{
  "day": "2026-07-15",
  "boundary": "UTC calendar day",
  "published_count": 269,
  "by_severity": {
    "CRITICAL": 36,
    "HIGH": 123,
    "MEDIUM": 92,
    "LOW": 17
  },
  "kev_count": 2,
  "exploit_reference_count": 14,
  "awaiting_enrichment_count": 1,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-46817",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.13309,
      "epss_percentile": 0.96082,
      "kev": true,
      "kev_due_at": "2026-07-18",
      "vendor": "Oracle Corporation",
      "product": "Oracle Payments",
      "cwe": "CWE-269",
      "title": "Oracle E-Business Suite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46817"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2023-4346",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00907,
      "epss_percentile": 0.57087,
      "kev": true,
      "kev_due_at": "2026-07-29",
      "vendor": "KNX Association",
      "product": "KNX Protocol Connection Authorization Option 1",
      "cwe": null,
      "title": "KNX Association KNX Protocol Connection Authorization Option 1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-4346"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-30623",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.05952,
      "epss_percentile": 0.92678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP servers via a JSON configuration specifying arbitrary command and args values. LiteLLM executes these values on the host without validation, enabling attackers to run arbitrary operating system commands. Successful exploitation may result in remote code execution with the privileges of the LiteLLM process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30623"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-42533",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.03506,
      "epss_percentile": 0.88238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "NGINX Plus",
      "cwe": "CWE-122",
      "title": "NGINX Map directive and Regex matching vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42533"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-46339",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02395,
      "epss_percentile": 0.82663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9router",
      "cwe": "CWE-78",
      "title": "9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46339"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-35152",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0228,
      "epss_percentile": 0.81752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Fineract",
      "cwe": "CWE-89",
      "title": "Apache Fineract: SQL injection in runreports endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35152"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-30618",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01671,
      "epss_percentile": 0.74914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker can access the publicly exposed MCP management interface and configure an MCP STDIO server with attacker-controlled commands and parameters, resulting in execution of arbitrary commands on the server. Successful exploitation allows arbitrary command execution within the context of the Fay service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-30618"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-58655",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01084,
      "epss_percentile": 0.62591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-94",
      "title": "Grav Flex Objects - Server-Side Template Injection via Dynamic Titles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58655"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-57821",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00844,
      "epss_percentile": 0.55133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Fineract",
      "cwe": "CWE-89",
      "title": "Apache Fineract: Office list: SQL Injection via Subquery in orderBy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57821"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-45793",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00797,
      "epss_percentile": 0.53653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "composer",
      "product": "composer",
      "cwe": "CWE-200",
      "title": "Composer: Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45793"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2025-65720",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00722,
      "epss_percentile": 0.5114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted HTML page.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-65720"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-62312",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00719,
      "epss_percentile": 0.5103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9router",
      "cwe": "CWE-78",
      "title": "9Router: Authenticated RCE via Unvalidated MCP Plugin Arguments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62312"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-60005",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0071,
      "epss_percentile": 0.50706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "NGINX Plus",
      "cwe": "CWE-908",
      "title": "NGINX ngx_http_slice_module vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60005"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-15895",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0063,
      "epss_percentile": 0.47483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "jsii",
      "cwe": "CWE-78",
      "title": "OS command injection in jsii-diff in AWS jsii",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15895"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-12997",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00619,
      "epss_percentile": 0.46995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gravity Forms",
      "product": "Gravity Forms",
      "cwe": "CWE-22",
      "title": "Gravity Forms <= 2.10.4 - Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12997"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-52887",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00593,
      "epss_percentile": 0.45745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocobase",
      "product": "nocobase",
      "cwe": "CWE-89",
      "title": "NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52887"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-49987",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00539,
      "epss_percentile": 0.43075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yamadashy",
      "product": "repomix",
      "cwe": "CWE-88",
      "title": "Repomix: Command Injection (RCE) via `--remote-branch` Argument Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49987"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-26032",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00507,
      "epss_percentile": 0.41203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Ivy",
      "cwe": "CWE-22",
      "title": "Apache Ivy: PackagerResolver path traversal vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26032"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-61443",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00499,
      "epss_percentile": 0.4074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-22",
      "title": "PraisonAI before 1.6.78 Remote Code Execution via SkillTools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61443"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-15583",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00492,
      "epss_percentile": 0.40262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana MCP Server",
      "cwe": "CWE-610",
      "title": "SSRF (confused deputy) in Grafana MCP Server via X-Grafana-URL header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15583"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-20297",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00481,
      "epss_percentile": 0.39586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-22",
      "title": "Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20297"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-14960",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00478,
      "epss_percentile": 0.39399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pegatron Corp.",
      "product": "Tdelo64.sys",
      "cwe": "CWE-269",
      "title": "CVE-2026-14960",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14960"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-59236",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0047,
      "epss_percentile": 0.38845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roskus",
      "product": "Prospero Flow CRM",
      "cwe": "CWE-639",
      "title": "Authorization bypass in Prospero Flow CRM Excel import allows cross-tenant record injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59236"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-56287",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00469,
      "epss_percentile": 0.38784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Fineract",
      "cwe": "CWE-89",
      "title": "Apache Fineract: Boolean SQL Injection in Client Search API (orderBy parameter) leading to Local File Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56287"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-61457",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00464,
      "epss_percentile": 0.38499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-434",
      "title": "Grav before 1.0.3 Remote Code Execution via File Upload Extension Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61457"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-59762",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0046,
      "epss_percentile": 0.38209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "BIG-IP",
      "cwe": "CWE-770",
      "title": "BIG-IP HTTP/2 vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59762"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-56434",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0045,
      "epss_percentile": 0.37606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "NGINX Plus",
      "cwe": "CWE-416",
      "title": "NGINX ngx_http_ssi_module vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56434"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-40501",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CherryHQ",
      "product": "cherry-studio",
      "cwe": "CWE-829",
      "title": "Cherry Studio RCE via SearchService nodeIntegration Misconfiguration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40501"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-49352",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00437,
      "epss_percentile": 0.36557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9router",
      "cwe": "CWE-798",
      "title": "9Router: Hardcoded Default fallback JWT Secret Allows Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49352"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-50148",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00427,
      "epss_percentile": 0.35807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "metabase",
      "product": "metabase",
      "cwe": "CWE-73",
      "title": "Metabase: Remote Code Execution via Snowflake JDBC Driver Arbitrary File Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50148"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-43637",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00425,
      "epss_percentile": 0.35635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PreferredAI",
      "product": "cornac",
      "cwe": "CWE-22",
      "title": "Cornac < 2.6.0 Path Traversal via _extract_archive() in download.py",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43637"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-56398",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-20",
