{
  "day": "2026-07-10",
  "boundary": "UTC calendar day",
  "published_count": 350,
  "by_severity": {
    "CRITICAL": 36,
    "HIGH": 122,
    "MEDIUM": 163,
    "LOW": 29
  },
  "kev_count": 2,
  "exploit_reference_count": 27,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-48939",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.82501,
      "epss_percentile": 0.99638,
      "kev": true,
      "kev_due_at": "2026-07-13",
      "vendor": "icagenda.com",
      "product": "iCagenda extension for Joomla",
      "cwe": "CWE-434",
      "title": "Joomla Extension - icagenda.com - Remote Code Execution in iCaganda extension for Joomla < 4.0.8/3.9.15",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48939"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-56291",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.76066,
      "epss_percentile": 0.99492,
      "kev": true,
      "kev_due_at": "2026-07-13",
      "vendor": "balbooa.com",
      "product": "balbooa.com Balbooa Forms extension for Joomla",
      "cwe": "CWE-434",
      "title": "Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56291"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-14894",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02803,
      "epss_percentile": 0.85345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebRehab",
      "product": "Super Forms – Drag & Drop Form Builder",
      "cwe": "CWE-434",
      "title": "Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14894"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-61459",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02105,
      "epss_percentile": 0.80262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flux159",
      "product": "mcp-server-kubernetes",
      "cwe": "CWE-88",
      "title": "MCP Server Kubernetes < 3.9.0 Argument Injection via kubectl Structured Tools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61459"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2025-30007",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01986,
      "epss_percentile": 0.7899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hestiacp",
      "product": "hestiacp",
      "cwe": "CWE-78",
      "title": "HestiaCP < 1.9.5 Authenticated OS Command Injection via DNS Record Management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-30007"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-10768",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0126,
      "epss_percentile": 0.67253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "LocalGov Workflows",
      "cwe": "CWE-862",
      "title": "LocalGov Workflows - Moderately critical - Information disclosure - SA-CONTRIB-2026-039",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10768"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-56688",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01199,
      "epss_percentile": 0.65686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex Manager",
      "cwe": "CWE-78",
      "title": "Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability during OS Repository processing to achieve arbitrary command execution as root, potentially leading to full appliance compromise and lateral movement into managed infrastructure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56688"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-15282",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01018,
      "epss_percentile": 0.60615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tenteeglobal",
      "product": "Instant Appointment",
      "cwe": "CWE-434",
      "title": "Instant Appointment <= 1.2 - Unauthenticated Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15282"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-41880",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01011,
      "epss_percentile": 0.60419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "R-SOFT SERWIS",
      "product": "DMS",
      "cwe": "CWE-78",
      "title": "OS Command Injection in R-SOFT DMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41880"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-41876",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00828,
      "epss_percentile": 0.54668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "R-SOFT SERWIS",
      "product": "DMS",
      "cwe": "CWE-78",
      "title": "OS Command Injection in R-SOFT DMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41876"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-57219",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00784,
      "epss_percentile": 0.53223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-522",
      "title": "RabbitMQ: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57219"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-55175",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00615,
      "epss_percentile": 0.46815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "spinnaker",
      "product": "spinnaker",
      "cwe": "CWE-502",
      "title": "Spinnaker: Improper yaml processing on kustomize bake operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55175"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-13347",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00601,
      "epss_percentile": 0.46118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "templatic1",
      "product": "Hide My WP Lite",
      "cwe": "CWE-22",
      "title": "Hide My WP Lite <= 1.3 - Unauthenticated Path Traversal to Arbitrary File Read via 'he_wrapper_js' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13347"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-13430",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00597,
      "epss_percentile": 0.45961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpazleen",
      "product": "Post Export Import with Media",
      "cwe": "CWE-434",
      "title": "Post Export Import with Media <= 1.13.1 - Authenticated (Administrator+) Arbitrary File Upload via Trailing-Dot Filename Bypass in ZIP Media Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13430"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-61434",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00579,
      "epss_percentile": 0.45106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-78",
      "title": "PraisonAI before 4.6.78 Allowlist Bypass via find -exec",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61434"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-56814",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00579,
      "epss_percentile": 0.45088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-plug",
      "product": "plug",
      "cwe": "CWE-770",
      "title": "Plug: multipart :length limit is not charged for part headers, enabling unbounded temp-file creation (denial of service)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56814"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-49844",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00574,
      "epss_percentile": 0.44859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Log4j API",
      "cwe": "CWE-116",
      "title": "Apache Log4j API: Improper serialization of non-finite floating-point values in MapMessage.asJson()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49844"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2025-70796",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00565,
      "epss_percentile": 0.44421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "An unauthenticated path traversal vulnerability exists in the web management interface of WTI (Wireless Technology, Inc.) version 3.5.0.r 2024/05/24 00:00:00. An unauthenticated attacker can craft malicious HTTP requests containing traversal sequences to access files outside of the intended web root directory. This may allow disclosure of sensitive system files and configuration data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-70796"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-20744",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00562,
      "epss_percentile": 0.44258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hydro-Québec",
      "product": "Le Circuit Electrique charging station backend",
      "cwe": "CWE-284",
      "title": "Hydro-Québec Le Circuit Electrique charging station backend Improper Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20744"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-57220",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00547,
      "epss_percentile": 0.43506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-770",
      "title": "RabbitMQ: Stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57220"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-44795",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00543,
      "epss_percentile": 0.43258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "spinnaker",
      "product": "spinnaker",
      "cwe": "CWE-470",
      "title": "Spinnaker: Non-safe yaml deserialization allowing RCE when using specific types",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44795"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-15302",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00533,
      "epss_percentile": 0.42735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "reputeinfosystems",
      "product": "ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup",
      "cwe": "CWE-36",
      "title": "ARMember <= 4.0.27 - Directory Traversal via X-FILENAME",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15302"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-52747",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00519,
      "epss_percentile": 0.41959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "owasp-modsecurity",
      "product": "ModSecurity",
      "cwe": "CWE-180",
      "title": "ModSecurity: Multipart form-data parser silently strips embedded line breaks from form-field values, enabling request-body inspection bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52747"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-57807",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00509,
      "epss_percentile": 0.41315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miniOrange Security Software Pvt Ltd.",
      "product": "OAuth Single Sign On - SSO (OAuth Client)",
      "cwe": "CWE-288",
      "title": "WordPress OAuth Single Sign On - SSO (OAuth Client) plugin <= 38.5.8 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57807"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-57216",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00504,
      "epss_percentile": 0.4099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-287",
      "title": "RabbitMQ: AMQP 1.0, AMQP 0-9-1, Stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57216"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2025-11977",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00501,
      "epss_percentile": 0.40824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "happyforms",
      "product": "Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms",
      "cwe": "CWE-98",
      "title": "HappyForms <= 1.26.12 - Authenticated (Admin+) Local File Inclusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-11977"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-15291",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0047,
      "epss_percentile": 0.38873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeatelier",
      "product": "ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form",
      "cwe": "CWE-862",
      "title": "Chat Help – Click to Chat Button & Form <= 3.1.3 - Missing Authorization to Unauthenticated Sensitive Information Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15291"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-21045",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00465,
      "epss_percentile": 0.38541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Out-of-bounds write in parsing TIFF format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21045"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-12761",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00463,
      "epss_percentile": 0.38411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cyberlord92",
      "product": "miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)",
      "cwe": "CWE-287",
      "title": "miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.7.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via Profile Completion OTP Flow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12761"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-59792",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00461,
      "epss_percentile": 0.38306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-23",
      "title": "In JetBrains IntelliJ IDEA before 2026.1.4, 2026.2 code execution via path traversal in project workspace ID handling was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59792"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-57158",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00459,
      "epss_percentile": 0.38204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-125",
      "title": "FreeRDP planar_decompress_plane_rle_only: heap OOB read — incomplete fix for CVE-2026-23530",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57158"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-55852",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00457,
      "epss_percentile": 0.38057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-22",
      "title": "Frappe: TarSlip RCE in Package Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55852"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-42219",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00457,
      "epss_percentile": 0.38056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-22",
      "title": "Frappe: Path Traversal via /backups Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42219"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-44383",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00448,
      "epss_percentile": 0.37429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hydro-Québec",
      "product": "Le Circuit Electrique charging station backend",
      "cwe": "CWE-613",
      "title": "Hydro-Québec Le Circuit Electrique charging station backend Insufficient Session Expiration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44383"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-28564",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00442,
      "epss_percentile": 0.36935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache IoTDB",
      "cwe": "CWE-294",
      "title": "Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28564"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-14480",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0044,
      "epss_percentile": 0.36821,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenPLC",
      "product": "OpenPLC",
      "cwe": "CWE-73",
      "title": "OpenPLC v3 External Control of File Name or Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14480"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-54469",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00433,
      "epss_percentile": 0.36235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Unisphere for PowerMax",
      "cwe": "CWE-502",
      "title": "Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a Deserialization of Untrusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54469"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-57212",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00433,
      "epss_percentile": 0.36258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-770",
      "title": "RabbitMQ management HTTP API accepts request bodies larger than configured max_http_body_size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57212"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-38059",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00431,
