{
  "day": "2026-07-12",
  "boundary": "UTC calendar day",
  "published_count": 63,
  "by_severity": {
    "CRITICAL": 3,
    "HIGH": 17,
    "MEDIUM": 20,
    "LOW": 23
  },
  "kev_count": 0,
  "exploit_reference_count": 4,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-15511",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.02624,
      "epss_percentile": 0.84255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Comfast",
      "product": "CF-WR631AX V3",
      "cwe": "CWE-77",
      "title": "Comfast CF-WR631AX V3 FastCGI Backend webmgnt system_wl_upload_pic_file os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15511"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-15481",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.01563,
      "epss_percentile": 0.73277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trendnet",
      "product": "TEW-635BRM",
      "cwe": "CWE-74",
      "title": "Trendnet TEW-635BRM IPoA WAN Connection Setup rc ipoa_test command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15481"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-15495",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01543,
      "epss_percentile": 0.72944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicCloudOrg",
      "product": "sonic-agent",
      "cwe": "CWE-77",
      "title": "SonicCloudOrg sonic-agent Android WebSocket Server AndroidWSServer.java os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15495"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-15496",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01158,
      "epss_percentile": 0.64553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicCloudOrg",
      "product": "sonic-agent",
      "cwe": "CWE-77",
      "title": "SonicCloudOrg sonic-agent Groovy Script GroovyScriptImpl.java evalIsFailed os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15496"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-15485",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01072,
      "epss_percentile": 0.62249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TEW-821DAP",
      "cwe": "CWE-77",
      "title": "TRENDnet TEW-821DAP DNS Lookup tools_nslookup sub_43F2C4 os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15485"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-15486",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01072,
      "epss_percentile": 0.62249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TEW-821DAP",
      "cwe": "CWE-77",
      "title": "TRENDnet TEW-821DAP Firmware Update tools_ddns sub_42026C os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15486"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-15487",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01072,
      "epss_percentile": 0.62248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TEW-821DAP",
      "cwe": "CWE-77",
      "title": "TRENDnet TEW-821DAP Firmware Update system_ntp sub_41FBD0 os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15487"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-15513",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01067,
      "epss_percentile": 0.62115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wavlink",
      "product": "WL-NU516U1",
      "cwe": "CWE-77",
      "title": "Wavlink WL-NU516U1 adm.cgi wlink_uci_set_value os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15513"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-61876",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00851,
      "epss_percentile": 0.55349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openwrt",
      "product": "luci",
      "cwe": "CWE-79",
      "title": "LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61876"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-59260",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00714,
      "epss_percentile": 0.5084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openwrt",
      "product": "luci",
      "cwe": "CWE-269",
      "title": "OpenWrt luci-app-samba4 read ACL remote code execution via smbd",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59260"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-58596",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0048,
      "epss_percentile": 0.39518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-822",
      "title": "Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58596"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-15483",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00472,
      "epss_percentile": 0.39031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TEW-821DAP",
      "cwe": "CWE-119",
      "title": "TRENDnet TEW-821DAP ssi tools_nslookup sub_41EC14 buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15483"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-15484",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00472,
      "epss_percentile": 0.39031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TRENDnet",
      "product": "TEW-821DAP",
      "cwe": "CWE-119",
      "title": "TRENDnet TEW-821DAP ssi tools_nslookup sub_41EC14 buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15484"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-15480",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00472,
      "epss_percentile": 0.39032,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trendnet",
      "product": "TEW-635BRM",
      "cwe": "CWE-119",
      "title": "Trendnet TEW-635BRM Web Service rc start_httpd stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15480"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-10666",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00454,
      "epss_percentile": 0.37815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-121",
      "title": "Stack buffer overflow in `net_ipaddr_parse()` IPv4 address-with-port parsing in `subsys/net/ip/utils.c`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10666"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-10665",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00442,
      "epss_percentile": 0.36953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Heap buffer overflow on WireGuard receive path via unbounded incoming packet length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10665"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-56260",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00421,
      "epss_percentile": 0.35319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crawl4AI",
      "product": "Crawl4AI",
      "cwe": "CWE-22",
      "title": "Crawl4AI - Arbitrary File Write via output_path Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56260"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-15497",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00394,
      "epss_percentile": 0.327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SonicCloudOrg",
      "product": "sonic-agent",
      "cwe": "CWE-74",
      "title": "SonicCloudOrg sonic-agent JWT Authentication Filter ExchangeController.java code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15497"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-15491",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00383,
      "epss_percentile": 0.3165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RafyMrX",
      "product": "TOKO-ONLINE-ROTI",
      "cwe": "CWE-287",
      "title": "RafyMrX TOKO-ONLINE-ROTI missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15491"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-56271",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00376,
      "epss_percentile": 0.30878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flowise",
      "product": "Flowise",
      "cwe": "CWE-321",
