{
  "day": "2026-07-16",
  "boundary": "UTC calendar day",
  "published_count": 248,
  "by_severity": {
    "CRITICAL": 38,
    "HIGH": 96,
    "MEDIUM": 101,
    "LOW": 12
  },
  "kev_count": 2,
  "exploit_reference_count": 23,
  "awaiting_enrichment_count": 1,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-39808",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.9121,
      "epss_percentile": 0.99801,
      "kev": true,
      "kev_due_at": "2026-07-19",
      "vendor": "Fortinet",
      "product": "FortiSandbox",
      "cwe": null,
      "title": "Fortinet FortiSandbox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39808"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-25089",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.73603,
      "epss_percentile": 0.99427,
      "kev": true,
      "kev_due_at": "2026-07-19",
      "vendor": "Fortinet",
      "product": "FortiSandbox",
      "cwe": "CWE-78",
      "title": "Fortinet FortiSandbox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25089"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-59865",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0319,
      "epss_percentile": 0.87072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "kiota",
      "cwe": "CWE-94",
      "title": "Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59865"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-55173",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.02162,
      "epss_percentile": 0.80761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-78",
      "title": "AVideo incomplete fix for CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sink",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55173"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-59867",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.01921,
      "epss_percentile": 0.78272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "kiota",
      "cwe": "CWE-22",
      "title": "Kiota: Generation-time SSRF + remote/local file inclusion via unrestricted $ref",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59867"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-44596",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01729,
      "epss_percentile": 0.75738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yamcs",
      "product": "yamcs",
      "cwe": "CWE-307",
      "title": "Yamcs: No Rate Limiting on Authentication Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44596"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-47729",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01503,
      "epss_percentile": 0.72269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "squid-cache",
      "product": "squid",
      "cwe": "CWE-125",
      "title": "Squid: Memory disclosure in FTP gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47729"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-59861",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01471,
      "epss_percentile": 0.71685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "kiota",
      "cwe": "CWE-94",
      "title": "Kiota: Code Generation Literal Injection in Kiota Ruby Generator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59861"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-63305",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01383,
      "epss_percentile": 0.69985,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-78",
      "title": "AVideo through 29.0 OS Command Injection via ffmpeg.json.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63305"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-50012",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01364,
      "epss_percentile": 0.69597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "squid-cache",
      "product": "squid",
      "cwe": "CWE-20",
      "title": "Squid: Memory corruption in cache_digest reply handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50012"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-59866",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01355,
      "epss_percentile": 0.69402,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "kiota",
      "cwe": "CWE-22",
      "title": "Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59866"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-63304",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01355,
      "epss_percentile": 0.69396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-78",
      "title": "AVideo through 29.0 OS Command Injection via listFFmpegProcesses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63304"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-59864",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01275,
      "epss_percentile": 0.67615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "kiota",
      "cwe": "CWE-22",
      "title": "Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59864"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-44632",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0117,
      "epss_percentile": 0.64914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yamcs",
      "product": "yamcs",
      "cwe": "CWE-94",
      "title": "Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44632"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-59863",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01123,
      "epss_percentile": 0.63649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "kiota",
      "cwe": "CWE-22",
      "title": "Kiota: Workspace-config poisoning: out-of-repo file write + generation-time SSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59863"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-53598",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01057,
      "epss_percentile": 0.61798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "prompty",
      "cwe": "CWE-22",
      "title": "Prompty: Arbitrary File Read via ${file:path} Reference Expansion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53598"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-59862",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0102,
      "epss_percentile": 0.60659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "kiota",
      "cwe": "CWE-94",
      "title": "Kiota: Code Generation Literal Injection in the Python Generator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59862"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-59859",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01016,
      "epss_percentile": 0.60575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "kiota",
      "cwe": "CWE-94",
      "title": "Kiota: Code Generation Literal Injection in the PHP Generator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59859"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-59860",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01016,
      "epss_percentile": 0.60574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "kiota",
      "cwe": "CWE-94",
      "title": "Kiota: XML Doc-Comment Newline Breakout Code Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59860"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-46621",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00998,
      "epss_percentile": 0.60008,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yamcs",
      "product": "yamcs",
      "cwe": "CWE-94",
      "title": "Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46621"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-44595",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00984,
      "epss_percentile": 0.59561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yamcs",
      "product": "yamcs",
      "cwe": "CWE-862",
      "title": "Yamcs: Unauthorized user enumeration via IAM API endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44595"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-53597",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00931,
      "epss_percentile": 0.57875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "prompty",
      "cwe": "CWE-94",
      "title": "Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53597"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-54733",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00915,
      "epss_percentile": 0.57357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "o365-moodle",
      "cwe": "CWE-347",
      "title": "moodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54733"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-14890",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00909,
      "epss_percentile": 0.57166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SGLang",
      "product": "SGLang",
      "cwe": "CWE-502",
      "title": "CVE-2026-14890",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14890"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-57206",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00891,
      "epss_percentile": 0.56606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "simplechat",
      "cwe": "CWE-306",
      "title": "SimpleChat plugin validation endpoints missing authentication and authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57206"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-46562",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0078,
      "epss_percentile": 0.53095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yamcs",
      "product": "yamcs",
      "cwe": "CWE-94",
      "title": "Yamcs: Remote Code Execution via Mission Database algorithm override",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46562"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-14371",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00757,
      "epss_percentile": 0.52339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "XClarity Integrator for Microsoft Windows Admin Center",
      "cwe": "CWE-78",
      "title": "The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command Injection when establishing remote PowerShell commands.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14371"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-23538",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00748,
      "epss_percentile": 0.52058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Feast",
      "product": "Feast Feature Server",
      "cwe": "CWE-770",
      "title": "Feast: resource exhaustion via websocket endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23538"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-44181",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00701,
