manjurulhoque",
      "product": "django-job-portal",
      "cwe": "CWE-266",
      "title": "manjurulhoque django-job-portal Employee Dashboard Endpoint views.py EditEmployeeProfileAPIView access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15188"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-6910",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.11029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "safistudio",
      "product": "Bookero.pl – system rezerwacji online",
      "cwe": "CWE-79",
      "title": "Bookero.pl <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6910"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-9253",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.10724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "loopus",
      "product": "WP Cost Estimation & Payment Forms Builder",
      "cwe": "CWE-79",
      "title": "WP Cost Estimation & Payment Forms Builder (E&P Forms) <= 10.5.97 - Unauthenticated Stored Cross-Site Scripting via 'customerInfos' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9253"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-4298",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mlfactory",
      "product": "DSGVO All in one for WP",
      "cwe": "CWE-862",
      "title": "DSGVO All in one for WP <= 4.9 - Missing Authorization to Authenticated (Subscriber+) Settings Reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4298"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-31267",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Mercusys MW302R MW302R(EU)_V1_1.4.10 Build 231023 is vulnerable to Buffer Overflow in the administrative web interface. A stack buffer overflow vulnerability in the administrative web interface allows an authenticated attacker with administrative privileges to trigger a system crash by sending a specially crafted request. The vulnerability results in denial of service through control flow manipulation to an arbitrary instruction address.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31267"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-15311",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00203,
      "epss_percentile": 0.10629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NousResearch",
      "product": "hermes-agent",
      "cwe": "CWE-79",
      "title": "NousResearch hermes-agent Matrix Adapter matrix.py MatrixAdapter._markdown_to_html cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15311"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-60120",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webkul",
      "product": "Bagisto",
      "cwe": "CWE-79",
      "title": "Bagisto < 2.4.4 Stored XSS via CSTI in create.blade.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60120"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-13253",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpxpo",
      "product": "Post Grid Gutenberg Blocks – PostX",
      "cwe": "CWE-79",
      "title": "Post Grid Gutenberg Blocks for News, Magazines, Blog Websites <= 5.0.31 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'moreResultsText' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13253"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2025-63579",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed with this vulnerability, allowing encrypted data to be decrypted. Passwords and other sensitive information can be obtained. This affects Kyocera Command Center RX TASKalfa 2552ci, TASKalfa 3252ci, TASKalfa 2553ci, TASKalfa 3253ci, TASKalfa 3554ci, TASKalfa 4052ci, TASKalfa 5052ci, TASKalfa 6052ci, TASKalfa 7052ci, TASKalfa 8052ci, TASKalfa 7353ci, TASKalfa 8353ci, TASKalfa 2554ci, TASKalfa 3254ci, TASKalfa 505.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-63579"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-55212",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pimcore",
      "product": "pimcore",
      "cwe": "CWE-285",
      "title": "Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55212"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-9235",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dhlparcel",
      "product": "DHL eCommerce (Benelux) for WooCommerce",
      "cwe": "CWE-862",
      "title": "DHL eCommerce (Benelux) for WooCommerce <= 2.2.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Shipping Label Creation and Deletion via dhlpwc_label_create and dhlpwc_label_delete AJAX Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9235"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-9240",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iscpcolissimo",
      "product": "Colissimo shipping methods for WooCommerce",
      "cwe": "CWE-862",
      "title": "Colissimo Officiel : Méthodes de livraison pour WooCommerce <= 2.9.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Shipment Modification via lpc_order_affect AJAX action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9240"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-4653",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bouncingsprout",
      "product": "Block, Suspend, Report for BuddyPress",
      "cwe": "CWE-79",
      "title": "Block, Suspend, Report for BuddyPress <= 3.6.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'link' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4653"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-14343",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codename065",
      "product": "Download Manager",
      "cwe": "CWE-79",
      "title": "Download Manager <= 3.3.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'note_before' and 'note_after' Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14343"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-11869",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP DSGVO Tools (GDPR)",
      "cwe": null,
      "title": "WP DSGVO Tools (GDPR) < 3.1.40 - Unauthenticated Sensitive Information Disclosure via Subject Access Request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11869"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-11875",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Support Plus Responsive Ticket System",
      "cwe": null,
      "title": "WP Support Plus Responsive Ticket System <= 9.1.2 - Unauthenticated Support Ticket Access via Session Cookie Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11875"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-47831",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.09078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloud Foundry Foundation",
      "product": "bosh-windows-stemcell-builder",
      "cwe": null,