      "title": "Flowise - Weak Default JWT Secrets in Authentication Middleware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56271"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-56238",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00368,
      "epss_percentile": 0.29995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-200",
      "title": "Capgo - Unauthenticated Information Disclosure via PostgREST global_stats Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56238"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-15488",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.24215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hcr707305003",
      "product": "shiroiAdmin",
      "cwe": "CWE-284",
      "title": "hcr707305003 shiroiAdmin FileController.php upload unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15488"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-56259",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23464,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crawl4AI",
      "product": "Crawl4AI",
      "cwe": "CWE-200",
      "title": "Crawl4AI - LLM Credential Exfiltration via base_url and Environment Variable Resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56259"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-61875",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openwrt",
      "product": "luci",
      "cwe": "CWE-79",
      "title": "luci-app-upnp Stored XSS via UPnP Port Mapping Description",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61875"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-15479",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00284,
      "epss_percentile": 0.20972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "H3C",
      "product": "NX15",
      "cwe": "CWE-640",
      "title": "H3C NX15 Administrator Password Modification Endpoint modify change_passwd password recovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15479"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-56313",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-285",
      "title": "Capgo - Cross-Organization Account Disruption via SSO Prelink Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56313"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-15482",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.19864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aster Telecom",
      "product": "Azcall",
      "cwe": "CWE-74",
      "title": "Aster Telecom Azcall HTTP sis.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15482"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-15489",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.19862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RafyMrX",
      "product": "TOKO-ONLINE-ROTI",
      "cwe": "CWE-74",
      "title": "RafyMrX TOKO-ONLINE-ROTI login.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15489"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-15490",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RafyMrX",
      "product": "TOKO-ONLINE-ROTI",
      "cwe": "CWE-74",
      "title": "RafyMrX TOKO-ONLINE-ROTI add.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15490"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-15492",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00263,
      "epss_percentile": 0.18344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "igweze",
      "product": "wizgrade",
      "cwe": "CWE-79",
      "title": "igweze wizgrade studentConductManager.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15492"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-15498",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.1714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sergomanov",
      "product": "SmartHomeAdatum",
      "cwe": "CWE-74",
      "title": "sergomanov SmartHomeAdatum Login users.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15498"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-15514",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.1714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Metasoft 美特软件",
      "product": "MetaCRM",
      "cwe": "CWE-74",
      "title": "Metasoft 美特软件 MetaCRM PHPRPC Remote Call rpc.jsp RPCService.query sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15514"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-56308",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.15915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-640",
      "title": "Capgo - Insufficient Authentication in Email Change Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56308"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-10664",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in nRF70 Wi-Fi driver power-save event handler (unbounded TWT flow count)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10664"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-15512",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00228,
      "epss_percentile": 0.13771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pig-mesh",
      "product": "Pig",
      "cwe": "CWE-74",
      "title": "pig-mesh Pig pig-codegen GeneratorServiceImpl.java code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15512"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-56241",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-285",
      "title": "Capgo - RBAC Demotion Privilege Retention via Stale org_users.user_right",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56241"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-15500",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11438,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AstrBotDevs",
      "product": "AstrBot",
      "cwe": "CWE-918",
      "title": "AstrBotDevs AstrBot market_list Endpoint plugin.py get_online_plugins server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15500"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-15471",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00207,
      "epss_percentile": 0.11162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Call Recording Software",
      "cwe": "CWE-266",
      "title": "Eleveo Call Recording Software pci_dss_status.jsp improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15471"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-15472",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00207,
      "epss_percentile": 0.11162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Call Recording Software",
      "cwe": "CWE-266",
      "title": "Eleveo Call Recording Software composeEmailAction.do improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15472"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-15474",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00207,
      "epss_percentile": 0.11163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Call Recording Software",
      "cwe": "CWE-266",
      "title": "Eleveo Call Recording Software audio.jsp improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15474"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-15501",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00206,
      "epss_percentile": 0.10936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AstrBotDevs",
      "product": "AstrBot",
      "cwe": "CWE-918",
      "title": "AstrBotDevs AstrBot MCP Test Endpoint tools.py ToolsRoute.test_mcp_connection server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15501"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-15507",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00206,
      "epss_percentile": 0.10934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coollabsio",
      "product": "Coolify",
      "cwe": "CWE-862",
      "title": "coollabsio Coolify Policy Policies authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15507"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-15508",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00206,