      "epss_percentile": 0.50394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyter-server",
      "product": "enterprise_gateway",
      "cwe": "CWE-1336",
      "title": "Jupyter Enterprise Gateway: Jinja2 Template Server Side Template Injection results in Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44181"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-55440",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0066,
      "epss_percentile": 0.48842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "UFO",
      "cwe": "CWE-400",
      "title": "Microsoft UFO: COMMAND_RESULTS handler creates unowned sessions, allowing authenticated session-squatting denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55440"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-53412",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00647,
      "epss_percentile": 0.4825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zoom Communications",
      "product": "Zoom Workplace for Windows",
      "cwe": "CWE-20",
      "title": "Zoom Workplace VDI Plugin for Windows - Improper Input Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53412"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-15008",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00594,
      "epss_percentile": 0.4579,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uncannyowl",
      "product": "Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin",
      "cwe": "CWE-502",
      "title": "Uncanny Automator <= 7.3.1.4 - Unauthenticated PHP Object Injection to Arbitrary File Deletion via Forminator Submitted-Field Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15008"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-53535",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00574,
      "epss_percentile": 0.4489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "activepieces",
      "product": "activepieces",
      "cwe": "CWE-22",
      "title": "Activepieces: Arbitrary file write in git-sync via path traversal and symlinks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53535"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-47751",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00561,
      "epss_percentile": 0.44248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "anthropics",
      "product": "claude-code-action",
      "cwe": "CWE-78",
      "title": "Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47751"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-44180",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00552,
      "epss_percentile": 0.4377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyter-server",
      "product": "enterprise_gateway",
      "cwe": "CWE-20",
      "title": "Jupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can be Bypassed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44180"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2023-49900",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00536,
      "epss_percentile": 0.42894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "X-Rite",
      "product": "MA-T6",
      "cwe": "CWE-78",
      "title": "Origin Validation Error in X-Rite MA-T6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-49900"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-54568",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00536,
      "epss_percentile": 0.42917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "UFO",
      "cwe": "CWE-639",
      "title": "Microsoft UFO: Missing Authorization in DEVICE_INFO_REQUEST Allows a DEVICE Client to Read Another Device's system_info",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54568"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2024-32386",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00522,
      "epss_percentile": 0.42115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the SNMP update mechanism.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-32386"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-15422",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00508,
      "epss_percentile": 0.41222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "illumos",
      "product": "illumos-gate",
      "cwe": "CWE-122",
      "title": "SCTP needs to better-check INIT ACK chunk parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15422"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-57205",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.005,
      "epss_percentile": 0.40766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microsoft",
      "product": "simplechat",
      "cwe": "CWE-200",
      "title": "SimpleChat: Authenticated users can access other users' profile metadata through user IDOR endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57205"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-44182",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00498,
      "epss_percentile": 0.40678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jupyter-server",
      "product": "enterprise_gateway",
      "cwe": "CWE-74",
      "title": "Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44182"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-1609",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00498,
      "epss_percentile": 0.40666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Keycloak",
      "product": "Keycloak",
      "cwe": "CWE-284",
      "title": "Org.keycloak/keycloak-quarkus-server: keycloak: unauthorized access via jwt authorization grant with disabled users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1609"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-45367",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00489,
      "epss_percentile": 0.40101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hapifhir",
      "product": "org.hl7.fhir.core",
      "cwe": "CWE-1333",
      "title": "HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45367"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-33754",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00485,
      "epss_percentile": 0.39825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-400",
      "title": "Wazuh: Unauthenticated cluster packet length leads to uncontrolled memory allocation (remote DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33754"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-48863",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0047,
      "epss_percentile": 0.38846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSUSE",
      "product": "libsolv",
      "cwe": "CWE-121",
      "title": "Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48863"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-55629",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00456,
      "epss_percentile": 0.3799,
      "kev": false,
      "kev_due_at": null,
      "vendor": "avwo",
      "product": "whistle",
      "cwe": "CWE-22",
      "title": "Whistle: Path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55629"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-44177",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00454,
      "epss_percentile": 0.37871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkirby",
      "product": "kirby",
      "cwe": "CWE-22",
      "title": "Kirby: Pre-authentication path traversal and PHP file inclusion during user lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44177"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-15013",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00448,
      "epss_percentile": 0.37459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cyberlord92",
      "product": "SAML Single Sign On – SSO Login",
      "cwe": "CWE-347",
      "title": "SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15013"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-22752",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00445,
      "epss_percentile": 0.37231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring Security",
      "product": "Spring Authorization Server",
      "cwe": "CWE-287",
      "title": "Spring Security Authorization Server Dynamic Client Registration endpoints perform insufficient validation of client metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22752"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-59117",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00442,
      "epss_percentile": 0.36966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows Terminal App",
      "cwe": "CWE-190",
      "title": "Windows Terminal Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59117"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-15352",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00429,
      "epss_percentile": 0.35977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NASA",
      "product": "Core Flight System (cFS) Health & Safety (HS) Application",
      "cwe": "CWE-476",
      "title": "NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15352"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-45336",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00428,
      "epss_percentile": 0.35883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StratonWebDesigners",
      "product": "HireFlow",
      "cwe": "CWE-798",
      "title": "HireFlow: Use of Hard-coded Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45336"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-63087",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00427,
      "epss_percentile": 0.35796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grafana-cold-storage",
      "product": "oncall",
      "cwe": "CWE-306",
      "title": "Grafana OnCall 1.16.11 Unauthenticated Token Hijack via Plugin Install Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63087"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-55407",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00423,
      "epss_percentile": 0.35485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "anthropics",
      "product": "buffa",
      "cwe": "CWE-400",
      "title": "Buffa: Memory Exhaustion Denial of Service in decode_unknown_field via Unbounded Allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55407"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-57073",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00422,