      "epss_percentile": 0.36108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ST Engineering iDirect",
      "product": "Evolution iQ‑Series terminals",
      "cwe": "CWE-306",
      "title": "ST Engineering iDirect iQ-Series Terminals Missing authentication for critical function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38059"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-53448",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00431,
      "epss_percentile": 0.36073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coturn",
      "product": "coturn",
      "cwe": "CWE-89",
      "title": "Coturn: SQL Injection in HTTPS Admin Panel Delete Operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53448"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-57211",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00429,
      "epss_percentile": 0.35934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-36",
      "title": "RabbitMQ: UNC SSRF affecting the management UI on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57211"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-39244",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00426,
      "epss_percentile": 0.35728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "adm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP file with a manipulated uncompressed size header field. In zipEntry.js line 103, Buffer.alloc(_centralHeader.size) allocates memory based on the declared uncompressed size from the ZIP central directory header without validating it against the actual compressed data size or imposing any upper bound. The size value is read directly from the binary header at entryHeader.js line 266 with no bounds check. An attacker can craft a ~120-byte ZIP file that declares ~4GB uncompressed size, causing a memory allocation amplification ratio of over 33 million to 1. The allocation occurs before CRC validation, so the malicious payload cannot be rejected early. All extraction and read methods are affected: readFile(), readAsText(), extractEntryTo(), extractAllTo(), extractAllToAsync(), test(), and entry.getData(). Any application accepting untrusted ZIP files via adm-zip is vulnerable to immediate process crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39244"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-40008",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00423,
      "epss_percentile": 0.35515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache IoTDB",
      "cwe": "CWE-470",
      "title": "Apache IoTDB: Arbitrary Class Instantiation via Pipe Transfer RPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40008"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-57850",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0042,
      "epss_percentile": 0.3522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RustDesk",
      "product": "RustDesk",
      "cwe": "CWE-862",
      "title": "RustDesk Missing Session Scope Enforcement Allows Out-of-Scope Control Message Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57850"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-57584",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00419,
      "epss_percentile": 0.35149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phalcon",
      "product": "cphalcon",
      "cwe": "CWE-1333",
      "title": "Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57584"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-40006",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00419,
      "epss_percentile": 0.35096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache IoTDB",
      "cwe": "CWE-306",
      "title": "Apache IoTDB: Unauthenticated heap-exhaustion DoS via unbounded allocation in IoTDB AirGap pipe receiver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40006"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-57156",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00418,
      "epss_percentile": 0.35003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-122",
      "title": "FreeRDP: Integer overflow leading to heap buffer overflow in Orders Delta Points parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57156"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-52761",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00414,
      "epss_percentile": 0.34685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "owasp-modsecurity",
      "product": "ModSecurity",
      "cwe": "CWE-467",
      "title": "ModSecurity: Transformation utf8toUnicode produces wrong output on i386 architecture",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52761"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-40005",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache IoTDB",
      "cwe": "CWE-22",
      "title": "Apache IoTDB: Path Traversal in Pipe File Transfer Receiver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40005"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-57221",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0041,
      "epss_percentile": 0.34377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-862",
      "title": "RabbitMQ: Passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57221"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-5801",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00404,
      "epss_percentile": 0.33796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Semtek Informatics Software Consulting Trade Ltd. Co.",
      "product": "SEM-PMP",
      "cwe": "CWE-89",
      "title": "SQLi in Semtek Informatics' SEM-PMP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5801"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-42952",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hydro-Québec",
      "product": "Le Circuit Electrique charging station backend",
      "cwe": "CWE-307",
      "title": "Hydro-Québec Le Circuit Electrique charging station backend Improper Restriction of Excessive Authentication Attempts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42952"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-47199",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00401,
      "epss_percentile": 0.33445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-89",
      "title": "Frappe: check_safe_sql_query Permits SELECT INTO OUTFILE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47199"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-55884",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00398,
      "epss_percentile": 0.33128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tilt-dev",
      "product": "tilt",
      "cwe": "CWE-306",
      "title": "Tilt: Missing authentication on the network-exposed Tilt HUD server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55884"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-59161",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qax-os",
      "product": "excelize",
      "cwe": "CWE-400",
      "title": "Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59161"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-8609",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00397,
      "epss_percentile": 0.33106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana OSS",
      "cwe": "CWE-400",
      "title": "Pre-authentication denial of service via the OAuth login route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8609"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-15290",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ultimatemember",
      "product": "Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin",
      "cwe": "CWE-89",
      "title": "Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin <= 2.10.1 - Unauthenticated Blind SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15290"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-61444",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00392,
      "epss_percentile": 0.32539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-94",
      "title": "PraisonAI before 4.6.78 Code Injection via f-string",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61444"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-61492",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00391,
      "epss_percentile": 0.32393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-79",
      "title": "In JetBrains YouTrack before 2026.2.17394 stored XSS via article titles in digest emails was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61492"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-59162",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0039,
      "epss_percentile": 0.32348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qax-os",
      "product": "excelize",
      "cwe": "CWE-248",
      "title": "Excelize: Negative shared-string index causes panic in GetCellValue and GetRows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59162"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-59193",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0039,
      "epss_percentile": 0.32333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-409",
      "title": "Grav CMS — Improper Handling of Highly Compressed Data in Installer::unZip()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59193"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-33382",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00388,
      "epss_percentile": 0.32139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana OSS",
      "cwe": "CWE-400",
      "title": "Denial of service via unbounded request body size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33382"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-54063",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00388,
      "epss_percentile": 0.32107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "qax-os",
      "product": "excelize",
      "cwe": "CWE-770",
      "title": "Excelize: Unbounded Row Index Allocation in Worksheet Parser (checkSheet OOM/Panic DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54063"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-55500",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00387,
      "epss_percentile": 0.32062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9router",
      "cwe": "CWE-200",
      "title": "9router: Exposure of Sensitive Information and Unprotected Database Import/Export Allows Complete Credential Theft and Database Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55500"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-21048",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00387,
      "epss_percentile": 0.32074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Out-of-bounds write in parsing DNG format in libimagecodec.media.quram.so prior to SMR Jul-2026 Release 1 allows remote attackers to write out-of-bounds memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21048"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-12535",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00386,
      "epss_percentile": 0.31968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Formatter Field",
      "cwe": "CWE-915",
      "title": "Formatter Field - Critical - PHP object injection - SA-CONTRIB-2026-048",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12535"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-29519",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00386,
      "epss_percentile": 0.31947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lucee",
      "product": "Lucee",
      "cwe": "CWE-79",
      "title": "Lucee CFML Server Reflected XSS via URL Path Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-29519"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-55687",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00385,
      "epss_percentile": 0.31795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "espressif",
      "product": "esp-idf",
      "cwe": "CWE-121",
      "title": "ESF-IDF: Stack-Based Out-of-Bounds Write in JPEG Decoder DQT Marker Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55687"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-54149",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-78",
      "title": "MaxKB MCP tool import validation bypass allows post-authentication remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54149"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-55882",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tilt-dev",
      "product": "tilt",
      "cwe": "CWE-200",
      "title": "Tilt: Unauthenticated pprof debug endpoints on the Tilt HUD server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55882"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-51119",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00382,
      "epss_percentile": 0.31504,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-269",
      "title": "An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51119"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-57215",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.31573,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-863",
      "title": "RabbitMQ: Direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57215"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-55469",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00378,
      "epss_percentile": 0.31079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-22",
      "title": "Snipe-IT: Path traversal vulnerability via CSV import `image` field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55469"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-15331",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00378,
      "epss_percentile": 0.31051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zhayujie",
      "product": "CowAgent",
      "cwe": "CWE-22",
      "title": "zhayujie CowAgent Skill Installation service.py _add_package path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15331"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-59793",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00377,
      "epss_percentile": 0.30988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-73",
      "title": "In JetBrains TeamCity before 2026.1.2 arbitrary file access was possible via the Perforce VCS integration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59793"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-55638",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00372,
      "epss_percentile": 0.30459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9router",
      "cwe": "CWE-862",
      "title": "9router: Unauthenticated LLM proxy access via /codex rewrite authorization bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55638"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-56261",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00371,
      "epss_percentile": 0.30427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crawl4AI",
      "product": "Crawl4AI",
      "cwe": "CWE-918",
      "title": "Crawl4AI - Server-Side Request Forgery via Webhook URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56261"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-48127",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00369,
      "epss_percentile": 0.3012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-862",
      "title": "Frappe: Arbitrary Attachment Injection via add_attachments and upload_file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48127"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-57157",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00368,
      "epss_percentile": 0.29996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in the camera device enumerator server (rdpecam) via unterminated DeviceName / VirtualChannelName",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57157"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-15326",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00364,