      "title": "Open WebUI - Stored Cross-Site Scripting via OAuth Picture Claim SVG Data URI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56398"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-59235",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00413,
      "epss_percentile": 0.34601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roskus",
      "product": "Prospero Flow CRM",
      "cwe": "CWE-639",
      "title": "Missing authorization in Prospero Flow CRM allows low-privileged users to read all bank accounts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59235"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-51380",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or potentially execute remote code via the /cgi-bin/UploadCfg endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51380"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-59954",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00409,
      "epss_percentile": 0.34242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apolloconfig",
      "product": "apollo",
      "cwe": "CWE-20",
      "title": "Apollo ConfigService access key authentication bypass via appId parsing and non-canonical matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59954"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-59955",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00409,
      "epss_percentile": 0.34242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apolloconfig",
      "product": "apollo",
      "cwe": "CWE-20",
      "title": "Apollo ConfigService access key authentication bypass via raw config file appId parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59955"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-55445",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00404,
      "epss_percentile": 0.33809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "whyour",
      "product": "qinglong",
      "cwe": "CWE-287",
      "title": "Qinglong: Incomplete fix for CVE-2026-3965: Improper Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55445"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-52891",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00403,
      "epss_percentile": 0.33693,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wekan",
      "product": "wekan",
      "cwe": "CWE-78",
      "title": "Wekan: Shell Injection via Avatar Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52891"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-61740",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "LightRAG",
      "cwe": "CWE-287",
      "title": "LightRAG: Authentication bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61740"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-62349",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00401,
      "epss_percentile": 0.33454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "taosdata",
      "product": "TDengine",
      "cwe": "CWE-121",
      "title": "TDengine: Off-by-One Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62349"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-36590",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00401,
      "epss_percentile": 0.33471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An issue in EMQ NanoMQ v.0.24.9 allows a remote attacker to cause a denial of service via the nni_qos_db_set function in broker_tcp.c component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36590"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-62947",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00401,
      "epss_percentile": 0.33454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openwrt",
      "product": "openwrt",
      "cwe": "CWE-22",
      "title": "OpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62947"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-45534",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.32975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-94",
      "title": "DataEase: RCE Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45534"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-10673",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in ADIN2111/ADIN1110 OA SPI Ethernet RX frame reassembly",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10673"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-45738",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "argoproj",
      "product": "argo-cd",
      "cwe": "CWE-79",
      "title": "Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45738"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-58658",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0039,
      "epss_percentile": 0.32285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gpustack",
      "product": "gpustack",
      "cwe": "CWE-306",
      "title": "GPUStack Unauthenticated Information Disclosure via Worker Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58658"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-61613",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00388,
      "epss_percentile": 0.32099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cursor",
      "product": "cursor",
      "cwe": "CWE-306",
      "title": "Cursor: Cloud Agent Browser Sandbox Escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61613"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-46421",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00384,
      "epss_percentile": 0.31734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cap-js",
      "product": "@cap-js/sqlite",
      "cwe": "CWE-506",
      "title": "Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-js/postgres, @cap-js/db-service)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46421"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-61435",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-287",
      "title": "PraisonAI before 4.6.78 Authentication Bypass via Host Header Spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61435"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-13230",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00382,
      "epss_percentile": 0.3151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Kasa EC71 v4",
      "cwe": "CWE-200",
      "title": "Information Disclosure Vulnerability in Local Discovery Response in TP-Link Kasa EC70 and EC71",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13230"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-45804",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00376,
      "epss_percentile": 0.3093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "huggingface",
      "product": "diffusers",
      "cwe": "CWE-367",
      "title": "Diffusers: TOCTOU Trust Remote Code Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45804"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-62350",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "taosdata",
      "product": "TDengine",
      "cwe": "CWE-94",
      "title": "TDengine: UDF lead to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62350"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-47159",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0037,
      "epss_percentile": 0.30269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dani-garcia",
      "product": "vaultwarden",
      "cwe": "CWE-287",
      "title": "Vaultwarden: Authentication Flow Information Disclosure in SSO Discovery Allows Organization Enumeration and Pre-Validation Token Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47159"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-55410",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0037,
      "epss_percentile": 0.30286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocobase",
      "product": "nocobase",
      "cwe": "CWE-78",
      "title": "NocoBase backup restore schema name allows command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55410"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-11851",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00368,
      "epss_percentile": 0.30052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Router",
      "cwe": "CWE-89",
      "title": "Improper Neutralization of Special Elements used in an SQL Command (\"SQL Injection\") in the web management interface of certain ASUS router models allows a remote authenticated user to disclose confidential information via a crafted request that bypasses existing input validation Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11851"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-12382",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.29838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-290",
      "title": "Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12382"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-9770",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.29539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Kasa EC71 v4",
      "cwe": "CWE-321",
      "title": "Hardcoded Cryptographic Key Information Disclosure Vulnerability on TP-Link Kasa EC70 and EC71",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9770"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-61371",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-59",
      "title": "Microsoft AVML before 0.17.0 could follow a symlink when opening a destination output path on Unix, allowing truncation/overwrite of the symlink target. The destructive effect is performed at open-time via O_TRUNC, and can happen before full input validation completes (“truncation-before-validation”).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61371"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-45737",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00359,
      "epss_percentile": 0.29124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "argoproj",
      "product": "argo-cd",
      "cwe": "CWE-200",
      "title": "Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45737"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-62948",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.28995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openwrt",
      "product": "openwrt",
      "cwe": "CWE-79",
      "title": "OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62948"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-26719",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00356,
      "epss_percentile": 0.28852,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a crafted HTTP GET request containing a malicious script",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26719"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-55652",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00355,
      "epss_percentile": 0.28745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wekan",
      "product": "wekan",
      "cwe": "CWE-287",
      "title": "Wekan: Header-login IP allowlist bypass via X-Forwarded-For spoofing in Wekan allows unauthenticated full account takeover (incl. admin)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55652"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-58660",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.28753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kanboard",
      "product": "kanboard",
      "cwe": "CWE-639",
      "title": "Kanboard BoardAjaxController Missing Ownership Check via Drag-and-Drop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58660"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-56400",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00348,
      "epss_percentile": 0.27953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-webui",
      "product": "open-webui",
      "cwe": "CWE-613",