      "epss_percentile": 0.10931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Helicone",
      "product": "ai-gateway",
      "cwe": "CWE-918",
      "title": "Helicone ai-gateway AWS Metadata Service service.rs build_target_url server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15508"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-15509",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00206,
      "epss_percentile": 0.10931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Leantime",
      "cwe": "CWE-266",
      "title": "Leantime JSON-RPC Endpoint addUser improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15509"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-15510",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00206,
      "epss_percentile": 0.10935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "Leantime",
      "cwe": "CWE-266",
      "title": "Leantime API saveSetting improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15510"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-56336",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-200",
      "title": "Capgo - Information Disclosure via Unauthenticated SSO check-domain Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56336"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-15477",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00205,
      "epss_percentile": 0.10789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bahmni",
      "product": "bahmnicore",
      "cwe": "CWE-74",
      "title": "Bahmni bahmnicore Search Endpoint sql additionalParams sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15477"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-15494",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00202,
      "epss_percentile": 0.10446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AMTT",
      "product": "Hotel Broadband Operation System",
      "cwe": "CWE-74",
      "title": "AMTT Hotel Broadband Operation System switch_status.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15494"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-15473",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00201,
      "epss_percentile": 0.10394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eleveo",
      "product": "Call Recording Software",
      "cwe": "CWE-266",
      "title": "Eleveo Call Recording Software Recorded Calls restoreCallAction.do improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15473"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-15499",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00201,
      "epss_percentile": 0.10397,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AstrBotDevs",
      "product": "AstrBot",
      "cwe": "CWE-266",
      "title": "AstrBotDevs AstrBot Scheduled Task cron_tools.py FutureTaskTool.call improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15499"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-61874",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00198,
      "epss_percentile": 0.09953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-863",
      "title": "filebrowser before 2.63.17 Stale Public Share via Trailing-Slash Delete",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61874"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-56281",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-89",
      "title": "Capgo - SQL Injection via Unvalidated limit Parameter in Admin Stats Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56281"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-15502",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AojiaoZero",
      "product": "Antaris",
      "cwe": "CWE-74",
      "title": "AojiaoZero Antaris PayPal IPN Payment ipn.php _rewardPurchase sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15502"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-15478",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00196,
      "epss_percentile": 0.09748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "IceHRM",
      "cwe": "CWE-74",
      "title": "IceHRM UserReport Endpoint EmployeeAttendanceReport.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15478"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-15505",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00195,
      "epss_percentile": 0.09572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vnotex",
      "product": "vnote",
      "cwe": "CWE-79",
      "title": "vnotex vnote YAML Frontmatter markdownit.js cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15505"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-15493",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Akpali9",
      "product": "Attendance-Management-System",
      "cwe": "CWE-79",
      "title": "Akpali9 Attendance-Management-System absent.php cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15493"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-56252",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00169,
      "epss_percentile": 0.06668,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Capgo",
      "product": "Capgo",
      "cwe": "CWE-863",
      "title": "Capgo - Scope Isolation Failure in Webhook Test Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56252"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-10663",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-416",
      "title": "Use-after-free / double-free of the root USB device in the experimental USB host stack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10663"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-10668",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-400",
      "title": "Host-triggerable control-endpoint wedge (DoS) in Nuvoton NuMaker HSUSBD UDC driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10668"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-10667",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.04878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-416",
      "title": "SMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable from unprivileged user threads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10667"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-15506",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00141,
      "epss_percentile": 0.03933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SecureAge",
      "product": "CatchPulse",
      "cwe": "CWE-119",
      "title": "SecureAge CatchPulse Driver saappctl.sys heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15506"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-15476",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00106,
      "epss_percentile": 0.01242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QILING",
      "product": "Disk Master",
      "cwe": "CWE-266",
      "title": "QILING Disk Master Kernel Driver diskbckp.sys access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15476"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-15475",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00105,
      "epss_percentile": 0.01225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MiniTool",
      "product": "Partition Wizard",
      "cwe": "CWE-266",
      "title": "MiniTool Partition Wizard Signed Kernel Driver pwdrvio.sys access control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15475"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10664",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10664 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10665",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10665 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10666",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10666 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10667",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10667 (zephyrproject zephyr). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