      "epss_percentile": 0.29687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "halo-dev",
      "product": "halo",
      "cwe": "CWE-22",
      "title": "halo-dev halo Theme Installation ThemeUtils.java ThemeUtils.unzipThemeTo path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15326"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-56765",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.29046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Vikunja",
      "product": "Vikunja",
      "cwe": "CWE-639",
      "title": "Vikunja - Unauthenticated Instance-Wide Data Breach via Link Share Hash Disclosure Chained with Cross-Project Attachment IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56765"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-56305",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00357,
      "epss_percentile": 0.2891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-620",
      "title": "Capgo - Authentication Bypass in Password Change via Missing Current Password Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56305"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-58499",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00356,
      "epss_percentile": 0.28867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EverMind-AI",
      "product": "EverOS",
      "cwe": "CWE-22",
      "title": "Path traversal in EverOS /api/v1/memory/add via unvalidated sender_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58499"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-55229",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.28721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gotenberg",
      "product": "gotenberg",
      "cwe": "CWE-918",
      "title": "Gotenberg: SSRF via LibreOffice document processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55229"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-58503",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00354,
      "epss_percentile": 0.28698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-203",
      "title": "Frappe: Unauthenticated User Enumeration via reset_password",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58503"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-61461",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langgenius",
      "product": "dify",
      "cwe": "CWE-89",
      "title": "Dify < 1.16.0-rc1 SQL Injection via MyScale Vector Store search_by_full_text",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61461"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-57217",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-863",
      "title": "RabbitMQ: Topic authorization can lead to cross-tenant routing-key bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57217"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-15330",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00352,
      "epss_percentile": 0.28398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zhayujie",
      "product": "CowAgent",
      "cwe": "CWE-918",
      "title": "zhayujie CowAgent Vision Tool vision.py _download_to_data_url server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15330"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-57218",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00352,
      "epss_percentile": 0.28381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-863",
      "title": "RabbitMQ: AMQP 0-9-1 in combination with OAuth 2: consumer persistence can lead to post-revocation message disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57218"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-15300",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00349,
      "epss_percentile": 0.28094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ninjew",
      "product": "GEO my WP",
      "cwe": "CWE-89",
      "title": "GEO my WP <= 4.5.4 - Unauthenticated SQL Injection via 'distance' / 'lat' / 'lng' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15300"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-15293",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.2794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joeyoungblood",
      "product": "WP Business Intelligence Lite",
      "cwe": "CWE-862",
      "title": "WP Business Intelligence Lite <= 3.2.0 - Authenticated (Subscriber+) Missing Authorization to Privilege Escalation via Arbitrary SQL Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15293"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-55405",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.27993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langchain4j",
      "product": "langchain4j",
      "cwe": "CWE-89",
      "title": "LangChain4j: SQL injection via metadata filters in langchain4j-mariadb and langchain4j-pgvector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55405"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-57575",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00347,
      "epss_percentile": 0.27928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misskey-dev",
      "product": "misskey",
      "cwe": "CWE-918",
      "title": "Misskey: SSRF bypass in URL Preview",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57575"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-55466",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00347,
      "epss_percentile": 0.27822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-79",
      "title": "Snipe-IT: Stored XSS via inline-served attachment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55466"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-15289",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00346,
      "epss_percentile": 0.27789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevart",
      "product": "Booking calendar, Appointment Booking System",
      "cwe": "CWE-89",
      "title": "Booking calendar, Appointment Booking System <= 3.2.17 - Unauthenticated Time-Based SQL Injection via 'wpdevart_id'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15289"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-55213",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.2751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "h2o",
      "product": "h2o",
      "cwe": "CWE-789",
      "title": "h2o: musl libc stack overflow (QPACK)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55213"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-55233",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openresty",
      "product": "openresty",
      "cwe": "CWE-787",
      "title": "OpenResty: Buffer overflow when writing PROXY protocol v2 header to upstream",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55233"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-11990",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00342,
      "epss_percentile": 0.27302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iqonicdesign",
      "product": "KiviCare – Clinic & Patient Management System (EHR)",
      "cwe": "CWE-862",
      "title": "KiviCare <= 4.4.0 - Missing Authorization to Unauthenticated Payment Bypass and Appointment Status Manipulation via /payment-success REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11990"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-15288",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brainstormforce",
      "product": "SureForms – Drag & Drop Contact Form & Form Builder, Payment Form, Survey, Quiz & Calculator",
      "cwe": "CWE-20",
      "title": "SureForms – Drag and Drop Form Builder for WordPress <= 2.2.1 - Unauthenticated Stripe Payment Amount Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15288"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-57574",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misskey-dev",
      "product": "misskey",
      "cwe": "CWE-294",
      "title": "Misskey: TOTP tokens can be reused",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57574"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-57475",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0034,
      "epss_percentile": 0.27108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Deloitte",
      "product": "AI Assist for Customer",
      "cwe": "CWE-306",
      "title": "Deloitte AI Assist for Customer unauthenticated configuration write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57475"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-55827",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-131",
      "title": "FreeRDP: Heap out-of-bounds write in RemoteFX (RFX) Cache Bitmap V3 decode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55827"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-41482",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-22",
      "title": "Frappe: Possible Path Traversal and Local File Inclusion via Chrome PDF Generator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41482"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-39903",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00333,
      "epss_percentile": 0.26337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SimpleMachines",
      "product": "SMF",
      "cwe": "CWE-863",
      "title": "Simple Machines Forum Authorization Bypass via AttachmentApprove.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39903"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-40007",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache IoTDB",
      "cwe": "CWE-400",
      "title": "Apache IoTDB: Unauthenticated unbounded recursion in IoTDB AirGap receiver's E-language prefix parser causes per-connection StackOverflowError",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40007"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-40454",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache IoTDB C++ client",
      "cwe": "CWE-20",
      "title": "Apache IoTDB C++ client: Out-of-bounds reads in C++ client TsBlock deserializer crash client process on malformed server data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40454"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-55474",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-23",
      "title": "Snipe-IT: Directory traversal in displaySig",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55474"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-44918",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00329,
      "epss_percentile": 0.25854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Ironic",
      "cwe": "CWE-862",
      "title": "OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44918"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-22660",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flaskbb",
      "product": "flaskbb",
      "cwe": "CWE-697",
      "title": "FlaskBB Logic Flaw Authorization Group Deletion via Bulk AJAX Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22660"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-15319",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.25204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sipeed",
      "product": "PicoClaw",
      "cwe": "CWE-266",
      "title": "Sipeed PicoClaw Launcher access_control.go IPAllowlist access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15319"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-55665",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gristlabs",
      "product": "grist-core",
      "cwe": "CWE-79",
      "title": "DOM-based XSS in Grist via unsanitized links, enabling privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55665"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-11913",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0032,
      "epss_percentile": 0.24906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Mother May I",
      "cwe": "CWE-79",
      "title": "Mother May I - Critical - Unsupported - SA-CONTRIB-2026-045",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11913"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-55501",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24874,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9router",
      "cwe": "CWE-307",
      "title": "9router: Login brute-force protection bypass via spoofed X-Forwarded-For header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55501"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-49213",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baptisteArno",
      "product": "typebot.io",
      "cwe": "CWE-918",
      "title": "TypeBot: SSRF protection bypass via IPv6 unspecified address in Typebot HTTP request execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49213"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-12918",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00319,
      "epss_percentile": 0.24808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getwpfunnels",
      "product": "Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails",
      "cwe": "CWE-89",
      "title": "Mail Mint <= 1.24.1 - Authenticated (Administrator+) SQL Injection via 'recipients' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12918"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-15378",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00316,
      "epss_percentile": 0.2437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI (RHOAI)",
      "cwe": "CWE-918",
      "title": "Guardrails-detectors: guardrails-detectors: ssrf and local file read via user-supplied xml schema (xml-with-schema:)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15378"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-56675",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.24345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9router",
      "cwe": "CWE-287",
      "title": "9router: Reverse proxy locality collapse allows unauthenticated access to 9router /v1 APIs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56675"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-15298",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.24215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pechenki",
      "product": "TelSender – Сontact form 7, Events, Wpforms, ninja forms  and woocommerce to telegram bot",
      "cwe": "CWE-79",
      "title": "TelSender <= 1.14.14 - Unauthenticated Stored Cross-Site Scripting via Telegram Chat Title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15298"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-11321",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.24228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pluginsGLPI",
      "product": "datainjection",
      "cwe": "CWE-89",
      "title": "GLPI DataInjection Plugin Authenticated SQL Injection via CSV Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11321"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-9726",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Drupal AlternativeCommerce (Basket)",
      "cwe": "CWE-915",
      "title": "Drupal AlternativeCommerce (Basket) - Highly critical - Arbitrary PHP code execution - SA-CONTRIB-2026-038",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9726"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-56279",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.24104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-862",
      "title": "Capgo - Information Disclosure via get_orgs_v7 RPC Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56279"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-55780",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00309,
      "epss_percentile": 0.23639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "M2Team",
      "product": "NanaZip",
      "cwe": "CWE-248",
      "title": "NanaZip: Uncaught exception / unbounded allocation in NanaZip .NET single-file Extract() via unvalidated entry Size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55780"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-55809",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Flag attendance field",