      "title": "open-webui - Remote Code Execution via CORS Misconfiguration and Session Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56400"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-56349",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00344,
      "epss_percentile": 0.27499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-20",
      "title": "n8n - Guardrail Node Bypass via Crafted Input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56349"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-20146",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0034,
      "epss_percentile": 0.27136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco Identity Services Engine Software",
      "cwe": "CWE-22",
      "title": "Cisco Identity Services Engine Path Traversal Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20146"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-61427",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00338,
      "epss_percentile": 0.26878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-20",
      "title": "PraisonAI before 4.6.78 Authentication Bypass via HTTP-stream",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61427"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-62378",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00332,
      "epss_percentile": 0.26201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rustfs",
      "product": "console",
      "cwe": "CWE-79",
      "title": "RustFS Console: Critical Stored XSS in Preview Modal leading to Administrative Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62378"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-49279",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "WWBN AVideo: Stored XSS via autoEvalCodeOnHTML Bypass in MessageSQLite WebSocket Handler (CVE-2026-43874 Bypass)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49279"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-58659",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.25532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lightning-AI",
      "product": "pytorch-lightning",
      "cwe": "CWE-470",
      "title": "PyTorch Lightning Arbitrary Code Execution via _instantiator Hyperparameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58659"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-45806",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.2552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "penpot",
      "product": "penpot",
      "cwe": "CWE-918",
      "title": "Penpot: Authenticated SSRF in remote image import via create-file-media-object-from-url",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45806"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-52890",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wekan",
      "product": "wekan",
      "cwe": "CWE-22",
      "title": "Wekan: Arbitrary file read and server DoS via attachment versions.original.path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52890"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-56679",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9router",
      "cwe": "CWE-915",
      "title": "9Router: Mass assignment in PATCH /api/settings allows authenticated authorization downgrade",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56679"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-62351",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "taosdata",
      "product": "TDengine",
      "cwe": "CWE-125",
      "title": "TDengine: Unauthenticated Remote Denial of Service via Out-of-Bounds Read in transDecompressMsg",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62351"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-62685",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-647",
      "title": "File Browser: Colliding username normalization gives two users the same home directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62685"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-50124",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-434",
      "title": "DataEase: Remote Code Execution (RCE) via Zip Protocol & File Dropper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50124"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-52869",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.2481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "modelcontextprotocol",
      "product": "python-sdk",
      "cwe": "CWE-639",
      "title": "MCP Python SDK: HTTP transports serve session requests without verifying the authenticated principal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52869"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-58077",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weeblr.com",
      "product": "4Analytics extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58077"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-57833",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weeblr.com",
      "product": "4Analytics extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57833"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-59258",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.24274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "immich-app",
      "product": "immich",
      "cwe": "CWE-863",
      "title": "immich < 3.0.3 Shared Album Editor Ownership Takeover via updateUser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59258"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-59259",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00315,
      "epss_percentile": 0.24354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-639",
      "title": "n8n - Permission Bypass via Expression Parser Mismatch in External Secrets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59259"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-45419",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.24091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-22",
      "title": "DataEase: Arbitrary File Write Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45419"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-45533",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.24091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-22",
      "title": "DataEase: Path Traversal Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45533"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-40957",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Absolute Security",
      "product": "Secure Access",
      "cwe": "CWE-1021",
      "title": "Frameable content vulnerability in the Secure Access server login page",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40957"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-15804",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MetaGuru",
      "product": "HCM",
      "cwe": "CWE-89",
      "title": "MetaGuru｜HCM - SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15804"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-13585",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "System Control Interface v3",
      "cwe": "CWE-226",
      "title": "Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a Denial of Service (DoS) on the system. Refer to the ' Security Update for ASUS System Control Interface ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13585"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-61736",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00305,
      "epss_percentile": 0.23221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HKUDS",
      "product": "LightRAG",
      "cwe": "CWE-942",
      "title": "LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61736"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-46485",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lissy93",
      "product": "dashy",
      "cwe": "CWE-15",
      "title": "Dash: Users can write to config despire permissions (OIDC tested)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46485"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2025-32781",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00304,
      "epss_percentile": 0.23116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apolloconfig",
      "product": "apollo",
      "cwe": "CWE-639",
      "title": "Apollo: Apollo Portal release endpoint allows cross-application configuration disclosure via releaseId",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-32781"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-54458",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.23046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "AVideo: Unauthenticated Stored DOM Cross-Site Scripting via Per-Client Metadata Broadcast in YPTSocket Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54458"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-52893",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00302,
      "epss_percentile": 0.22828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wekan",
      "product": "wekan",
      "cwe": "CWE-287",
      "title": "Wekan: OIDC Account Takeover via Unconditional Email-Based Account Merge in onCreateUser hook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52893"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-48795",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "adonisjs",
      "product": "core",
      "cwe": "CWE-1321",
      "title": "Incomplete fix for CVE-2026-25754 in @adonisjs/bodyparser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48795"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-8919",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "GameSDK",
      "cwe": "CWE-942",
      "title": "Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a crafted web page that sends a request containing a UNC path to the application’s local service endpoint. This can result in information disclosure or data tampering, may cause GameSDK to become unavailable, and may also enable access to the victim’s information on other services. Refer to the ' Security Update for ASUS GameSDK ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8919"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-55576",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.22384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MaaAssistantArknights",
      "product": "MaaAssistantArknights",
      "cwe": "CWE-78",
      "title": "MaaAssistantArknights: PR-title expression injection in release-preparation.yml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55576"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-61684",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "labring",
      "product": "FastGPT",
      "cwe": "CWE-798",
      "title": "FastGPT: Unauthenticated cross-tenant data access via forgeable plugin-invoke JWT (default INVOKE_TOKEN_SECRET='token')",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61684"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-63175",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22097,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lookyloo",
      "product": "PlaywrightCapture",
      "cwe": "CWE-613",
      "title": "Cross-Capture Session Data Leakage Due to Shared Mutable State in Looklyloo - PlaywrightCapture",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63175"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-55723",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.21859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "NGINX Ingress Controller",
      "cwe": "CWE-76",
      "title": "NGINX Ingress Controller vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55723"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-61436",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.21561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-287",
      "title": "PraisonAI before 4.6.78 Missing Webhook Signature Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61436"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-46459",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ICU Scandinavia",