      "title": "Cryptographically Weak Password Generation in bosh-windows-stemcell-builder Allows Remote SSH Brute-Force Attacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47831"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-12879",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google Cloud",
      "product": "Apigee",
      "cwe": "CWE-441",
      "title": "Cross-Tenant Data Exfiltration in Apigee via BigQuery Confused Deputy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12879"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-0280",
      "cvss_base": 1.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00188,
      "epss_percentile": 0.08805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cloud NGFW",
      "cwe": "CWE-131",
      "title": "PAN-OS: IPv6 Firewall Policy Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0280"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-4275",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00187,
      "epss_percentile": 0.08605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "badhonrocks",
      "product": "Divi Torque Lite – Divi Modules for the Divi Builder & Theme",
      "cwe": "CWE-352",
      "title": "Divi Torque Lite <= 4.2.3 - Cross-Site Request Forgery to Arbitrary Plugin Installation via 'install_plugin' REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4275"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-12516",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Fediverse Embeds",
      "cwe": null,
      "title": "Fediverse Embeds < 1.5.8 - Unauthenticated SSRF via Media Proxy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12516"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-12517",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Fediverse Embeds",
      "cwe": null,
      "title": "Fediverse Embeds < 1.5.8 - Unauthenticated SSRF via Site Info Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12517"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-51598",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.08012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-20",
      "title": "An input validation vulnerability in the RTSP service of MERCURY MIPC252W IP Camera v1.0.5 Build 230306 Rel.79931n) allows an unauthenticated, network-adjacent attacker to cause a denial of service via a crafted DESCRIBE request with a malformed URL in the request line.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51598"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-12270",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Everest Forms",
      "cwe": null,
      "title": "Everest Forms < 3.5.0 - Unauthenticated Missing Authorization via Site Assistant REST Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12270"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-57028",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS Evolved",
      "cwe": "CWE-923",
      "title": "Junos OS Evolved: A port which has been inadvertently exposed can be reached by an attacker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57028"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-57019",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00177,
      "epss_percentile": 0.07557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS",
      "cwe": "CWE-1284",
      "title": "Junos OS: MX Series: Specific traffic causes an FPC to reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57019"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-57020",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00177,
      "epss_percentile": 0.07557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS",
      "cwe": "CWE-754",
      "title": "Junos OS: QFX10000 Series: IPv6 multicast traffic received on non-IRB interfaces causes a multicast flood",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57020"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-0282",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00177,
      "epss_percentile": 0.07539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cloud NGFW",
      "cwe": "CWE-20",
      "title": "PAN-OS: File Deletion Vulnerability in Management Web Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0282"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-58143",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cotonti",
      "product": "Cotonti",
      "cwe": "CWE-352",
      "title": "Cotonti Siena 0.9.26 CSRF via admin.php Config Update Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58143"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-59148",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mockoon",
      "product": "mockoon",
      "cwe": "CWE-306",
      "title": "Mockoon: Unauthenticated admin API + wildcard CORS allows mock-state hijack and secret theft",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59148"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-31982",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nozomi Networks",
      "product": "Guardian",
      "cwe": "CWE-601",
      "title": "Open Redirect in SAML Single Sign-On in Guardian/CMC before 26.2.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31982"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-33801",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS",
      "cwe": "CWE-754",
      "title": "Junos OS and Junos OS Evolved: When a specifically malformed BGP route update is received RPD crashes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33801"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-59269",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.0017,
      "epss_percentile": 0.06773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VMware",
      "product": "Pinniped",
      "cwe": null,
      "title": "Privilege Escalation via Active Directory LDAP injection in Pinniped Supervisor can be executed by an attacker who can edit LDAP Group DN entries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59269"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-0281",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00168,
      "epss_percentile": 0.0656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cloud NGFW",
      "cwe": "CWE-524",
      "title": "PAN-OS: Information Disclosure Vulnerability in Management Web Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0281"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-33800",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS",
      "cwe": "CWE-606",
      "title": "Junos OS: MX Series: In a VC scenario a high rate of micro-BFD session flaps will cause an FPC crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33800"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-57027",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS",
      "cwe": "CWE-401",