      "cwe": "CWE-915",
      "title": "Flag attendance field - Critical - PHP object injection - SA-CONTRIB-2026-049",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55809"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-49394",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-862",
      "title": "Frappe: Auth. bypass via update_page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49394"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-59155",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00304,
      "epss_percentile": 0.23069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nezhahq",
      "product": "nezha",
      "cwe": "CWE-200",
      "title": "Nezha Monitoring: DDNS and Notification credential exposure via unredacted list API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59155"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-14461",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00304,
      "epss_percentile": 0.23074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BitWizard",
      "product": "mtr",
      "cwe": "CWE-125",
      "title": "Out-of-bound read in mtr",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14461"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-58492",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00302,
      "epss_percentile": 0.22899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-89",
      "title": "grav-plugin-database: SQL Injection in PDO::tableExists() due to Unsanitized Table Name Interpolation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58492"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-54423",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Ironic",
      "cwe": "CWE-424",
      "title": "In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54423"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-54468",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.22867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Unisphere for PowerMax",
      "cwe": "CWE-22",
      "title": "Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior, contain(s) a path traversal vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability to read arbitrary files.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54468"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-53653",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-770",
      "title": "Grav: Unauthenticated denial of service via unbounded image derivative dimensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53653"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-15089",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00298,
      "epss_percentile": 0.2241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Commerce guest registration",
      "cwe": "CWE-287",
      "title": "Commerce guest registration - Critical - Unsupported - SA-CONTRIB-2026-079",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15089"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-55789",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "logto-io",
      "product": "logto",
      "cwe": "CWE-91",
      "title": "Logto: SAML IdP injects user-controlled profile attributes raw into signed assertions, allowing privilege escalation at relying Service Providers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55789"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-55843",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-269",
      "title": "Snipe-IT: Improper Privilege Management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55843"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-15284",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00298,
      "epss_percentile": 0.22436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kingaddons",
      "product": "King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder",
      "cwe": "CWE-79",
      "title": "King Addons for Elementor <= 51.1.62 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'form_page_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15284"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-59151",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00296,
      "epss_percentile": 0.22206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "prowler-cloud",
      "product": "prowler",
      "cwe": "CWE-287",
      "title": "Prowler: SAML Domain Claiming Enables Cross-Tenant Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59151"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-9838",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00296,
      "epss_percentile": 0.22235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "room34",
      "product": "ICS Calendar",
      "cwe": "CWE-79",
      "title": "ICS Calendar <= 12.0.9 - Reflected Cross-Site Scripting via 'htmltagtitle' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9838"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-53363",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00295,
      "epss_percentile": 0.22152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53363"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-56335",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-284",
      "title": "Capgo - Channel Configuration Mutation via Write-Scoped API Keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56335"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-14475",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wplegalpages",
      "product": "Cookie Banner for GDPR / CCPA – WPLP Cookie Consent",
      "cwe": "CWE-89",
      "title": "Cookie Banner for GDPR / CCPA <= 4.3.6 - Authenticated (Administrator+) SQL Injection via 'scan_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14475"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-41878",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.2192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "R-SOFT SERWIS",
      "product": "DMS",
      "cwe": "CWE-639",
      "title": "Insecure Direct Object Reference in R-SOFT DMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41878"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-57474",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Deloitte",
      "product": "AI Assist for Customer",
      "cwe": "CWE-200",
      "title": "Deloitte AI Assist for Customer information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57474"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-55879",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0029,
      "epss_percentile": 0.21566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openreplay",
      "product": "openreplay",
      "cwe": "CWE-79",
      "title": "OpenReplay: Unauthenticated stored XSS leads to dashboard account takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55879"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-58493",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-74",
      "title": "grav-plugin-database: DSN Parameter Injection via Unsanitized Configuration Values in Connection String Construction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58493"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-9857",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "saskaita123",
      "product": "Invoice123",
      "cwe": "CWE-862",
      "title": "Invoice123 <= 1.7.0 - Missing Authorization to Authenticated (Subscriber+) Setting Modification via s123_submit_api_key & s123_submit_invoice_settings AJAX actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9857"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-40452",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache IoTDB",
      "cwe": "CWE-284",
      "title": "Apache IoTDB: Authorization bypass in /rest/v2/fastLastQuery exposes last-value data to unauthorized authenticated users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40452"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-55670",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00286,
      "epss_percentile": 0.21176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-284",
      "title": "ZITADEL: Cross-Tenant User Leakage via Recycled Identifiers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55670"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-55460",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.21125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-863",
      "title": "Snipe-IT: Authorization bypass on bulk editing users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55460"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-22659",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.20988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flaskbb",
      "product": "flaskbb",
      "cwe": "CWE-863",
      "title": "FlaskBB Authorization Bypass via Topic ID Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22659"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-15287",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rtcamp",
      "product": "rtMedia for WordPress, BuddyPress and bbPress",
      "cwe": "CWE-89",
      "title": "rtMedia for WordPress, BuddyPress and bbPress <= 4.6.18 - Authenticated (Subscriber+) SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15287"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-55187",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axllent",
      "product": "mailpit",
      "cwe": "CWE-918",
      "title": "Mailpit: Incomplete SSRF protection in Link Check API via IPv6 transition mechanisms (follow-up to CVE-2026-27808)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55187"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-61460",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "krayin",
      "product": "laravel-crm",
      "cwe": "CWE-639",
      "title": "Krayin CRM Insecure Direct Object Reference via Controllers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61460"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-11992",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "easyappointments",
      "product": "Easy Appointments",
      "cwe": "CWE-862",
      "title": "Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Author+) Bulk Appointment Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11992"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-61432",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-22",
      "title": "PraisonAI FastContext before 1.6.78 Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61432"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-47422",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.2028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "frappe",
      "cwe": "CWE-862",
      "title": "Frappe: Unrestricted API access to save_report",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47422"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-55462",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-863",
      "title": "Snipe-IT: Authorization bypass on print inventory page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55462"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-55672",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.2009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-287",
      "title": "ZITADEL: Missing client_id binding in OIDC authorization code exchange and refresh token flows (RFC 6749 Section 4.1.3 violation)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55672"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-15086",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.20142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Raw Formatter [Meta Tag Formatter]",
      "cwe": null,
      "title": "Raw Formatter [Meta Tag Formatter] - Critical - Unsupported - SA-CONTRIB-2026-077",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15086"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-55659",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.19984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gristlabs",
      "product": "grist-core",
      "cwe": "CWE-79",
      "title": "Grist: XSS through unsafe value interpolation in server-rendered pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55659"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-56312",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-287",
      "title": "Capgo - Account Creation Before CAPTCHA Validation in accept_invitation Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56312"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-59796",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-862",
      "title": "In JetBrains TeamCity before 2026.1.2 pipeline modification was possible due to improper permission checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59796"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-57961",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phpMyFAQ",
      "product": "phpMyFAQ",
      "cwe": "CWE-22",
      "title": "phpMyFAQ - Authenticated Path Traversal in PDF Export via concatenatePaths Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57961"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-57167",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chocobozzz",
      "product": "PeerTube",
      "cwe": "CWE-80",
      "title": "PeerTube: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57167"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-55515",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-639",
      "title": "Snipe-IT: Cross-company deletion of pending checkout acceptances via unscoped report endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55515"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-11392",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thimpress",
      "product": "WP Hotel Booking",
      "cwe": "CWE-79",
      "title": "WP Hotel Booking <= 2.3.1 - Reflected Cross-Site Scripting via 'check_in_date' and 'check_out_date' Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11392"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-12400",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "priyanshuchaudhary",
      "product": "FlowForms – Conversational Form Builder",
      "cwe": "CWE-639",
      "title": "FlowForms <= 1.1.1 - Authenticated (Contributor+) Insecure Direct Object Reference to Arbitrary Form Modification via REST API '/flowforms/v1/forms/{id}' Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12400"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-15286",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19049,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stellarwp",
      "product": "Kadence Blocks — Page Builder Toolkit for Gutenberg Editor",
      "cwe": "CWE-863",
      "title": "Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.5.32 - Incorrect Authorization to Authenticated (Contributor+) Post Publication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15286"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-40009",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache IoTDB",
      "cwe": "CWE-269",
      "title": "Apache IoTDB: Authenticated users can escalate to full tree-path access by renaming themselves to __internal_auditor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40009"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-2397",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00265,
      "epss_percentile": 0.18512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adam Retail Automation Ltd.",
      "product": "MobilMen 20T",
      "cwe": "CWE-89",
      "title": "SQLi in AdamPOS' MobilMen 20T",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2397"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-59795",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-79",
      "title": "In JetBrains TeamCity before 2026.1.2 stored XSS via unauthenticated agent registration was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59795"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-15285",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "posimyththemes",