      "product": "Boomerang",
      "cwe": "CWE-862",
      "title": "Missing Authorization in ICU Scandinavia Boomerang",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46459"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-52865",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "NGINX Ingress Controller",
      "cwe": "CWE-476",
      "title": "NGINX Ingress Controller vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52865"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-53446",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.21215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wekan",
      "product": "wekan",
      "cwe": "CWE-918",
      "title": "Wekan: Server-Side Request Forgery (SSRF) via webhook integration URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53446"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-44986",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "penpot",
      "product": "penpot",
      "cwe": "CWE-287",
      "title": "Penpot: Pre-authenticated account takeover via team-invitation token + prepare-register-profile",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44986"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-56339",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cap-go",
      "product": "capgo",
      "cwe": "CWE-203",
      "title": "Capgo - Unauthenticated Organization Existence Enumeration via rescind_invitation RPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56339"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-61836",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "directus",
      "product": "directus",
      "cwe": "CWE-524",
      "title": "Directus: Authorization-dependent response served from unsegmented cache key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61836"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-47164",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dani-garcia",
      "product": "vaultwarden",
      "cwe": "CWE-284",
      "title": "Vaultwarden: SSO Email Auto-Link Can Bind an Existing Local Account to an Attacker-Controlled IdP Identity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47164"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-62314",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19312,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TecharoHQ",
      "product": "anubis",
      "cwe": "CWE-284",
      "title": "Anubis: Policy bypass via client controlled X-Original-URI header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62314"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-45320",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-89",
      "title": "DataEase Data Dashboard SqlVariable transFilter Unfiltered SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45320"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-50030",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-89",
      "title": "DataEase: Arbitrary SQL execution in preview path (direct data disclosure)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50030"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-52888",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nocobase",
      "product": "nocobase",
      "cwe": "CWE-184",
      "title": "NocoBase: Sensitive Data Exposure via SQL Blacklist Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52888"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-49867",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-79",
      "title": "DataEase: Authenticated Stored XSS in DataEase Template Static Resources",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49867"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-12512",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Quotes llama",
      "cwe": "CWE-89",
      "title": "Quotes Llama < 3.1.6 - Unauthenticated SQL Injection via sc Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12512"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-20153",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco RoomOS Software",
      "cwe": "CWE-20",
      "title": "Cisco RoomOS Security Hardening Release - Input Validation Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20153"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-20158",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco RoomOS Software",
      "cwe": "CWE-664",
      "title": "Cisco RoomOS Security Hardening Release - Resource Lifetime Management Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20158"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-20187",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco RoomOS Software",
      "cwe": "CWE-703",
      "title": "Cisco RoomOS Security Hardening Release - Exceptional Conditions Handling Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20187"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-59254",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-639",
      "title": "n8n - External Secrets Disclosure via Workflow Node Expressions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59254"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-60065",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.18517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "NGINX Plus",
      "cwe": "CWE-125",
      "title": "NGINX Plus ngx_stream_mqtt_filter_module vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60065"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-62843",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-22",
      "title": "File Browser: Archive builder turns backslash filenames into path traversal (zip-slip)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62843"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-52892",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wekan",
      "product": "wekan",
      "cwe": "CWE-862",
      "title": "Wekan: Read-only board members can create/modify/delete Custom Fields (privilege escalation via read-level authz on write ops)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52892"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-33444",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Absolute Secutity",
      "product": "Secure Access",
      "cwe": "CWE-119",
      "title": "Memory management vulnerability in Secure Access servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33444"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-9007",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL Notes",
      "cwe": "CWE-79",
      "title": "Reflected XSS in HCL Notes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9007"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-20156",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00256,
      "epss_percentile": 0.17355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco RoomOS Software",
      "cwe": "CWE-119",
      "title": "Cisco RoomOS Security Hardening Release - Buffer Management Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20156"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-61873",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-73",
      "title": "Grav before 9.1.8 Arbitrary File Write via Twig-Processed Filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61873"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-15907",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "H3C",
      "product": "SecPath F1000-C8300",
      "cwe": "CWE-74",
      "title": "H3C SecPath F1000-C8300 g=log_fw_nbc_mail_jsondata sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15907"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-49997",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-285",
      "title": "SurrealDB: Edge PERMISSIONS FOR delete bypassed when a connected node is deleted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49997"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-45150",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.16992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zen-browser",
      "product": "desktop",
      "cwe": "CWE-451",
      "title": "Zen Browser - Missing Fullscreen Security Notification Allows Origin Spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45150"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-45535",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-89",
      "title": "DataEase: Stored SQL Injection Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45535"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-61646",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.16467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "labring",
      "product": "FastGPT",
      "cwe": "CWE-918",
      "title": "FastGPT: Shared axios SSRF guard validates only the initial URL before following redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61646"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-56352",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.16485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-22",
      "title": "n8n - Arbitrary File Read and Execution via ExecuteWorkflow localFile Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56352"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-54560",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cloudreve",
      "product": "cloudreve",
      "cwe": "CWE-863",
      "title": "Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54560"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-61449",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-409",
      "title": "Grav before 2.0.2 Decompression Bomb via Forged ZIP Size",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61449"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-62353",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "taosdata",
      "product": "TDengine",
      "cwe": "CWE-125",
      "title": "TDengine: Authenticated Out-of-Bounds Read in SQL Lexer tGetToken",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62353"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-57996",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phpMyFAQ",
      "product": "phpMyFAQ",
      "cwe": "CWE-269",
      "title": "phpMyFAQ - Privilege Escalation via Missing SuperAdmin Guard in user/add Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57996"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-59255",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SpecterOps",
      "product": "BloodHound",
      "cwe": "CWE-862",
      "title": "BloodHound Missing Authorization on Custom Node Management API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59255"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-61451",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00244,
      "epss_percentile": 0.15878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-601",
      "title": "Grav before 1.0.4 Password Reset Token Poisoning via admin_base_url",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61451"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-15746",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Amazon",
      "product": "strands-agents-tools",
      "cwe": "CWE-918",
      "title": "Credential disclosure in Strands Agents Tools elasticsearch_memory tool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15746"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-54562",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cloudreve",
      "product": "cloudreve",
      "cwe": "CWE-918",
      "title": "Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54562"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-55234",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wekan",
      "product": "wekan",
      "cwe": "CWE-284",