      "epss_percentile": 0.35387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CODECHILD",
      "product": "HTML::Bare",
      "cwe": "CWE-125",
      "title": "HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57073"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-36425",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00422,
      "epss_percentile": 0.35413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-269",
      "title": "An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send process termination requests without privilege validation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36425"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-57074",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00403,
      "epss_percentile": 0.33666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CODECHILD",
      "product": "XML::Bare",
      "cwe": "CWE-125",
      "title": "XML::Bare versions through 0.53 for Perl have an unbounded character lookahead",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57074"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-3031",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00402,
      "epss_percentile": 0.33533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TOKUHIROM",
      "product": "Image::EPEG",
      "cwe": "CWE-1104",
      "title": "Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3031"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-13397",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00393,
      "epss_percentile": 0.32629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CODECHILD",
      "product": "HTML::Bare",
      "cwe": "CWE-835",
      "title": "HTML::Bare versions through 0.04 for Perl will hang in an infinite loop when parsing malformed attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13397"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-13401",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00388,
      "epss_percentile": 0.32151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CODECHILD",
      "product": "XML::Bare",
      "cwe": "CWE-835",
      "title": "XML::Bare versions through 0.53 for Perl will hang in an infinite loop when parsing malformed attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13401"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2025-71377",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00383,
      "epss_percentile": 0.31626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stoatchat",
      "product": "stoatchat",
      "cwe": "CWE-1025",
      "title": "stoatchat before 20250210-1 Unrestricted Message History Fetch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71377"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-62309",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00377,
      "epss_percentile": 0.30975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coredns",
      "product": "coredns",
      "cwe": "CWE-476",
      "title": "CoreDNS: proxyproto plugin panics on PPv2 datagram with non-UDP transport — single 28-byte packet remote DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62309"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-57075",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00374,
      "epss_percentile": 0.30704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TODDR",
      "product": "YAML::Syck",
      "cwe": "CWE-125",
      "title": "YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57075"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-63085",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axelor",
      "product": "axelor-open-platform",
      "cwe": "CWE-863",
      "title": "Axelor Open Platform 8.x < 8.2.2 Authorization Bypass via Nested Relational Record Persistence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63085"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-63088",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stoatchat",
      "product": "stoatchat",
      "cwe": "CWE-918",
      "title": "stoatchat < 0.14.0 SSRF via DNS-based IP Blocklist Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63088"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-59237",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00369,
      "epss_percentile": 0.30087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roskus",
      "product": "Prospero Flow CRM",
      "cwe": "CWE-639",
      "title": "IDOR in Prospero Flow CRM Order API allows cross-tenant read and modification of orders",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59237"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-54526",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.29519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "argoproj",
      "product": "argo-workflows",
      "cwe": "CWE-284",
      "title": "Argo Workflows: Incomplete fix for CVE-2026-31892: ArtifactGC.PodSpecPatch bypass of Strict/Secure templateReferencing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54526"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2025-45870",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00362,
      "epss_percentile": 0.29493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated user to exploit path traversal flaws in the fileExt parameter, enabling unauthorized access to sensitive files outside the designated directories.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-45870"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-45568",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00361,
      "epss_percentile": 0.29298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openziti",
      "product": "zrok",
      "cwe": "CWE-22",
      "title": "zrok Python ProxyShare can be used as an SSRF proxy through absolute URL paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45568"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-15727",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00355,
      "epss_percentile": 0.28787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xylus",
      "product": "WP Bulk Delete",
      "cwe": "CWE-89",
      "title": "WP Bulk Delete <= 1.4.2 - Authenticated (Administrator+) SQL Injection via 'delete_user_roles' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15727"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-46512",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00352,
      "epss_percentile": 0.28374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mwtcmi",
      "product": "frogman",
      "cwe": "CWE-94",
      "title": "Frogman: Dialplan template parameters interpolated into extensions_custom.conf without escaping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46512"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-45695",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00348,
      "epss_percentile": 0.27958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kopia",
      "product": "kopia",
      "cwe": "CWE-78",
      "title": "Kopia: Unauthenticated RCE via SSH ProxyCommand Injection when --insecure --without-password is used",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45695"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-38158",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00347,
      "epss_percentile": 0.27902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database information via crafted SQL statements.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38158"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-11386",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00342,
      "epss_percentile": 0.27333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "ubuntu-pro-client (ubuntu-advantage-tools)",
      "cwe": "CWE-20",
      "title": "ubuntu-pro-client Input Validation Vulnerability Leading to Arbitrary APT Directive Injection and Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11386"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-45576",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.2721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openziti",
      "product": "zrok",
      "cwe": "CWE-22",
      "title": "zrok copy writes attacker-controlled WebDAV paths outside the destination root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45576"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-15022",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00341,
      "epss_percentile": 0.27204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Tutor LMS – eLearning and online course solution",
      "cwe": "CWE-89",
      "title": "Tutor LMS <= 4.0.0 - Authenticated (Subscriber+) SQL Injection via Stored Quiz Answer Array",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15022"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-45368",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkirby",
      "product": "kirby",
      "cwe": "CWE-79",
      "title": "Kirby: Cross-site scripting (XSS) from links in KirbyTags and image blocks in the site frontend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45368"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-46336",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "manyfold3d",
      "product": "manyfold",
      "cwe": "CWE-22",
      "title": "Manyfold: Authenticated Path Traversal via File Rename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46336"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-62826",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.26081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft SharePoint Enterprise Server 2016",
      "cwe": "CWE-79",
      "title": "Microsoft SharePoint Server Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62826"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-14254",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0033,
      "epss_percentile": 0.25945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Perforce",
      "product": "Delphix Continuous Data",
      "cwe": "CWE-307",
      "title": "Improper Restriction of Excessive Authentication Attempts in Delphix Continuous Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14254"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-46515",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00323,
      "epss_percentile": 0.25227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mwtcmi",
      "product": "frogman",
      "cwe": "CWE-862",