      "product": "The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce",
      "cwe": "CWE-79",
      "title": "The Plus Addons for Elementor <= 6.4.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button Widget Custom Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15285"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-15070",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wordpresschef",
      "product": "Salon Booking System – Free Version",
      "cwe": "CWE-352",
      "title": "Salon Booking System <= 10.30.32 - Cross-Site Request Forgery to Remote Code Execution via 'value' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15070"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-55377",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "logto-io",
      "product": "logto",
      "cwe": "CWE-287",
      "title": "Logto: Account Center MFA management step-up bypass via WebAuthn registration verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55377"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-61431",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-22",
      "title": "PraisonAI before 4.6.78 Path Traversal via ContextGatherer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61431"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-56309",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-770",
      "title": "Capgo - Plan Bypass via Unrestricted Attachment Upload Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56309"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-15081",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17548,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Location Selector",
      "cwe": "CWE-89",
      "title": "Location Selector - Critical - SQL Injection - SA-CONTRIB-2026-072",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15081"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-13039",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "arraytics",
      "product": "Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)",
      "cwe": "CWE-862",
      "title": "Eventin 4.0.26 - 4.1.15 - Missing Authorization to Unauthenticated Payment Bypass via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13039"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-15297",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17491,
      "kev": false,
      "kev_due_at": null,
      "vendor": "neeraj_slit",
      "product": "Brevo – Email, SMS, Web Push, Chat, and more.",
      "cwe": "CWE-79",
      "title": "Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.77 - Reflected Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15297"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-15373",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00256,
      "epss_percentile": 0.175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Call Recording Software",
      "cwe": "CWE-266",
      "title": "Eleveo Call Recording Software userAddAction.do improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15373"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-15374",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00256,
      "epss_percentile": 0.17501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Call Recording Software",
      "cwe": "CWE-266",
      "title": "Eleveo Call Recording Software Group roleAddAction.do improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15374"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-15376",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00256,
      "epss_percentile": 0.17501,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Call Recording Software",
      "cwe": "CWE-266",
      "title": "Eleveo Call Recording Software statisticReportAction.do improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15376"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-15143",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00255,
      "epss_percentile": 0.17228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI (RHOAI)",
      "cwe": "CWE-918",
      "title": "Guardrails-detectors: guardrails-detectors: ssrf and local file read via user-supplied xml schema (xml-with-schema:)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15143"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-3907",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "prasunsen",
      "product": "Hostel",
      "cwe": "CWE-79",
      "title": "Hostel <= 1.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wphostel-book' Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3907"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-15296",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.1729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cservit",
      "product": "affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display",
      "cwe": "CWE-79",
      "title": "affiliate-toolkit – WP Affiliate Plugin with Amazon <= 3.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15296"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-15377",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00255,
      "epss_percentile": 0.17335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Call Recording Software",
      "cwe": "CWE-266",
      "title": "Eleveo Call Recording Software sendlogfile improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15377"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-54714",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.17024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "logto-io",
      "product": "logto",
      "cwe": "CWE-79",
      "title": "Logto: XSS via unescaped RelayState in SAML auto-submit form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54714"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-57213",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-79",
      "title": "RabbitMQ: Stored XSS federation management plugin via unsanitized consumer_tag rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57213"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-55671",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00252,
      "epss_percentile": 0.16854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-918",
      "title": "ZITADEL: Server-Side Request Forgery (SSRF) and Denylist Bypass in Outgoing HTTP Components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55671"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-6212",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Teracity Software Technologies Inc.",
      "product": "TeraMIS",
      "cwe": "CWE-639",
      "title": "IDOR in Teracity's TeraMIS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6212"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-41877",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "R-SOFT SERWIS",
      "product": "DMS",
      "cwe": "CWE-79",
      "title": "Stored XSS in R-SOFT DMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41877"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-2398",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adam Retail Automation Ltd.",
      "product": "MobilMen 20T",
      "cwe": "CWE-639",
      "title": "IDOR in AdamPOS' MobilMen 20T",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2398"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-61455",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-409",
      "title": "Grav before 2.0.1 Decompression Bomb via ZipArchiver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61455"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-13244",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Tealium iQ Tag Management",
      "cwe": "CWE-915",
      "title": "Tealium iQ Tag Management - Critical - PHP object injection - SA-CONTRIB-2026-064",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13244"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-55810",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.1645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Plotly.js Graphing",
      "cwe": "CWE-915",
      "title": "Plotly.js Graphing - Critical - PHP object injection - SA-CONTRIB-2026-050",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55810"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-57476",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.16373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Deloitte",
      "product": "AI Assist for Customer",
      "cwe": "CWE-306",
      "title": "Deloitte AI Assist for Customer unauthenticated RAG corpus read and write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57476"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-13010",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "beardev",
      "product": "JoomSport – for Sports: Team & League, Football, Hockey & more",
      "cwe": "CWE-89",
      "title": "JoomSport <= 5.7.9 - Authenticated (Contributor+) SQL Injection via 'event' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13010"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-15317",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00247,
      "epss_percentile": 0.16278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sipeed",
      "product": "PicoClaw",
      "cwe": "CWE-918",
      "title": "Sipeed PicoClaw Guarded Web Fetch Flow web.go WebFetchTool.Execute server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15317"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-55641",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9router",
      "cwe": "CWE-290",
      "title": "9router: Unauthenticated `/v1` proxy access via `Host`-header spoofing → open AI relay + SSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55641"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-55881",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openreplay",
      "product": "openreplay",
      "cwe": "CWE-639",
      "title": "OpenReplay: Cross-tenant session replay disclosure via missing session ownership check in first-mob endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55881"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-61450",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.1621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-94",
      "title": "Grav before 2.0.2 Config Exfiltration via offsetGet Filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61450"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-53449",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.16089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coturn",
      "product": "coturn",
      "cwe": "CWE-73",
      "title": "Coturn: Arbitrary File Write via CLI psd Command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53449"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-15087",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Clean RESTful",
      "cwe": "CWE-287",
      "title": "Clean RESTful - Critical - Unsupported - SA-CONTRIB-2026-078",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15087"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-11818",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "arraytics",
      "product": "WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System",
      "cwe": "CWE-862",
      "title": "WPCafe <= 3.0.14 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Modification via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11818"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-15292",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.1575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tibouille",
      "product": "Sudoku Shortcode",
      "cwe": "CWE-79",
      "title": "Sudoku Shortcode <= 1.0.0 - Authenticated (Contributor+) Cross-Site Scripting via 'background' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15292"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-6802",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fahadmahmood",
      "product": "Easy Upload Files During Checkout",
      "cwe": "CWE-639",
      "title": "Easy Upload Files During Checkout <= 3.0.1 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion via 'eufdc-delete' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6802"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-55664",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gristlabs",
      "product": "grist-core",
      "cwe": "CWE-200",
      "title": "Grist: Insufficient access control in the /forms endpoint exposes table metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55664"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-15104",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevteam",
      "product": "BetterDocs –  AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot",
      "cwe": "CWE-89",
      "title": "BetterDocs <= 4.6.0 - Authenticated (Custom+) SQL Injection via 'lang' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15104"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-15329",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00241,
      "epss_percentile": 0.15572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zhayujie",
      "product": "CowAgent",
      "cwe": "CWE-200",
      "title": "zhayujie CowAgent Browser Tool browser_tool.py BrowserTool._do_navigate information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15329"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-56690",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex Manager",
      "cwe": "CWE-89",
      "title": "Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure, Information exposure, and Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56690"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-8595",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana OSS",
      "cwe": "CWE-79",
      "title": "Stored XSS in the table panel (TableNG)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8595"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-61441",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-862",
      "title": "PraisonAI Platform before 0.1.9 Authorization Bypass via Dependencies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61441"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-12123",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.1517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "plugins360",
      "product": "All-in-One Video Gallery",
      "cwe": "CWE-918",
      "title": "All-in-One Video Gallery <= 4.8.5 - Authenticated (Subscriber+) Server-Side Request Forgery via 'vdl' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12123"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-56329",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-436",
      "title": "Capgo - Cross-Tenant Preview Namespace Collision via Non-Bijective Underscore Decoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56329"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-55481",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-79",
      "title": "Snipe-IT: CSS Injection via `header_color` Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55481"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-55452",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-1236",
      "title": "Snipe-IT: CSV formula injection in Activity Report export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55452"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-15320",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00234,
      "epss_percentile": 0.1463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sipeed",
      "product": "PicoClaw",
      "cwe": "CWE-862",
      "title": "Sipeed PicoClaw pico.go rt.ReloadConfig authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15320"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-55461",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-601",
      "title": "Snipe-IT: Open Redirect After User Edit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55461"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-56668",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-862",