      "title": "Wekan: Broken access control: any authenticated user can move their Cards/Lists/Swimlanes into a private board they are not a member of (cross-board write via collection allow rule)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55234"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-61644",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "labring",
      "product": "FastGPT",
      "cwe": "CWE-863",
      "title": "FastGPT: /api/core/chat/record/getCollectionQuote can disclose cross-tenant dataset text due to an unbound initialId lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61644"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-46458",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ICU Scandinavia",
      "product": "Boomerang",
      "cwe": "CWE-522",
      "title": "Credential exposure in ICU Scandinavia Boomerang",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46458"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-60085",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-273",
      "title": "PraisonAI before 4.6.78 Unenforced Security Policy in Subprocess Sandbox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60085"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-53517",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "better-auth",
      "product": "better-auth",
      "cwe": "CWE-362",
      "title": "Better Auth OAuth Provider: Refresh Token Rotation Race Condition Allows Concurrent Replay and Token Family Forking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53517"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-62361",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15292,
      "kev": false,
      "kev_due_at": null,
      "vendor": "knadh",
      "product": "listmonk",
      "cwe": "CWE-89",
      "title": "listmonk: SQL Injection in `/api/subscribers/export` bypasses table access control, leaking admin password hashes and SMTP credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62361"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-53444",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wekan",
      "product": "wekan",
      "cwe": "CWE-269",
      "title": "Wekan: Missing authorization on OIDC Meteor methods allows privilege escalation to admin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53444"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-53445",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wekan",
      "product": "wekan",
      "cwe": "CWE-862",
      "title": "Wekan: Authorization bypass in copyBoard DDP method allows any user to copy private boards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53445"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-53515",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "better-auth",
      "product": "better-auth",
      "cwe": "CWE-269",
      "title": "Better Auth: Privilege escalation via SSO provider registration: missing admin role check in @better-auth/sso",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53515"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-57831",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "digital-peak.com",
      "product": "DP Calendar extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57831"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-57832",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomdonation.com",
      "product": "EDocman extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57832"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-11579",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.15043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Kali Forms — Contact Form & Drag-and-Drop Builder",
      "cwe": "CWE-434",
      "title": "Kali Forms < 2.4.17 - Unauthenticated Media Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11579"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-20150",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco RoomOS Software",
      "cwe": "CWE-284",
      "title": "Cisco RoomOS Security Hardening Release - Access Control Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20150"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-33445",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Absolute Security",
      "product": "Secure Access",
      "cwe": "CWE-400",
      "title": "Memory management vulnerability in Secure Access servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33445"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-52870",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "modelcontextprotocol",
      "product": "python-sdk",
      "cwe": "CWE-862",
      "title": "MCP Python SDK: Experimental task handlers allow any client to access and cancel other clients' tasks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52870"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-38754",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BusyBox",
      "product": "BusyBox",
      "cwe": "CWE-125",
      "title": "A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38754"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-61835",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "directus",
      "product": "directus",
      "cwe": "CWE-918",
      "title": "Directus: SSRF Protection Bypass via 0.0.0.0 in File Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61835"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-61871",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-401",
      "title": "ImageMagick before 7.1.2-26 Memory Leak in ICON decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61871"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-12281",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Shibboleth",
      "cwe": "CWE-287",
      "title": "Shibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Identity Header Spoofing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12281"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-49353",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9router",
      "cwe": "CWE-290",
      "title": "9Router: Local-Only Access Gate Bypass in 9router via Host Header SpoofING",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49353"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-20298",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-200",
      "title": "Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20298"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-53447",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wekan",
      "product": "wekan",
      "cwe": "CWE-639",
      "title": "Wekan: `cloneBoard` Meteor method has no authorization check — any user can clone (read) any private board by ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53447"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-56353",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n",
      "product": "n8n",
      "cwe": "CWE-287",
      "title": "n8n - Authentication Bypass in Chat Trigger Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56353"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-47160",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dani-garcia",
      "product": "vaultwarden",
      "cwe": "CWE-918",
      "title": "Vaultwarden: Server-side request forgery (SSRF) via Icon Endpoint Decimal/Hex/Octal IP Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47160"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-45805",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.13907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "penpot",
      "product": "penpot",
      "cwe": "CWE-749",
      "title": "Penpot: MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45805"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-20296",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.13994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Splunk",
      "product": "Splunk Enterprise",
      "cwe": "CWE-352",
      "title": "SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20296"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-53518",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.13988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "better-auth",
      "product": "better-auth",
      "cwe": "CWE-362",
      "title": "Better Auth OAuth Provider: Race Condition in Authorization Code Exchange Enables Multi-Use Code Redemption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53518"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-56764",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.1399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hono",
      "product": "Hono",
      "cwe": "CWE-208",
      "title": "Hono - Timing Attack in basicAuth and bearerAuth Middleware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56764"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-54443",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lissy93",
      "product": "dashy",
      "cwe": "CWE-80",
      "title": "Dashy: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54443"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-54052",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00228,
      "epss_percentile": 0.13848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "czlonkowski",
      "product": "n8n-mcp",
      "cwe": "CWE-639",
      "title": "n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54052"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-41580",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stirling-Tools",
      "product": "Stirling-PDF",
      "cwe": "CWE-79",
      "title": "Stirling-PDF: Reflected XSS through crafted PDF metadata fields (Title and Author)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41580"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-45417",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-89",
      "title": "DataEase: SQL injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45417"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-46709",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eugeny",
      "product": "tabby",
      "cwe": "CWE-77",
      "title": "Tabby: Drag-and-drop path injection still allows RCE via shell command substitution (incomplete fix for CVE-2026-45038)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46709"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-15921",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00225,
      "epss_percentile": 0.13398,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nvm-sh",
      "product": "nvm",
      "cwe": "CWE-22",
      "title": "nvm path traversal via a malicious mirror's LTS codename writes outside the alias directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15921"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-26718",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00224,
      "epss_percentile": 0.13289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-352",
      "title": "A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized modifications to Glue IDE shell scripts. The affected endpoint lacks proper CSRF token validation and accepts arbitrary HTTP methods via a permissive request mapping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26718"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-14251",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00223,
      "epss_percentile": 0.13143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift GitOps",
      "cwe": "CWE-862",
      "title": "Gitops-operator: gitops-operator: missing allowednamespace check in reconcilerhook for clusterrole/role cases enables potential privilege escalation and dos",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14251"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-40958",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00223,
      "epss_percentile": 0.13213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Absolute Security",
      "product": "Secure Access",
      "cwe": "CWE-20",