      "title": "Frogman: Multiple read-tier tools expose admin-grade data and arbitrary GraphQL execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46515"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-46686",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "emlog",
      "product": "emlog",
      "cwe": "CWE-79",
      "title": "Emlog Reflected Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46686"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-63086",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.25193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "huggingface",
      "product": "text-generation-inference",
      "cwe": "CWE-918",
      "title": "text-generation-inference 3.3.7 SSRF via fetch_image in multimodal chat completions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63086"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-62299",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00311,
      "epss_percentile": 0.23912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coredns",
      "product": "coredns",
      "cwe": "CWE-476",
      "title": "CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62299"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-15103",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23741,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getwpfunnels",
      "product": "WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell",
      "cwe": "CWE-269",
      "title": "WPFunnels <= 3.12.8 - Authenticated (Funnel Manager+) Privilege Escalation via 'group_id' Path Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15103"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-46338",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0031,
      "epss_percentile": 0.23739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "facelessuser",
      "product": "pymdown-extensions",
      "cwe": "CWE-22",
      "title": "PyMdown Extensions: Regression in pymdownx.snippets reintroduces sibling-prefix path traversal bypass despite restrict_base_path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46338"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-61718",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00306,
      "epss_percentile": 0.23337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bunkerity",
      "product": "bunkerweb",
      "cwe": "CWE-285",
      "title": "bunkerweb: Read-only Web UI users can delete job cache files due to missing authorization on /cache/ routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61718"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-12753",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.2312,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themehunk",
      "product": "Advance Product Search- Voice & Ajax Search for WooCommerce",
      "cwe": "CWE-89",
      "title": "Advance Product Search- Voice & Ajax Search for WooCommerce <= 1.4.4 - Unauthenticated SQL Injection via 's' and 'match' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12753"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-62963",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "centrifugal",
      "product": "centrifugo",
      "cwe": "CWE-409",
      "title": "Centrifugo: Decompression bomb DoS via permessage-deflate in unidirectional WebSocket transport",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62963"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-59249",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00301,
      "epss_percentile": 0.2277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "elixir-mint",
      "product": "mint",
      "cwe": "CWE-444",
      "title": "Sign-tolerant HTTP/1 chunk-size parser in Mint enables response smuggling against strict intermediaries on pooled connections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59249"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-12492",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00299,
      "epss_percentile": 0.22545,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Happy Coders OTP Login for WooCommerce",
      "cwe": "CWE-287",
      "title": "Happy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeover via hcotp_auto_login_user",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12492"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-62994",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00295,
      "epss_percentile": 0.22106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coredns",
      "product": "coredns",
      "cwe": "CWE-248",
      "title": "CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62994"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-44981",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crowdsecurity",
      "product": "crowdsec",
      "cwe": "CWE-409",
      "title": "CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44981"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-46687",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "emlog",
      "product": "emlog",
      "cwe": "CWE-24",
      "title": "Emlog Local File Inclusion (LFI)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46687"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-39359",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-22",
      "title": "Wazuh: Unauthenticated Path Traversal in authd via Agent Group Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39359"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-15651",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jgwhite33",
      "product": "WP TripAdvisor Review Slider",
      "cwe": "CWE-89",
      "title": "WP TripAdvisor Review Slider <= 14.6 - Authenticated (Administrator+) SQL Injection via 'filtersource' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15651"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-15407",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themifyme",
      "product": "Themify Builder",
      "cwe": "CWE-862",
      "title": "Themify Builder <= 7.7.7 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post Stylesheet Write/Delete via tb_generate_on_fly AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15407"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-44023",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docling-project",
      "product": "docling-core",
      "cwe": "CWE-22",
      "title": "Docling Core has unsafe remote filename resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44023"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2025-45868",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to manipulate SQL queries via crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-45868"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-44174",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkirby",
      "product": "kirby",
      "cwe": "CWE-470",
      "title": "Kirby: Arbitrary Method Call via REST API search and collection query endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44174"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-44453",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "h2o",
      "product": "h2o",
      "cwe": "CWE-770",
      "title": "h2o is vulnerable to musl libc stack overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44453"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-54340",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "h2o",
      "product": "h2o",
      "cwe": "CWE-400",
      "title": "h2o has HTTP/2 state amplification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54340"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-44433",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "h2o",
      "product": "quicly",
      "cwe": "CWE-400",
      "title": "Quicly is vulnerable to memory exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44433"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-44435",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "h2o",
      "product": "quicly",
      "cwe": "CWE-400",
      "title": "Quicly: Remote Denial of Service via assertion failure when CRYPTO stream handshake data exceeds 32KB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44435"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-44436",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "h2o",
      "product": "quicly",
      "cwe": "CWE-120",
      "title": "Quicly is vulnerable to connection state corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44436"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2025-71388",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.19931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stoatchat",
      "product": "stoatchat",
      "cwe": "CWE-639",
      "title": "stoatchat 20241213-1 Webhook Token Disclosure via Read Permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71388"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-15106",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.19732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quantumcloud",
      "product": "WPBot – AI ChatBot for Live Support, Lead Generation, AI Services",
      "cwe": "CWE-862",
      "title": "WPBot <= 8.5.6 - Missing Authorization to Unauthenticated Arbitrary Chat Session Deletion via 'userid' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15106"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-15445",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cleverplugins",
      "product": "SEO Booster",
      "cwe": "CWE-89",
      "title": "SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15445"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-15458",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cleverplugins",
      "product": "SEO Booster",
      "cwe": "CWE-89",
      "title": "SEO Booster <= 7.3.1 - Authenticated (Administrator+) SQL Injection via 'sort_field' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15458"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-35147",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "DFXServer",
      "cwe": "CWE-639",
      "title": "HCL DFXServer is affected by a Broken Authentication vulnerability via direct API access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35147"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-45325",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tmlmobilidade",
      "product": "go",
      "cwe": "CWE-1321",
      "title": "Gestor de Oferta: Prototype pollution in @tmlmobilidade/utils setValueAtPath",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45325"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-56455",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "DFXAnalytics",