      "title": "Junos OS: EX4100 Series, EX4400: With sFlow configured in a VC scenario multicast traffic leads to an FPC crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57027"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-44342",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuantumNous",
      "product": "new-api",
      "cwe": "CWE-352",
      "title": "New API CSRF in email and WeChat account binding endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44342"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2025-27462",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00158,
      "epss_percentile": 0.05487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Windows PV drivers",
      "cwe": "CWE-276",
      "title": "WinPVDrivers: Excessive permissions on user-exposed devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-27462"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2025-27463",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00158,
      "epss_percentile": 0.05487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Windows PV drivers",
      "cwe": "CWE-276",
      "title": "WinPVDrivers: Excessive permissions on user-exposed devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-27463"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2025-27464",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00158,
      "epss_percentile": 0.05488,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Windows PV drivers",
      "cwe": "CWE-276",
      "title": "WinPVDrivers: Excessive permissions on user-exposed devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-27464"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-56458",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.04942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "HCL DevOps Deploy",
      "cwe": "CWE-942",
      "title": "HCL DevOps Deploy is susceptible to a Permissive Cross-domain Security Policy with Untrusted Domains",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56458"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-57031",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.04816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS",
      "cwe": "CWE-754",
      "title": "Junos OS: MX Series: For subscribers configured on static interfaces, input filters are not in effect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57031"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-5793",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Inrove Software and Internet Services",
      "product": "BiEticaret",
      "cwe": "CWE-79",
      "title": "XSS in Inrove Software's BiEticaret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5793"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-47828",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BOSH-Ecosystem / BOSH (bosh-cli)",
      "product": "bosh-cli",
      "cwe": null,
      "title": "Missing TLS Certificate Verification in BOSH CLI Allows Root Code Execution via Man-in-the-Middle Credential Replay",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47828"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-41857",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CloudFoundry BOSH",
      "product": "BOSH CLI",
      "cwe": "CWE-78",
      "title": "BOSH CLI Shell Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41857"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-31981",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nozomi Networks",
      "product": "Guardian",
      "cwe": "CWE-79",
      "title": "HTML injection in Diagram tab and Graph view in Guardian/CMC before 26.2.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31981"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-54800",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "CPCI85 Central Processing/Communication",
      "cwe": "CWE-1188",
      "title": "A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application ships with a default configuration that disables all OPC UA security mechanisms. This could allow an attacker to gain unauthorized access and control over critical system functions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54800"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-23560",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0014,
      "epss_percentile": 0.03836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "XAPI",
      "cwe": "CWE-250",
      "title": "Multiple RBAC issues in XAPI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23560"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-23561",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0014,
      "epss_percentile": 0.03836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "XAPI",
      "cwe": "CWE-250",
      "title": "Multiple RBAC issues in XAPI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23561"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2025-58146",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00137,
      "epss_percentile": 0.03591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "XAPI",
      "cwe": "CWE-20",
      "title": "XAPI UTF-8 string handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58146"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-23556",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00137,
      "epss_percentile": 0.03558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "oxenstored",
      "cwe": "CWE-281",
      "title": "oxenstored keeps quota related use counts across domain destruction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23556"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-59858",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.03606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-94",
      "title": "Vim: Arbitrary Code Execution via C Omni-Completion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59858"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-58144",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cotonti",
      "product": "Cotonti",
      "cwe": "CWE-79",
      "title": "Cotonti Siena 0.9.26 Stored XSS via PFS Module ntitle Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58144"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-23559",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00134,
      "epss_percentile": 0.03367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "XAPI",
      "cwe": "CWE-250",
      "title": "Multiple RBAC issues in XAPI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23559"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-23562",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00134,
      "epss_percentile": 0.03367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "XAPI",
      "cwe": "CWE-250",