      "title": "Input validation error in Secure Access clients prior to 14.55",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40958"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-61860",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-416",
      "title": "ImageMagick before 7.1.2-26 Use-After-Free via freetype",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61860"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-61868",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-401",
      "title": "ImageMagick before 7.1.2-26 Memory Leak in YUV Decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61868"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-61446",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-94",
      "title": "PraisonAI before 1.6.78 Remote Code Execution via Plugin Auto-Discovery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61446"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-55399",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Absolute Security",
      "product": "Secure Access",
      "cwe": "CWE-400",
      "title": "Resource exhaustion vulnerability in the Secure Access publisher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55399"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-53512",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00213,
      "epss_percentile": 0.11863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "better-auth",
      "product": "better-auth",
      "cwe": "CWE-287",
      "title": "Better Auth: OAuth refresh-token replay via missing client authentication on oidc-provider and mcp plugins",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53512"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-33443",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.11951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Absolute Security",
      "product": "Secure Access",
      "cwe": "CWE-400",
      "title": "Memory management error in Secure Access servers prior to 14.55",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33443"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-61440",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.11947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-862",
      "title": "PraisonAI Platform before 0.1.9 Authorization Bypass via Label Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61440"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-55398",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Absolute Security",
      "product": "Secure Access",
      "cwe": "CWE-119",
      "title": "Memory management vulnerability in Secure Access clients",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55398"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-62348",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11399,
      "kev": false,
      "kev_due_at": null,
      "vendor": "taosdata",
      "product": "TDengine",
      "cwe": "CWE-862",
      "title": "TDengine: KILL SSMIGRATE missing authorization lets low-privilege users interrupt shared-storage migrations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62348"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-33684",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-862",
      "title": "AVideo's Privilege AVideo: Escalation via Unguarded Permission Parameters in signUp API Allows Self-Granting Upload/Stream/Meet Permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33684"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-38752",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00207,
      "epss_percentile": 0.11117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BusyBox",
      "product": "BusyBox",
      "cwe": "CWE-674",
      "title": "A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38752"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-38755",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00207,
      "epss_percentile": 0.11117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BusyBox",
      "product": "BusyBox",
      "cwe": "CWE-674",
      "title": "A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38755"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-61430",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.10842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-918",
      "title": "PraisonAI before 1.6.78 DNS Rebinding SSRF via web_crawl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61430"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-61438",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-78",
      "title": "PraisonAI before 4.6.78 Remote Code Execution via Broken AST Sandbox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61438"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-60062",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "F5",
      "product": "NGINX Agent",
      "cwe": "CWE-22",
      "title": "NGINX Agent Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60062"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-40954",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00201,
      "epss_percentile": 0.10331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Absolute Security",
      "product": "Secure Access",
      "cwe": "CWE-191",
      "title": "Integer underflow in Secure Access clients prior to 14.55",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40954"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-40955",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00201,
      "epss_percentile": 0.10331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Absolute Security",
      "product": "Secure Access",
      "cwe": "CWE-191",
      "title": "Integer underflow vulnerability in Secure Access clients",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40955"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-50147",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.002,
      "epss_percentile": 0.10148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "metabase",
      "product": "metabase",
      "cwe": "CWE-88",
      "title": "Metabase: Arbitrary File Read via MySQL Connection Property Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50147"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-49988",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yamadashy",
      "product": "repomix",
      "cwe": "CWE-200",
      "title": "Repomix: attach_packed_output can bypass file-read secret scanning for supported local files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49988"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-62683",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00198,
      "epss_percentile": 0.09953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "filebrowser",
      "product": "filebrowser",
      "cwe": "CWE-863",
      "title": "File Browser: Trailing-slash delete leaves a stale public share behind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62683"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-38974",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.0953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-295",
      "title": "Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38974"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-61452",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-613",
      "title": "Grav before 2.0.4 Improper Session Invalidation JWT Access Tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61452"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-46684",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00193,
      "epss_percentile": 0.09383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dataease",
      "product": "dataease",
      "cwe": "CWE-347",
      "title": "DataEase: Unauthorized Command Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46684"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-53513",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00189,
      "epss_percentile": 0.08879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "better-auth",
      "product": "better-auth",
      "cwe": "CWE-20",
      "title": "Better Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53513"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-60087",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-863",
      "title": "PraisonAI before 1.6.78 Tool Approval Cache Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60087"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-11580",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Kali Forms — Contact Form & Drag-and-Drop Builder",
      "cwe": "CWE-639",
      "title": "Kali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11580"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-61863",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00187,
      "epss_percentile": 0.08709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-401",
      "title": "ImageMagick before 7.1.2-26 Memory Leak in TIFF Encoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61863"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-61866",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00187,
      "epss_percentile": 0.08709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-401",
      "title": "ImageMagick before 7.1.2-26 Memory Leak in JNG encoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61866"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-54563",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cloudreve",
      "product": "cloudreve",
      "cwe": "CWE-863",
      "title": "Cloudreve: Path Traversal / Broken Access Control in Cloudreve WebDAV (`/dav`) — scoped DAV credential escapes its configured account root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54563"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-33213",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getredash",
      "product": "redash",
      "cwe": "CWE-601",
      "title": "Redash: Open redirect vulnerability in post-login redirect handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33213"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-50182",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "AVideo Has Unauthenticated Reflected XSS via $_GET['search'] in YouTubeAPI Gallery Pagination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50182"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-52843",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00174,
      "epss_percentile": 0.07128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lightpanda-io",
      "product": "browser",
      "cwe": "CWE-346",
      "title": "Lightpanda: fetch() and XMLHttpRequest attach session cookies to cross-origin requests regardless of credentials mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52843"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-1563",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pegasystems",
      "product": "Pega Infinity",
      "cwe": "CWE-79",
      "title": "Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1563"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-1562",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.0709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pegasystems",
      "product": "Pega Infinity",
      "cwe": "CWE-79",
      "title": "Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1562"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-56742",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cilium",
      "product": "cilium",
      "cwe": "CWE-862",
      "title": "Cilium: Namespaced HTTPRoutes can redirect traffic to other namespaces",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56742"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-56678",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9router",
      "cwe": "CWE-20",
      "title": "9Router: Kiro region injection allows authenticated SSRF with Authorization header forwarding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56678"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-40956",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00171,