      "cwe": "CWE-121",
      "title": "HCL DFXAnalytics is affected by a Buffer Overflow vulnerability that can lead to a Denial of Service (DoS).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56455"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-46353",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bigbluebutton",
      "product": "bigbluebutton",
      "cwe": "CWE-284",
      "title": "BigBlueButton API checksum bypass via presentationUploadExternalUrl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46353"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-33692",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-20",
      "title": "AVideo Has Unauthenticated .env File Exposure via Official Docker Compose Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33692"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-33434",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-799",
      "title": "Wazuh: Rate Limit Bypass via /events Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33434"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-21729",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Loki",
      "cwe": "CWE-770",
      "title": "Loki detected_fields query limits results in unbounded memory allocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21729"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-46513",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.18024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mwtcmi",
      "product": "frogman",
      "cwe": "CWE-256",
      "title": "Frogman: API tokens stored in plaintext",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46513"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-46514",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mwtcmi",
      "product": "frogman",
      "cwe": "CWE-532",
      "title": "Frogman: Plaintext passwords and secrets persisted to audit log",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46514"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2024-58360",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stoatchat",
      "product": "stoatchat",
      "cwe": "CWE-1173",
      "title": "stoatchat before 0.7.8 Unrestricted Account Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-58360"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-46351",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bigbluebutton",
      "product": "bigbluebutton",
      "cwe": "CWE-330",
      "title": "BigBlueButton: Insecure Randomness allows to guess user's conference session token and impersonate them",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46351"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-46404",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bigbluebutton",
      "product": "bigbluebutton",
      "cwe": "CWE-918",
      "title": "BigBlueButton: Presentation URL Security Hardening",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46404"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-34150",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-122",
      "title": "Wazuh: Heap buffer overflow in wazuh-analysisd via rootcheck event parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34150"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-44175",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.17126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkirby",
      "product": "kirby",
      "cwe": "CWE-79",
      "title": "Kirby: Cross-site scripting (XSS) from list field content in the site frontend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44175"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-63397",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.17167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "remorses",
      "product": "genql",
      "cwe": "CWE-116",
      "title": "remorses/genql code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63397"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-12941",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wcmp",
      "product": "MultiVendorX – WooCommerce Multivendor Marketplace AI Powered Solutions",
      "cwe": "CWE-89",
      "title": "MultiVendorX <= 5.0.9 - Authenticated (Store Owner+) SQL Injection via 'order_by' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12941"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-44452",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "h2o",
      "product": "h2o",
      "cwe": "CWE-125",
      "title": "h2o is vulnerable to heap overrun",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44452"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-15336",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "catchplugins",
      "product": "Catch Themes Demo Import",
      "cwe": "CWE-862",
      "title": "Catch Themes Demo Import <= 3.3 - Missing Authorization to Authenticated (Subscriber+) Single Plugin Installation via 'activate_plugin' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15336"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-12684",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Customer Reviews for WooCommerce",
      "cwe": "CWE-434",
      "title": "Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr_upload_media",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12684"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-13754",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tickera",
      "product": "Tickera – Sell Tickets & Manage Events",
      "cwe": "CWE-89",
      "title": "Tickera <= 3.6.0.0 - Authenticated (Staff+) SQL Injection via 's' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13754"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-13767",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "expresstech",
      "product": "Quiz and Survey Master (QSM) – Quiz Maker & Survey Maker",
      "cwe": "CWE-89",
      "title": "Quiz and Survey Master (QSM) <= 11.2.0 - Authenticated (Custom+) SQL Injection via 'pages' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13767"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-35149",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "DFXServer",
      "cwe": "CWE-294",
      "title": "HCL DFXServer is affected by an Authentication Bypass vulnerability via server response manipulation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35149"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-13042",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yo35",
      "product": "RPB Chessboard",
      "cwe": "CWE-79",
      "title": "RPB Chessboard <= 8.1.2 - Unauthenticated Stored Cross-Site Scripting via Comment Content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13042"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-55548",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yamcs",
      "product": "yamcs",
      "cwe": "CWE-284",
      "title": "Yamcs: Insecure Direct Object Reference (IDOR) in PacketsApi allows unprivileged users to dump all telemetry packets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55548"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-13741",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UnitedOver",
      "product": "Digits: WordPress Mobile Number Signup and Login",
      "cwe": "CWE-269",
      "title": "Digits: WordPress Mobile Number Signup and Login <= 9.1.0.5 - Authenticated (Subscriber+) Privilege Escalation via 'digits_reg_userrole' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13741"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-63306",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00241,
      "epss_percentile": 0.15556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stoatchat",
      "product": "stoatchat",
      "cwe": "CWE-918",
      "title": "stoatchat before 0.13.5 Unauthenticated SSRF via proxy and embed endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63306"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-56456",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "DFXAnalytics",
      "cwe": "CWE-200",
      "title": "HCL DFXAnalytics is affected by an Internal File Path Disclosure vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56456"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-14782",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "melograno",
      "product": "Booking for Appointments and Events Calendar – Amelia",
      "cwe": "CWE-89",
      "title": "Booking for Appointments and Events Calendar – Amelia <= 2.4.3 - Authenticated (Custom+) SQL Injection via Customer Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14782"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-12434",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fernandobt",
      "product": "List category posts",
      "cwe": "CWE-862",
      "title": "List category posts <= 0.95.0 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via 'post_status' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12434"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-63089",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00238,
      "epss_percentile": 0.1509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wg-easy",
      "product": "wg-easy",
      "cwe": "CWE-338",
      "title": "WireGuard Easy Weak Token Generation Information Disclosure via OTL Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63089"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-58078",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themexpert.com",
      "product": "Quix Page Builder Pro extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58078"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-54728",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bunkerity",
      "product": "bunkerweb",
      "cwe": "CWE-20",
      "title": "bunkerweb: Improper Input Validation and Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in BunkerWeb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54728"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-44970",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dbt-labs",
      "product": "dbt-mcp",
      "cwe": "CWE-201",
      "title": "dbt-mcp: All MCP Tool Arguments Including Raw SQL and --vars Credentials Transmitted to dbt Labs Telemetry by Default Without Redaction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44970"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-44019",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "docling-project",