      "title": "ZITADEL: Unauthorized Token Privilege Escalation in OAuth2 Token Exchange",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56668"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-56373",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-416",
      "title": "ImageMagick - Use-After-Free Write in PDB Decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56373"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-38057",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ST Engineering iDirect",
      "product": "Evolution iQ‑Series terminals",
      "cwe": "CWE-352",
      "title": "ST Engineering iDirect iQ-Series Terminals Cross-Site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38057"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-58661",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-770",
      "title": "n8n - Disk Space Exhaustion via Data-Table File Upload Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58661"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-54329",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13498,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-862",
      "title": "Snipe-IT: Cross-Tenant Accessory Injection in Snipe-IT API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54329"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-56667",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.1339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-79",
      "title": "ZITADEL: Stored XSS via Default URI Redirect in Login V2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56667"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-15026",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "carazo",
      "product": "Import and export users and customers",
      "cwe": "CWE-862",
      "title": "Import and export users and customers <= 2.4.0 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via email_template_selected AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15026"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-55883",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tilt-dev",
      "product": "tilt",
      "cwe": "CWE-345",
      "title": "Tilt: Cross-site WebSocket hijacking of the Tilt HUD stream",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55883"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-12685",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "escortwp",
      "cwe": null,
      "title": "EscortWP <= 3.6.2 - Content Deletion via Vendor-Authored Backdoor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12685"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-1946",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.12999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nandhiniwp",
      "product": "GW AI Website Builder",
      "cwe": "CWE-862",
      "title": "GW AI Website Builder <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Settings Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1946"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-15375",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00222,
      "epss_percentile": 0.13042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Call Recording Software",
      "cwe": "CWE-266",
      "title": "Eleveo Call Recording Software LDAP User users_ldap.jsp improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15375"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-56689",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.12797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerFlex Manager",
      "cwe": "CWE-89",
      "title": "Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56689"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-57214",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.12731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rabbitmq",
      "product": "rabbitmq-server",
      "cwe": "CWE-79",
      "title": "RabbitMQ: Stored XSS in RabbitMQ management UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57214"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-60086",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-693",
      "title": "PraisonAI before 4.6.78 Prompt Injection Defense Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60086"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-15321",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0022,
      "epss_percentile": 0.12765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "MyEMS",
      "cwe": "CWE-79",
      "title": "MyEMS Admin Backend svg.py on_post cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15321"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-55516",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00218,
      "epss_percentile": 0.12514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-639",
      "title": "Snipe-IT: Cross-company asset maintenance re-parenting via API update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55516"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-11914",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Composer",
      "cwe": "CWE-20",
      "title": "Composer - Critical - Unsupported - SA-CONTRIB-2026-046",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11914"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-59190",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-639",
      "title": "Grav Admin Plugin — IDOR Privilege Escalation via saveUser()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59190"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-55803",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Drupal core",
      "cwe": "CWE-915",
      "title": "Drupal core - Critical - PHP object injection - SA-CORE-2026-005",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55803"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-55804",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Drupal core",
      "cwe": "CWE-915",
      "title": "Drupal core - Moderately critical - Gadget chain - SA-CORE-2026-006",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55804"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-57994",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phpMyFAQ",
      "product": "phpMyFAQ",
      "cwe": "CWE-200",
      "title": "phpMyFAQ - Information Disclosure of Inactive FAQ Content via Public API Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57994"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-15318",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00214,
      "epss_percentile": 0.12018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sipeed",
      "product": "PicoClaw",
      "cwe": "CWE-285",
      "title": "Sipeed PicoClaw MQTT Channel mqtt.go authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15318"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-15079",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Login Disable",
      "cwe": "CWE-307",
      "title": "Login Disable - Moderately critical - Access bypass - SA-CONTRIB-2026-070",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15079"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-15332",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zhayujie",
      "product": "CowAgent",
      "cwe": "CWE-862",
      "title": "zhayujie CowAgent Message Endpoint channel.py authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15332"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-59794",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-79",
      "title": "In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59794"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-12108",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "looswebstudio",
      "product": "Highlighting Code Block",
      "cwe": "CWE-79",
      "title": "Highlighting Code Block <= 2.2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via 'font_family' Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12108"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-59154",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wekan",
      "product": "wekan",
      "cwe": "CWE-863",
      "title": "Wekan: Checklist direct DDP updates can write checklist data into private boards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59154"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-57230",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openreplay",
      "product": "openreplay",
      "cwe": "CWE-89",
      "title": "OpenReplay: Authenticated ClickHouse SQL injection via session search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57230"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-55806",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.10957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Drupal core",
      "cwe": "CWE-601",
      "title": "Drupal core - Less critical - Cache poisoning and open redirect - SA-CORE-2026-007",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55806"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-13233",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00204,
      "epss_percentile": 0.10708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "OpenAI Provider",
      "cwe": "CWE-918",
      "title": "OpenAI Provider - Moderately critical - Server-side Request Forgery - SA-CONTRIB-2026-053",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13233"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-56664",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-613",
      "title": "ZITADEL: Missing Token Lifecyle Validation (`exp` and `iat`) in JWT IdP Provider",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56664"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-15028",
      "cvss_base": 3.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00203,
      "epss_percentile": 0.10614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-805",
      "title": "Libarchive: heap overflow oob read while parsing a tar archive contains a pax extended header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15028"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-12924",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "arraytics",
      "product": "Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)",
      "cwe": "CWE-79",
      "title": "Eventin <= 4.1.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'etn_faq_content' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12924"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-13710",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jegtheme",
      "product": "Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress",
      "cwe": "CWE-79",
      "title": "Jeg Kit for Elementor <= 3.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'sg_body_description' Parameter via 'jkit_image_box' Shortcode/Widget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13710"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-55476",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-862",
      "title": "Snipe-IT: Unauthorized Asset Request Cancellation via Unguarded cancel_by_admin Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55476"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-41879",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "R-SOFT SERWIS",
      "product": "DMS",
      "cwe": "CWE-328",
      "title": "Weak password hashing in R-SOFT DMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41879"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-55370",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "logto-io",
      "product": "logto",
      "cwe": "CWE-294",
      "title": "Logto: TOTP code can be replayed within the RFC 6238 validity window (one-time use violation)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55370"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-55472",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-863",
      "title": "Snipe-IT: API Location Creation Bypasses FMCS Parent-Child Company Boundary Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55472"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-12955",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wplegalpages",
      "product": "Cookie Banner for GDPR / CCPA – WPLP Cookie Consent",
      "cwe": "CWE-862",
      "title": "Cookie Banner for GDPR / CCPA <= 4.3.6 - Missing Authorization to Authenticated (Subscriber+) Scan Schedule Modification via gcc_save_schedule_scan AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12955"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-55880",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00195,
      "epss_percentile": 0.09533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openreplay",
      "product": "openreplay",
      "cwe": "CWE-639",
      "title": "OpenReplay: Cross-user IDOR in notes and dashboard widgets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55880"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-59180",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00195,
      "epss_percentile": 0.09543,
      "kev": false,
      "kev_due_at": null,
      "vendor": "caronc",
      "product": "apprise",
      "cwe": "CWE-200",
      "title": "Apprise forwards configured auth headers across cross-origin HTTP redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59180"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-15299",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.0937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wealcoder",
      "product": "Animation Addons for Elementor – GSAP Motion Elementor Addons & Website Templates",
      "cwe": "CWE-79",
      "title": "Animation Addons for Elementor <= 2.6.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Weather Widget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15299"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-11915",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Brute force attack protection",
      "cwe": "CWE-307",
      "title": "Brute force attack protection - Critical - Unsupported - SA-CONTRIB-2026-047",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11915"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-55475",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-863",
      "title": "Snipe-IT: Import created_by can be overwritten",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55475"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-54470",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.09068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Unisphere for PowerMax",
      "cwe": "CWE-611",
      "title": "Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54470"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-55479",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.08962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-863",
      "title": "Snipe-IT: Incorrect permission for legacy license checkin API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55479"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-15295",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.09029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dcooney",
      "product": "Ajax Load More – Infinite Scroll, Load More, & Lazy Load",
      "cwe": "CWE-692",
      "title": "Ajax Load More <= 7.0.1 - Authenticated (Administrator+) Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15295"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-56666",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.0895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-287",
      "title": "ZITADEL: Auto-linking by email: IdP-side email verification is not checked",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56666"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-13247",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "logichunt",
      "product": "Logo Slider WP – Responsive Logo Carousel, Logo Gallery & Logo Showcase",
      "cwe": "CWE-79",
      "title": "Logo Slider <= 5.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'lgx_tooltip_position' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13247"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-55890",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08712,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-79",