      "title": "Multiple RBAC issues in XAPI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23562"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-42486",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00134,
      "epss_percentile": 0.03367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "XAPI",
      "cwe": "CWE-250",
      "title": "Multiple RBAC issues in XAPI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42486"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-5005",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Twiser Informatics Technology Consulting, Trade and Education Inc.",
      "product": "OKRs & Goals",
      "cwe": "CWE-79",
      "title": "Stored XSS in Twiser's OKRs & Goals",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5005"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-15182",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00133,
      "epss_percentile": 0.03326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "LibreDWG",
      "cwe": "CWE-119",
      "title": "GNU LibreDWG BMP Image dwg.c dwg_bmp heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15182"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-47840",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00132,
      "epss_percentile": 0.03251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CloudFoundry Foundation",
      "product": "UAA",
      "cwe": null,
      "title": "LDAP StartTLS unconditionally disables hostname verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47840"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-54799",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Siemens",
      "product": "CPCI85 Central Processing/Communication",
      "cwe": "CWE-489",
      "title": "A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0). The affected application contains a vulnerability in its firmware update mechanism's signature validation process. This could allow an attacker to install malicious firmware, leading to persistent code execution and system compromise.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54799"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-31985",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nozomi Networks",
      "product": "Remote Collector",
      "cwe": "CWE-671",
      "title": "Disabled and non-configurable TLS certificate validation in n2os-tui when connecting the Remote Collector to a Guardian or CMC, in Remote Collector before v26.2.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-31985"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-57029",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS Evolved",
      "cwe": "CWE-820",
      "title": "Junos OS Evolved: QFX Series: When sFlow collector reachability changes evo-pfemand process can crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57029"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-15194",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00121,
      "epss_percentile": 0.02287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Open5GS",
      "cwe": "CWE-119",
      "title": "Open5GS AMF context.c amf_context_final use after free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15194"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2025-58151",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0012,
      "epss_percentile": 0.02126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "varstored",
      "cwe": "CWE-367",
      "title": "varstored: TOCTOU issues with mapped guest memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-58151"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-15274",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0012,
      "epss_percentile": 0.02215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lo48576",
      "product": "fbxcel",
      "cwe": "CWE-404",
      "title": "lo48576 fbxcel Node Header parser.rs denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15274"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-15276",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0012,
      "epss_percentile": 0.02214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pdeljanov",
      "product": "Symphonia",
      "cwe": "CWE-404",
      "title": "pdeljanov Symphonia Metadata denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15276"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-21901",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.02002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS",
      "cwe": "CWE-476",
      "title": "Junos OS and Junos OS Evolved: Configuration of a specific SSH option results in mgd crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21901"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-15184",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00118,
      "epss_percentile": 0.01999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "LibreDWG",
      "cwe": "CWE-404",
      "title": "GNU LibreDWG DWG File dwg.c dwg_next_entity null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15184"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-58303",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "Escargot",
      "cwe": "CWE-121",
      "title": "Stack-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before b30b63fc63b403907d8137da1c65aaa4521fe74e.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58303"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-58306",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "Escargot",
      "cwe": "CWE-122",
      "title": "Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before ef525f337fafddecde77a3c426212a84bb20cb98.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58306"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-56288",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01804,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "patch",
      "cwe": "CWE-476",
      "title": "NULL Pointer Dereference in GNU patch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56288"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-56289",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01804,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "patch",
      "cwe": "CWE-835",
      "title": "Loop with Unreachable Exit Condition in GNU patch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56289"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-0275",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00112,
      "epss_percentile": 0.01591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Prisma Browser",
      "cwe": "CWE-269",
      "title": "Prisma Browser: Local Privilege Escalation on macOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0275"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-15185",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00112,