      "product": "docling-core",
      "cwe": "CWE-73",
      "title": "Docling Core has insufficient validation of image reference URIs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44019"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-58643",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows Admin Center",
      "cwe": "CWE-79",
      "title": "Windows Admin Center Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58643"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-43977",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wger-project",
      "product": "wger",
      "cwe": "CWE-639",
      "title": "wger IDOR: Authenticated Users Can Read Others' Private Workout Session Data via Template Routine API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43977"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-15610",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quantumcloud",
      "product": "WPBot – AI ChatBot for Live Support, Lead Generation, AI Services",
      "cwe": "CWE-862",
      "title": "WPBot <= 8.5.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary RAG Document Re-Sync via ajax_rag_manual_sync() Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15610"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-12525",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.1408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Redux Framework",
      "cwe": "CWE-269",
      "title": "Redux Framework < 4.5.13 - Subscriber+ Privilege Escalation to Administrator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12525"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-12585",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Abandoned Cart Lite for WooCommerce",
      "cwe": "CWE-287",
      "title": "Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleable Recovery-Link Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12585"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-13755",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.1337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tickera",
      "product": "Tickera – Sell Tickets & Manage Events",
      "cwe": "CWE-79",
      "title": "Tickera <= 3.6.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'price_wrapper' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13755"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-15350",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kevp75",
      "product": "The Cache Purger",
      "cwe": "CWE-862",
      "title": "The Cache Purger <= 2.3.20 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Log Deletion via 'the_log_purge' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15350"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-12395",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Job Portal",
      "cwe": "CWE-89",
      "title": "WP Job Portal < 2.5.5 - Subscriber+ SQL Injection via Applied Resumes 'ta' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12395"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-44982",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00217,
      "epss_percentile": 0.1247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "crowdsecurity",
      "product": "crowdsec",
      "cwe": "CWE-693",
      "title": "CrowdSec AppSec silently drops request body for chunked / HTTP-2 requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44982"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-15737",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "bedrock-agentcore",
      "cwe": "CWE-532",
      "title": "Sensitive content disclosure via OpenTelemetry spans in AgentCore Python SDK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15737"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-15306",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rextheme",
      "product": "Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces",
      "cwe": "CWE-79",
      "title": "Product Feed Manager For WooCommerce <= 7.6.1 - Reflected Cross-Site Scripting via 's' Search Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15306"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-44176",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkirby",
      "product": "kirby",
      "cwe": "CWE-862",
      "title": "Kirby: `pages.access` permission is not checked during rendering of page drafts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44176"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-45334",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getkirby",
      "product": "kirby",
      "cwe": "CWE-862",
      "title": "Kirby: Content locks disclose IDs and emails of inaccessible users from `users.access/list` permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45334"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-47084",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cyrusimap",
      "product": "Cyrus IMAP",
      "cwe": "CWE-863",
      "title": "An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-admin user could invoke the admin-only LOCALDELETE IMAP command and delete mailboxes for which they had no permissions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47084"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-43978",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.11907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wger-project",
      "product": "wger",
      "cwe": "CWE-269",
      "title": "wger: Privilege escalation via trainer-login session chaining allows gym trainers to impersonate gym managers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43978"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-15005",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "timwhitlock",
      "product": "Loco Translate",
      "cwe": "CWE-352",
      "title": "Loco Translate <= 2.8.5 - Cross-Site Request Forgery to Remote Code Execution via 'template' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15005"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-15909",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11724,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RafyMrX",
      "product": "TOKO-ONLINE-ROTI",
      "cwe": "CWE-285",
      "title": "RafyMrX TOKO-ONLINE-ROTI add.php authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15909"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2023-49899",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0021,
      "epss_percentile": 0.11583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "X-Rite",
      "product": "MA-T6",
      "cwe": "CWE-346",
      "title": "Origin Validation Error in X-Rite MA-T6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2023-49899"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2024-32389",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-120",
      "title": "Buffer Overflow vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the update URLs component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-32389"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-15324",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phppoet",
      "product": "SysBasics Customize My Account for WooCommerce – Live My Account Customizer",
      "cwe": "CWE-79",
      "title": "SysBasics Customize My Account for WooCommerce <= 4.4.14 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'row_type' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15324"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2024-32385",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.1121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via a boardID and revisionID components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-32385"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-13005",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mxchat",
      "product": "MxChat – AI Chatbot & Content Generation for WordPress",
      "cwe": "CWE-79",
      "title": "MxChat <= 3.2.10 - Authenticated (Admin+) Stored Cross-Site Scripting via 'intro_message' Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13005"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2024-34268",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.10984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-306",
      "title": "EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth connections. This vulnerability allows attackers to gain full access to the device without authentication.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-34268"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-14987",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.10946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stellarwp",
      "product": "GiveWP – Donation Plugin and Fundraising Platform",
      "cwe": "CWE-79",
      "title": "GiveWP <= 4.16.3 - Authenticated (Give Worker+) Stored Cross-Site Scripting via 'twitter_message' Sequoia Template Setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14987"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-15021",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.10946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tomdever",
      "product": "wpForo Forum",
      "cwe": "CWE-79",
      "title": "wpForo Forum <= 3.1.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'location' Profile Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15021"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2024-32387",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the community string component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-32387"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-47085",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cyrusimap",
      "product": "Cyrus IMAP",
      "cwe": "CWE-340",
      "title": "An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim's account for which the victim had never issued an auth URL, they could forge a working URLAUTH token by computing an HMAC-SHA1 value with a predictable key, giving them read access to the mailbox. (URLAUTH is an obscure feature, meaning that the odds of any user actually being susceptible to this attack are very low. Perhaps no public clients use URLAUTH.)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47085"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-12979",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "FunnelKit",
      "cwe": "CWE-73",