      "title": "Grav: Stored CSS injection via Markdown image ?style=… reaches MediaObjectTrait::style()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55890"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-15283",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpvividplugins",
      "product": "WPvivid Backup for MainWP",
      "cwe": "CWE-79",
      "title": "WPvivid Backup for MainWP <= 0.9.33 - Authenticated (Admin+) Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15283"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-1667",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cifi",
      "product": "GEO Plugin by Squirrly SEO",
      "cwe": "CWE-862",
      "title": "SEO Plugin by Squirrly SEO <= 14.0.0 - Unauthenticated Arbitrary Post Creation and Stored Cross-Site Scripting via savePost()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1667"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-12276",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "LA-Studio Element Kit for Elementor",
      "cwe": null,
      "title": "LA-Studio Element Kit for Elementor < 1.6.1 - Unauthenticated Open Registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12276"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-10770",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Anti-Spam by CleanTalk",
      "cwe": "CWE-79",
      "title": "Anti-Spam by CleanTalk - Moderately critical - Cross site scripting - SA-CONTRIB-2026-042",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10770"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-13231",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Advanced Content Feedback (aka admin_feedback)",
      "cwe": "CWE-79",
      "title": "Advanced Content Feedback (aka admin_feedback) - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-051",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13231"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-13234",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.0799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "AI (Artificial Intelligence)",
      "cwe": "CWE-79",
      "title": "AI (Artificial Intelligence) - Moderately critical - Information Disclosure / Cross-site Scripting - SA-CONTRIB-2026-054",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13234"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-60091",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-918",
      "title": "PraisonAI before 4.6.78 Unauthenticated SSRF via webhook_url",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60091"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-15083",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "ECA: Event - Condition - Action",
      "cwe": "CWE-915",
      "title": "ECA: Event - Condition - Action - Less critical - Information disclosure - SA-CONTRIB-2026-074",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15083"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2025-30008",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hestiacp",
      "product": "hestiacp",
      "cwe": "CWE-79",
      "title": "HestiaCP < 1.9.5 Stored XSS via DNS Record Management Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-30008"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-55478",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-639",
      "title": "Snipe-IT: Missing object-level authorization in Kits API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55478"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-55885",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07169,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-312",
      "title": "Grav: Admin Backup Zip File Exposes Account Credentials and Configuration Secrets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55885"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-53450",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coturn",
      "product": "coturn",
      "cwe": "CWE-918",
      "title": "Coturn: IPv4-mapped 127.0.0.1 bypasses default loopback peer protection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53450"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-55464",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grokability",
      "product": "snipe-it",
      "cwe": "CWE-79",
      "title": "Snipe-IT: Stored XSS via Markdown custom field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55464"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-21055",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.07001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Bixby",
      "cwe": null,
      "title": "Improper export of android application components in Bixby prior to version 4.0.70.8 allows local attackers to execute arbitrary commands with Bixby privilege.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21055"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-5069",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmanageninja",
      "product": "Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder",
      "cwe": "CWE-863",
      "title": "Fluent Forms <= 6.2.1 - Incorrect Authorization to Authenticated (Subscriber+) Arbitrary Subscription Cancellation via 'subscription_id'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5069"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-56354",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06647,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-79",
      "title": "n8n - Cross-Site Scripting and Open Redirect in Form Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56354"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-56366",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-401",
      "title": "ImageMagick - Memory Leak in META Reader APP1JPEG Error Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56366"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-13237",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "AI Agents",
      "cwe": "CWE-863",
      "title": "AI Agents - Moderately critical - Information disclosure, Access bypass - SA-CONTRIB-2026-057",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13237"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-56665",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-613",
      "title": "ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56665"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-13242",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Geolocation Field",
      "cwe": "CWE-89",
      "title": "Geolocation Field - Critical - SQL Injection - SA-CONTRIB-2026-062",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13242"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-10769",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Commerce Core",
      "cwe": "CWE-79",
      "title": "Commerce Core - Moderately critical - Cross site scripting - SA-CONTRIB-2026-041",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10769"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-15082",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Siteimprove Analytics",
      "cwe": "CWE-79",
      "title": "Siteimprove Analytics - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-073",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15082"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-15084",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "UI Patterns (SDC in Drupal UI)",
      "cwe": "CWE-79",
      "title": "UI Patterns (SDC in Drupal UI) - Moderately critical - Cross site scripting - SA-CONTRIB-2026-075",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15084"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-15085",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "AI SEO/GEO Analyzer",
      "cwe": "CWE-79",
      "title": "AI SEO/GEO Analyzer - Moderately critical - Cross-site Scripting - SA-CONTRIB-2026-076",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15085"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-54919",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.0607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yhirose",
      "product": "cpp-httplib",
      "cwe": "CWE-295",
      "title": "cpp-httplib: TLS certificate chain verification bypassed for IP-literal hosts on Mbed TLS and wolfSSL backends",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54919"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-15146",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU wget",
      "product": "Wget",
      "cwe": null,
      "title": "CVE-2026-15146",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15146"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-58225",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00163,
      "epss_percentile": 0.05977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-ecto",
      "product": "postgrex",
      "cwe": "CWE-89",
      "title": "SQL injection via unescaped dollar-quote in Postgrex.Notifications reconnect replay causes notification denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58225"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-11908",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Tagify",
      "cwe": "CWE-79",
      "title": "Tagify - Moderately critical - Cross-site scripting (XSS) - SA-CONTRIB-2026-043",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11908"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-13232",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00162,
      "epss_percentile": 0.05896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Advanced Content Feedback (aka admin_feedback)",
      "cwe": "CWE-863",
      "title": "Advanced Content Feedback (aka admin_feedback) - Moderately critical - Access bypass / Insecure Direct Object Reference (IDOR) - SA-CONTRIB-2026-052",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13232"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-55808",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Drupal core",
      "cwe": "CWE-79",
      "title": "Drupal core - Moderately critical - Improper validation - SA-CORE-2026-009",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55808"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-11909",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00161,
      "epss_percentile": 0.05762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Examples for Developers",
      "cwe": "CWE-862",
      "title": "Examples for Developers - Moderately critical - Access bypass - SA-CONTRIB-2026-044",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11909"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-13235",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00161,
      "epss_percentile": 0.05762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "AI (Artificial Intelligence)",
      "cwe": "CWE-862",
      "title": "AI (Artificial Intelligence) - Moderately critical - Access bypass - SA-CONTRIB-2026-055",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13235"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-13239",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "WissKI",
      "cwe": "CWE-862",
      "title": "WissKI - Critical - Access bypass - SA-CONTRIB-2026-059",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13239"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-13240",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Paragraphs",
      "cwe": "CWE-862",
      "title": "Paragraphs - Less critical - Access bypass - SA-CONTRIB-2026-060",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13240"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-13241",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Paragraphs",
      "cwe": "CWE-862",
      "title": "Paragraphs - Moderately critical - Access bypass - SA-CONTRIB-2026-061",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13241"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-6440",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sovlix",
      "product": "GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference",
      "cwe": "CWE-352",
      "title": "GoodMeet <= 1.1.8 - Cross-Site Request Forgery to Google Meet Credential Reset via 'goodmeet_reset_google_meet_credential'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6440"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-15301",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "digiblogger",
      "product": "BuddyHolis TableSearch",
      "cwe": "CWE-79",
      "title": "BuddyHolis TableSearch <= 1.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15301"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-56676",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.05134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9router",
      "cwe": "CWE-367",
      "title": "9router: Image prefetch DNS rebinding allows SSRF to internal services",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56676"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-58588",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Drupal Canvas",
      "cwe": "CWE-79",
      "title": "Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-066",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58588"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-56254",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "capacitor-updater",
      "product": "capacitor-updater",
      "cwe": "CWE-320",
      "title": "capacitor-updater - End-to-End Encryption Bypass via Private Key Distribution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56254"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-58587",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Drupal Canvas",
      "cwe": "CWE-79",
      "title": "Drupal Canvas - Moderately critical - Improper validation - SA-CONTRIB-2026-065",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58587"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-3251",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webremium Istanbul Web Design",
      "product": "Mezunum Satiyorum",
      "cwe": "CWE-79",
      "title": "XSS in Webremium's Mezunum Satiyorum",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3251"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-54736",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00147,
      "epss_percentile": 0.04477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phalcon",
      "product": "cphalcon",
      "cwe": "CWE-208",
      "title": "Phalcon: Non-constant-time HMAC verification in `Encryption\\Crypt::decrypt` (timing side-channel)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54736"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-56813",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00146,
      "epss_percentile": 0.04358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-plug",
      "product": "plug",
      "cwe": "CWE-141",
      "title": "Cookie attribute injection in Plug.Conn.Cookies.encode/2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56813"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-13236",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "AI Agents",
      "cwe": "CWE-862",
      "title": "AI Agents - Less critical - Access bypass - SA-CONTRIB-2026-056",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13236"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-60089",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-22",
      "title": "PraisonAI before 1.6.78 Path Traversal via config.toml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60089"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-58589",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "FlowDrop",
      "cwe": "CWE-862",
      "title": "FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-067",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58589"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-58590",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "FlowDrop",