      "epss_percentile": 0.06866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Absolute Security",
      "product": "Secure Access",
      "cwe": "CWE-200",
      "title": "Memory disclosure in Secure Access Clients",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40956"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-15809",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.0607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Confidential Compute Attestation",
      "cwe": "CWE-134",
      "title": "Github.com/cri-o/cri-o: fix bypass for cve-2022-4318 — /etc/passwd injection via home env",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15809"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-48799",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitroomhq",
      "product": "postiz-app",
      "cwe": "CWE-345",
      "title": "Postiz: Unauthenticated arbitrary lifetime PRO grant via Nowpayments webhook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48799"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-55608",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "czlonkowski",
      "product": "n8n-mcp",
      "cwe": "CWE-200",
      "title": "n8n-MCP: Incorrect authorization can expose default-scope workflow version backups in multi-tenant HTTP mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55608"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-50183",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-79",
      "title": "WWBN AVideo: Stored XSS via Hostile YouTube Video Title in AVideo YouTubeAPI Gallery Section",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50183"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-52842",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00161,
      "epss_percentile": 0.05819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lightpanda-io",
      "product": "browser",
      "cwe": "CWE-346",
      "title": "Lightpanda:URL parser misidentifies page origin for URLs containing @ in the path - Same-Origin Policy bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52842"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-47158",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dani-garcia",
      "product": "vaultwarden",
      "cwe": "CWE-352",
      "title": "Vaultwarden: CSRF in SSO Authorization Flow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47158"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-56743",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.0553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cilium",
      "product": "cilium",
      "cwe": "CWE-863",
      "title": "Cilium may unexpectedly allow ingress traffic from the local namespace when a Kubernetes NetworkPolicy is configured with an ipBlock match",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56743"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-61453",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-79",
      "title": "Grav before 2.0.1 XSS via Twig String Concatenation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61453"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-61643",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.0512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "labring",
      "product": "FastGPT",
      "cwe": "CWE-863",
      "title": "FastGPT: workflow runtime can execute another user's private HTTP toolset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61643"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-53516",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.0489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "better-auth",
      "product": "better-auth",
      "cwe": "CWE-287",
      "title": "Better Auth: Account takeover via OAuth auto-link to unverified pre-registered email",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53516"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-50562",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00151,
      "epss_percentile": 0.04774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "labring",
      "product": "FastGPT",
      "cwe": "CWE-266",
      "title": "FastGPT: Untrusted PR artifacts are pushed and deployed by privileged preview workflows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50562"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-59950",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "modelcontextprotocol",
      "product": "python-sdk",
      "cwe": "CWE-346",
      "title": "MCP Python SDK: WebSocket server transport does not support Host/Origin validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59950"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-14961",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pegatron Corp.",
      "product": "Tdelo64.sys",
      "cwe": "CWE-20",
      "title": "CVE-2026-14961",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14961"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-56087",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.0423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ThinOS 10",
      "cwe": "CWE-693",
      "title": "Dell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism Failure vulnerability. An attacker with physical access could potentially exploit this vulnerability, leading to unauthorized access to encrypted data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56087"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-38753",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BusyBox",
      "product": "BusyBox",
      "cwe": "CWE-416",
      "title": "A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted AWK script.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38753"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-61433",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00144,
      "epss_percentile": 0.04156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MervinPraison",
      "product": "PraisonAI",
      "cwe": "CWE-94",
      "title": "PraisonAI before 4.6.78 Code Injection via API deployment generator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61433"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-59838",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fortinet",
      "product": "FortiSIEM",
      "cwe": "CWE-80",
      "title": "A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.2.0 through 7.2.6, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versions, FortiSIEM 6.6 all versions, FortiSIEM 6.5 all versions, FortiSIEM 6.4 all versions may allow attacker to execute unauthorized code or commands via <insert attack vector here>",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59838"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-13385",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00142,
      "epss_percentile": 0.0405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Router",
      "cwe": "CWE-295",
      "title": "An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(MITM) user to make the router download and execute arbitrary command via a spoofed server. Refer to the ' Security Update for ASUS Router Firmware ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13385"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-42936",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.03984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SBI SECURITIES Co.,Ltd.",
      "product": "HYPER SBI 2",
      "cwe": "CWE-427",
      "title": "The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected installer, arbitrary code may be executed with the privilege of the user invoking the installer.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42936"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-58559",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.04009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "Harmony OS",
      "cwe": "CWE-789",
      "title": "DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58559"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-45337",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.03875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "better-auth",
      "product": "better-auth",
      "cwe": "CWE-285",
      "title": "Better Auth: Device authorization approve and deny accept any authenticated session while the user code is pending",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45337"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-53514",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "better-auth",
      "product": "better-auth",
      "cwe": "CWE-287",
      "title": "Better Auth: Unauthorized invitation acceptance via unverified email match in organization plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53514"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-62355",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03637,
      "kev": false,
      "kev_due_at": null,
      "vendor": "taosdata",
      "product": "TDengine",
      "cwe": "CWE-269",
      "title": "TDengine: Standard User permission unexpect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62355"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-55242",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00136,
      "epss_percentile": 0.03539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "erpnext",
      "cwe": "CWE-863",
      "title": "ERPNext: Server-Side Template Injection (SSTI) in Batch autonaming via Stock Settings.naming_series_prefix",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55242"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-15029",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "System Control Interface v3",
      "cwe": "CWE-822",
      "title": "Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced memory protections. Refer to the ' Security Update for ASUS System Control Interface ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15029"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-49445",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cilium",
      "product": "cilium",
      "cwe": "CWE-732",
      "title": "Cilium: Sensitive information disclosure and cluster disruption via local Envoy admin socket access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49445"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-61859",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-59",
      "title": "ImageMagick before 7.1.2-26 Policy Bypass via script operation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61859"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-47703",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.0241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AdguardTeam",
      "product": "AdGuardHome",
      "cwe": "CWE-330",
      "title": "AdGuard Home: DoQ-to-UDP State Reduction and Source-Port Oracle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47703"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-15030",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "System Control Interface v3",
      "cwe": "CWE-125",
      "title": "Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation. Refer to the ' Security Update for ASUS System Control Interface ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15030"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-56375",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.0152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-401",
      "title": "ImageMagick - Memory Leak in ASHLAR Coder Action Failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56375"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-40633",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerScale OneFS",
      "cwe": "CWE-532",
      "title": "Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40633"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-45313",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00108,