      "title": "FunnelKit < 3.15.0.6 - Admin+ Arbitrary File Deletion via Path Traversal in Template Importer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12979"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-15652",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shapedplugin",
      "product": "Easy Accordion – AI-Powered FAQ & Accordion Blocks, Product FAQ",
      "cwe": "CWE-79",
      "title": "Easy Accordion <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'align' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15652"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-47082",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cyrusimap",
      "product": "Cyrus IMAP",
      "cwe": "CWE-863",
      "title": "An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation \"fcc\" feature skips the destination-mailbox ACL. A user whose vacation Sieve script used :fcc (to save a copy of the sent message) could deliver vacation auto-reply copies into any mailbox the script could name, regardless of whether the script owner had insert permissions on the destination mailbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47082"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-47083",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cyrusimap",
      "product": "Cyrus IMAP",
      "cwe": "CWE-204",
      "title": "An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated IMAP user could enumerate folder names under any account they could name. Search would return UIDs of messages matching the search, creating a content oracle (without allowing arbitrary reads of the target's content).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47083"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-15099",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdelicious",
      "product": "WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes)",
      "cwe": "CWE-79",
      "title": "WP Delicious <= 1.10.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'steps' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15099"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-11889",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00192,
      "epss_percentile": 0.09194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SALTO",
      "product": "ProAccess Space",
      "cwe": "CWE-639",
      "title": "SALTO ProAccess Space Authorization Bypass Through User-Controlled Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11889"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-35141",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "DFXAnalytics",
      "cwe": "CWE-294",
      "title": "HCL DFXAnalytics is affected by a Login Replay Attack vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35141"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-47087",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00192,
      "epss_percentile": 0.09233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cyrusimap",
      "product": "Cyrus IMAP",
      "cwe": "CWE-672",
      "title": "An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47087"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-46341",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "apify",
      "product": "apify-mcp-server",
      "cwe": "CWE-20",
      "title": "Apify MCP server: Domain Allowlist Bypass in fetch-apify-docs via String Prefix Matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46341"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-7543",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.09024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Breakdance",
      "product": "Breakdance",
      "cwe": "CWE-79",
      "title": "Breakdance <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting via Webhook Action Details",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7543"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-58598",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.0879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Windows 10 Version 21H2",
      "cwe": "CWE-362",
      "title": "Windows Backup Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58598"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-56453",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00187,
      "epss_percentile": 0.08631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "DFXAnalytics",
      "cwe": "CWE-294",
      "title": "HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56453"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-53536",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "activepieces",
      "product": "activepieces",
      "cwe": "CWE-345",
      "title": "Activepieces: Cross-tenant file download via missing JWT audience check on step-files signed URL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53536"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-35142",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00183,
      "epss_percentile": 0.08242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "DFXAnalytics",
      "cwe": "CWE-200",
      "title": "HCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35142"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-47086",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00179,
      "epss_percentile": 0.07758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cyrusimap",
      "product": "Cyrus IMAP",
      "cwe": "CWE-863",
      "title": "An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint a URLAUTH token (via the GENURLAUTH command) for any mailbox they could name, even without read access on it. This would allow reading mail from mailboxes despite having no granted permissions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47086"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-12906",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00179,
      "epss_percentile": 0.07748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "RTMKit",
      "cwe": "CWE-639",
      "title": "RTMKit Addons for Elementor < 2.0.9 - Contributor+ Private Post Title Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12906"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-47089",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cyrusimap",
      "product": "Cyrus IMAP",
      "cwe": "CWE-862",
      "title": "An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call IMAP LISTRIGHTS against any mailbox they could name and learn what principals had what access to it. (This action should have been restricted to users with admin access on the target mailbox.)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47089"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-47088",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00178,
      "epss_percentile": 0.07623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cyrusimap",
      "product": "Cyrus IMAP",
      "cwe": "CWE-126",
      "title": "An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. An authenticated IMAP user could craft an email message containing an RFC 822 comment ending with a backslash. When parsing the message, the server would read past the message's end in memory, and read into the heap, returning the read content to the user.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47088"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-15945",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00178,
      "epss_percentile": 0.07633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-639",
      "title": "Keycloak-services: keycloak-services: group hierarchy search discloses hidden parent groups under fgap v2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15945"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-15925",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00177,
      "epss_percentile": 0.07542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Snowflake",
      "product": "Snowflake Connector for Python",
      "cwe": "CWE-297",
      "title": "Improper TLS Hostname Verification in Snowflake Connector for Python",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15925"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-49998",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00177,
      "epss_percentile": 0.07553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "centrifugal",
      "product": "centrifugo",
      "cwe": "CWE-347",
      "title": "Centrifugo: Dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49998"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-35145",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00173,
      "epss_percentile": 0.07052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "DFXAnalytics",
      "cwe": "CWE-200",
      "title": "HCL DFXAnalytics is affected by a Missing HTTP Strict-Transport-Security Header vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35145"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-44968",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dbt-labs",
      "product": "dbt-mcp",
      "cwe": "CWE-88",
      "title": "dbt-mcp: Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44968"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-53366",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv4: account for fraggap on the paged allocation path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53366"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-12907",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00168,
      "epss_percentile": 0.06601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "RTMKit",
      "cwe": "CWE-862",
      "title": "RTMKit Addons for Elementor < 2.0.9 - Author+ Site-Wide Theme Builder Template Creation and Activation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12907"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-35148",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "DFXServer",
      "cwe": "CWE-284",
      "title": "HCL DFXServer is affected by a Missing Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35148"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-60073",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AutomationDirect",
      "product": "Productivity Suite",
      "cwe": "CWE-125",
      "title": "AutomationDirect Productivity Suite Out-of-bounds Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60073"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-12978",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06055,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "FunnelKit",
      "cwe": "CWE-79",