      "cwe": "CWE-862",
      "title": "FlowDrop - Moderately critical - Access bypass - SA-CONTRIB-2026-068",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58590"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-61456",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-79",
      "title": "Grav before 1.0.3 Stored XSS via SVG Upload API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61456"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-55807",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0014,
      "epss_percentile": 0.03877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Drupal core",
      "cwe": "CWE-918",
      "title": "Drupal core - Moderately critical - Server-side request forgery - SA-CORE-2026-008",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55807"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-13238",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.0366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Commerce Realex / Global Payments",
      "cwe": "CWE-863",
      "title": "Commerce Realex / Global Payments - Moderately critical - Access Bypass - SA-CONTRIB-2026-058",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13238"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-58591",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Colorbox",
      "cwe": "CWE-79",
      "title": "Colorbox - Moderately critical - Cross-site scripting - SA-CONTRIB-2026-069",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58591"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-59791",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00135,
      "epss_percentile": 0.03423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "YouTrack",
      "cwe": "CWE-1021",
      "title": "In JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59791"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-41154",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-787",
      "title": "GPU DDK - Incorrect Index Calculation in CMA Cleanup Path of AllocOSPages_Sparse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41154"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-21052",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.03179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Path traversal in SemClipboardService prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system privilege.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21052"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-61437",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-693",
      "title": "PraisonAI before 1.6.78 Remote Code Execution via tools.py",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61437"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-53657",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.0304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lima-vm",
      "product": "lima",
      "cwe": "CWE-276",
      "title": "Lima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53657"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-21043",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Path traversal in Wallpaper service prior to SMR Jul-2026 Release 1 allows local privileged attackers to access files with system server privilege.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21043"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-21049",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Out-of-bounds write in libpadm.so library prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21049"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-7639",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02389,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-459",
      "title": "GPU DDK - Page UAF read in PMMETA_PROTECT heap memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7639"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-34196",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.02018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-416",
      "title": "GPU DDK - UAF read and/or write of arbitrary physical memory due to integer truncation in PMRDevPhysAddrOSMem",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34196"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-15080",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.01998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Ray Enterprise Translation",
      "cwe": "CWE-352",
      "title": "Ray Enterprise Translation - Moderately critical - Cross site request forgery - SA-CONTRIB-2026-071",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15080"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-21042",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Out-of-bounds write in libsavsac.so prior to SMR Jul-2026 Release 1 allows local attackers to execute arbitrary code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21042"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-21057",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Pass",
      "cwe": null,
      "title": "Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bounds memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21057"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-21054",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "InputSharing",
      "cwe": null,
      "title": "Improper export of android application components in InputSharing prior to version 2.7.01.4 allows local attackers to access sharing data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21054"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-55782",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00113,
      "epss_percentile": 0.01669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "M2Team",
      "product": "NanaZip",
      "cwe": "CWE-400",
      "title": "NanaZip: Unbounded memory allocation (DoS) in NanaZip WebAssembly parser via attacker-controlled section/name length fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55782"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-55669",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-346",
      "title": "ZITADEL: Missing Token Audience Validation (`aud`) in JWT IdP Provider",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55669"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-55781",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00112,
      "epss_percentile": 0.01575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "M2Team",
      "product": "NanaZip",
      "cwe": "CWE-400",
      "title": "NanaZip: Unbounded memory allocation (DoS) in NanaZip UFS parser via unvalidated fs_bsize/fs_fsize superblock fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55781"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-55783",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00112,
      "epss_percentile": 0.01575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "M2Team",
      "product": "NanaZip",
      "cwe": "CWE-476",
      "title": "NanaZip: NULL pointer dereference in Extract() of all seven NanaZip custom archive handlers when extracting/testing the whole archive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55783"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-21053",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Email",
      "cwe": null,
      "title": "Improper input validation in Samsung Email prior to version 6.2.13.1 allows local attackers to create arbitrary files within the application sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21053"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-54000",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00108,
      "epss_percentile": 0.0135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "osquery",
      "product": "osquery",
      "cwe": "CWE-122",
      "title": "osquery: Heap buffer overflow in `getProcessCurrentDirectory()` via `processes` table (Windows)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54000"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-54001",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00108,
      "epss_percentile": 0.01349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "osquery",
      "product": "osquery",
      "cwe": "CWE-122",
      "title": "osquery: Heap buffer overflow via `authenticode` table (Windows)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54001"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-45196",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00106,
      "epss_percentile": 0.01247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-280",
      "title": "GPU DDK - Arbitrary GPU register write in rgxfw_hwperf_hw due to unsanitized pointers from host kernel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45196"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-21039",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Improper access control in Settings prior to SMR Jul-2026 Release 1 allows local attackers to configure Theft protection settings.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21039"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-21041",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Improper access control in SamsungSEAgentService prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21041"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-21050",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Improper access control in SmartThingsKit prior to SMR Jul-2026 Release 1 allows local attackers to access sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21050"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-21051",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Incorrect default permissions in WLAN security prior to SMR Jul-2026 Release 1 allows local attackers to configure TencentWifiSecurity settings.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21051"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-21040",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00099,
      "epss_percentile": 0.00935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Improper access control in IAFDService prior to SMR Jul-2026 Release 1 allows local privileged attackers to use the privileged APIs.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21040"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-21056",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00099,
      "epss_percentile": 0.00935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Health",
      "cwe": null,
      "title": "Improper authorization in Samsung Health prior to version 7.00.0.107 allows local attackers to access connected device information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21056"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-21046",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00096,
      "epss_percentile": 0.00828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Time-of-check time-of-use race condition in fabricKeymaster trustlet prior to SMR Jul-2026 Release 1 allows local privileged attackers to execute arbitrary code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21046"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-21044",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00096,
      "epss_percentile": 0.00828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": null,
      "title": "Improper authorization in KnoxGuardManager prior to SMR Jul-2026 Release 1 allows local attackers to bypass the persistence configuration of the application.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21044"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-46388",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.00704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "osquery",
      "product": "osquery",
      "cwe": "CWE-279",
      "title": "osquery: Unprivileged users can temporarily read file carve contents",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46388"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-45203",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00091,
      "epss_percentile": 0.00575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-367",
      "title": "GPU DDK - rgxfw_hwperf_ufo() re-reads psCmdHeader->ui32CmdSize after initial check, TOCTOU",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45203"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-13243",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0009,
      "epss_percentile": 0.00511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Drupal",
      "product": "Salesforce Suite",
      "cwe": "CWE-352",
      "title": "Salesforce Suite - Moderately critical - Cross-site request forgery - SA-CONTRIB-2026-063",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13243"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-52747",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-52747 (owasp-modsecurity ModSecurity). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-53448",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-53448 (coturn). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-53449",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-53449 (coturn). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54063",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54063 (qax-os excelize). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55460",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55460 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55462",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55462 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55466",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55466 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55515",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55515 (grokability snipe-it). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55827",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55827 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56291",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56291 (balbooa.com Balbooa Forms extension for Joomla). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57156",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57156 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57157",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57157 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57158",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57158 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57211",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57211 (rabbitmq-server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57212",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57212 (rabbitmq-server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57213",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57213 (rabbitmq-server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57215",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57215 (rabbitmq-server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57216",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57216 (rabbitmq-server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57217",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57217 (rabbitmq-server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57218",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57218 (rabbitmq-server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57220",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57220 (rabbitmq-server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57221",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57221 (rabbitmq-server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59161",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59161 (qax-os excelize). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59162",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59162 (qax-os excelize). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59193",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59193 (getgrav grav). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