      "epss_percentile": 0.01602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "GPAC",
      "cwe": "CWE-119",
      "title": "GPAC MP4Box vobsub.c vobsub_read_idx out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15185"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-0277",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Prisma Access Agent",
      "cwe": "CWE-295",
      "title": "Prisma Access Agent: Improper Certificate Validation on iOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0277"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-58307",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "Escargot",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read, Reachable assertion vulnerability in Samsung Open Source Escargot allows Overread Buffers, Input Data Manipulation. This issue affects Escargot: before 2dee22f5c7b8bf31cb7252d7731fae8c07f2842c.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58307"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-59857",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vim",
      "product": "vim",
      "cwe": "CWE-787",
      "title": "Vim: Out-of-bounds Write in SAL Soundfolding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59857"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-58304",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "Escargot",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read, Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58304"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-58305",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Open Source",
      "product": "Escargot",
      "cwe": "CWE-843",
      "title": "Access of resource using incompatible type ('type confusion') vulnerability in Samsung Open Source Escargot allows Pointer Manipulation. This issue affects Escargot: before 779f6bedf58f334dec64b0a51ebb724b4708b84a.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58305"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-0278",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Prisma Access Agent",
      "cwe": "CWE-693",
      "title": "Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0278"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-56459",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.0113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "HCL DevOps Deploy / HCL Launch",
      "cwe": "CWE-532",
      "title": "HCL DevOps Deploy / HCL Launch is susceptible to sensitive information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56459"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-47830",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.001,
      "epss_percentile": 0.00998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cloud Foundry Foundation",
      "product": "bosh-windows-stemcell-builder",
      "cwe": null,
      "title": "Incorrect Permission Assignment Allows Local Privilege Escalation to SYSTEM via Executable Overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47830"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-57025",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00098,
      "epss_percentile": 0.00878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS",
      "cwe": "CWE-466",
      "title": "Junos OS and Junos OS Evolved: EX Series, QFX Series, MX Series: A specific 'show l2-learning/ethernet-switching' command causes l2ald crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57025"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-0276",
      "cvss_base": 1.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00098,
      "epss_percentile": 0.00887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Palo Alto Networks",
      "product": "Cortex XDR Broker VM",
      "cwe": "CWE-269",
      "title": "Cortex XDR Broker VM: Privilege Escalation (PE) Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0276"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-58198",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gunthercox",
      "product": "ChatterBot",
      "cwe": "CWE-59",
      "title": "ChatterBot: Symlink-Following Arbitrary Write via UbuntuCorpusTrainer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58198"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-33802",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00092,
      "epss_percentile": 0.00592,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Juniper Networks",
      "product": "Junos OS",
      "cwe": "CWE-862",
      "title": "Junos OS: EX Series: Unauthorized users can execute service-impacting CLI command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33802"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-39243",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-39243. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-39245",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-39245. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-39246",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-39246. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54695",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54695 (pipecat-ai pipecat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56292",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56292 (acymailing.com AcyMailing extension for Joomla). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58459",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58459 (ntpsec gpsd). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59212",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59212 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59213",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59213 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59217",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59217 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59219",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59219 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59220",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59220 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59221",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59221 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59222",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59222 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59227",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59227 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59715",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59715 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59856",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59856 (vim). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