      "epss_percentile": 0.01377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sandboxie-plus",
      "product": "Sandboxie",
      "cwe": "CWE-284",
      "title": "Sandboxie-Plus: Sandboxie APC Injection Sandbox Escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45313"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-50144",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00108,
      "epss_percentile": 0.01374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tencent",
      "product": "ncnn",
      "cwe": "CWE-20",
      "title": "ncnn: Out-of-bounds heap write in ParamDict::load_param via unchecked negative parameter id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50144"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-20157",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00107,
      "epss_percentile": 0.01309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cisco",
      "product": "Cisco RoomOS Software",
      "cwe": "CWE-311",
      "title": "Cisco RoomOS Security Hardening Release - Missing Encryption Vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20157"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-61828",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.01305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NixOS",
      "product": "nixpkgs",
      "cwe": "CWE-276",
      "title": "nixos/mysql : `services.mysql` is configured with insecure authentication by default when used with `mysql` or `percona-server`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61828"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-49501",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00105,
      "epss_percentile": 0.01238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerScale OneFS",
      "cwe": "CWE-269",
      "title": "Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Privilege Management vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49501"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-61862",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00105,
      "epss_percentile": 0.01217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-125",
      "title": "ImageMagick before 7.1.2-26 Information Disclosure via identify",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61862"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-56687",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00104,
      "epss_percentile": 0.01192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "ThinOS 10",
      "cwe": "CWE-448",
      "title": "Dell ThinOS 10, versions prior to 2605_10.2100, contain an Obsolete Feature in UI vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56687"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-15779",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.01186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-732",
      "title": "Samba-winbind: samba: pam_winbind mkhomedir chowns critical system paths without validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15779"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-61864",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00102,
      "epss_percentile": 0.01074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-401",
      "title": "ImageMagick before 7.1.2-26 Memory Leak in Log Colorspace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61864"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-61865",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00102,
      "epss_percentile": 0.01074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-401",
      "title": "ImageMagick before 7.1.2-26 Memory Leak in Hough Lines",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61865"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-61867",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00102,
      "epss_percentile": 0.01073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-401",
      "title": "ImageMagick before 7.1.2-26 Memory Leak in TIFF Encoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61867"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-61869",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00102,
      "epss_percentile": 0.01074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-401",
      "title": "ImageMagick before 7.1.2-26 Memory Leak in MIFF Encoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61869"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-62294",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.01027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flameshot-org",
      "product": "flameshot",
      "cwe": "CWE-362",
      "title": "Flameshot: OCTOU symlink attack via predictable /tmp path in Flameshot \"Open With\"",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62294"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-8920",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.001,
      "epss_percentile": 0.0096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Aura Wallpaper Service",
      "cwe": "CWE-73",
      "title": "Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file operations by sending crafted commands containing an arbitrary file path and bypassing the service’s path restrictions . On specific models , this can also cause a single feature to become unavailable . Refer to the ' Security Update for Aura Wallpaper Service ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8920"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-61872",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00096,
      "epss_percentile": 0.0081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-401",
      "title": "ImageMagick before 7.1.2-26 Memory Leak via TIFF Encoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61872"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-40952",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00094,
      "epss_percentile": 0.0068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Absolute Security",
      "product": "Secure Access",
      "cwe": "CWE-276",
      "title": "Privilge misconfiguration in Secure Access installers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40952"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-61464",
      "cvss_base": 1,
      "cvss_severity": "LOW",
      "epss_score": 0.00092,
      "epss_percentile": 0.0059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-122",
      "title": "ImageMagick before 7.1.2-26 Heap Buffer Over-Write via X11",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61464"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-58549",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00089,
      "epss_percentile": 0.00478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-120",
      "title": "Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58549"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-58550",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00089,
      "epss_percentile": 0.00478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-120",
      "title": "Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58550"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-58553",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00089,
      "epss_percentile": 0.00477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-120",
      "title": "Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58553"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-58551",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00088,
      "epss_percentile": 0.00455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-120",
      "title": "Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58551"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-58552",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00088,
      "epss_percentile": 0.00455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-120",
      "title": "Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58552"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-58558",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00084,
      "epss_percentile": 0.00324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "Harmony OS",
      "cwe": "CWE-840",
      "title": "Permission control vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect service confidentiality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58558"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-58555",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0008,
      "epss_percentile": 0.00217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-264",
      "title": "Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58555"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-58556",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0008,
      "epss_percentile": 0.00192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "Harmony OS",
      "cwe": "CWE-264",
      "title": "Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58556"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-58554",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00077,
      "epss_percentile": 0.00133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-200",
      "title": "Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58554"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-40953",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00073,
      "epss_percentile": 0.00067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Absolute Security",
      "product": "Secure Access",
      "cwe": "CWE-787",
      "title": "Heap overflow in Secure Access clients",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40953"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-58557",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0007,
      "epss_percentile": 0.00047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Huawei",
      "product": "HarmonyOS",
      "cwe": "CWE-701",
      "title": "Design defect vulnerability in Expedition mode. Impact: Successful exploitation of this vulnerability may affect availability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58557"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10673",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10673 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41580",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41580 (Stirling-Tools Stirling-PDF). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45737",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45737 (argoproj argo-cd). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45738",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45738 (argoproj argo-cd). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45804",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45804 (huggingface diffusers). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46709",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46709 (Eugeny tabby). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47703",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47703 (AdguardTeam AdGuardHome). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49987",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49987 (yamadashy repomix). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49988",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49988 (yamadashy repomix). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56398",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56398 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56400",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56400 (open-webui). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-62947",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-62947 (openwrt). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-62948",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-62948 (openwrt). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