      "title": "FunnelKit < 3.15.0.6 - Reflected XSS via Divi Optin Form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12978"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-47081",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00163,
      "epss_percentile": 0.06004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cyrusimap",
      "product": "Cyrus IMAP",
      "cwe": "CWE-863",
      "title": "An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user could probe for the existence of arbitrary mailboxes on other users' accounts via the XAPPLEPUSHSERVICE command and then create Apple Push Notification Service notifications for new mail in those mailboxes to their own APNS device. This did not leak any data about the content of mailboxes. Instead, a \"mailbox has changed\" notice would be pushed when the mailbox modseq changed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47081"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-11371",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "BetterDocs",
      "cwe": "CWE-79",
      "title": "BetterDocs < 4.5.5 - Unauthenticated Stored XSS via AI Doc Summarizer Prompt Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11371"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-35140",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00161,
      "epss_percentile": 0.05835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "DFXAnalytics",
      "cwe": "CWE-200",
      "title": "HCL DFXAnalytics is affected by a Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35140"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-45795",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JanssenProject",
      "product": "jans",
      "cwe": "CWE-347",
      "title": "Janssen Project: JWE Request Object Signature Verification Bypass in jans-auth-server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45795"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-12391",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "ubuntu-pro-client (ubuntu-advantage-tools)",
      "cwe": "CWE-59",
      "title": "ubuntu-pro-client Local Privilege Escalation and Information Disclosure via Symlink Arbitrary File Read in collect-logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12391"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-63082",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ultimate Fosters",
      "product": "Perfect Support Ticketing & Document Management System",
      "cwe": "CWE-862",
      "title": "Perfect Support Ticketing System 1.7 Broken Access Control via Agent Assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63082"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-53409",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.04887,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zoom Communications",
      "product": "Zoom Rooms",
      "cwe": "CWE-20",
      "title": "Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege via local access.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53409"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-12869",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Header Footer Builder for Elementor",
      "cwe": "CWE-79",
      "title": "Header Footer Builder for Elementor < 1.2.1 - Contributor+ Stored XSS via Template Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12869"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-44969",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00148,
      "epss_percentile": 0.04551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dbt-labs",
      "product": "dbt-mcp",
      "cwe": "CWE-532",
      "title": "dbt-mcp: Tool Arguments Including SQL Queries and Credentials Logged in Plaintext Without Redaction When File Logging Is Enabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44969"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-44434",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "h2o",
      "product": "quicly",
      "cwe": "CWE-345",
      "title": "Quicly is vulnerable to stateless reset injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44434"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-6423",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.0423,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ESET, spol. s.r.o.",
      "product": "ESET Inspect Connector",
      "cwe": "CWE-269",
      "title": "Local privilege escalation via unauthenticated ALPC in ESET Inspect Connector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6423"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-12510",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "AI Engine",
      "cwe": "CWE-639",
      "title": "AI Engine < 3.5.5 - Subscriber+Chatbot Discussion Disclosure and Takeover via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12510"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-33731",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-345",
      "title": "AVideo has an Authorize.Net Webhook Signature Bypass that Enables Wallet Balance Inflation via Forged Payment Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33731"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-12379",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.04039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qt",
      "product": "Axivion",
      "cwe": "CWE-601",
      "title": "URL Redirection to Untrusted Site ('Open Redirect') vulnerability in the Dashboard OAuth/OIDC implementation of Axivion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12379"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-57077",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00141,
      "epss_percentile": 0.03949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TODDR",
      "product": "YAML::Syck",
      "cwe": "CWE-125",
      "title": "YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via an unbounded newline scan in newline_len",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57077"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-63081",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ultimate Fosters",
      "product": "Perfect Support Ticketing & Document Management System",
      "cwe": "CWE-79",
      "title": "Perfect Support Ticketing System 1.7 Stored XSS via Ticket Notes Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63081"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-56454",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.03591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "DFXAnalytics",
      "cwe": "CWE-327",
      "title": "HCL DFXAnalytics is affected by a Deprecated Protocol vulnerability due to the use of TLS 1.0 and TLS 1.1.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56454"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-13713",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.03356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TODDR",
      "product": "YAML::Syck",
      "cwe": "CWE-415",
      "title": "YAML::Syck versions before 1.47 for Perl allow a use-after-free and double-free via an anchor node freed while still on the parser value stack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13713"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-13103",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "App Store",
      "cwe": "CWE-22",
      "title": "A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13103"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-53411",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zoom Communications",
      "product": "Zoom Workplace VDI Plugin",
      "cwe": "CWE-20",
      "title": "Zoom Workplace VDI Plugin for Windows - Improper Input Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53411"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-12409",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "umarbajwa",
      "product": "Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages",
      "cwe": "CWE-352",
      "title": "Landing Page Builder <= 1.5.3.6 - Cross-Site Request Forgery to ulpb_admin_data AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12409"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-40106",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.0285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-122",
      "title": "Wazuh: Heap-based Buffer Overflow in syscheck Registry Wildcard Expansion (LPE / DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40106"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-46377",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TomWright",
      "product": "dasel",
      "cwe": "CWE-129",
      "title": "Dasel: Index-out-of-range panic in dasel selector lexer on trailing backslash in quoted string",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46377"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-55406",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "anthropics",
      "product": "buffa",
      "cwe": "CWE-200",
      "title": "Buffa: Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in Deref",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55406"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-5674",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-427",
      "title": "Pipewire: pipewire: sandbox escape and arbitrary code execution via malicious library loading",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5674"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-57076",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TODDR",
      "product": "YAML::Syck",
      "cwe": "CWE-416",
      "title": "YAML::Syck versions before 1.47 for Perl allow a heap use-after-free via an anchor name reused as an anchors-table key in syck_hdlr_add_anchor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57076"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-45612",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rizinorg",
      "product": "rz-libdemangle",
      "cwe": "CWE-125",
      "title": "rz-libdemangle: Out of bound read in rust demangler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45612"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-3842",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02305,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "qemu",
      "cwe": "CWE-787",
      "title": "Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3842"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-35146",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "DFXServer",
      "cwe": "CWE-326",
      "title": "HCL DFXServer is affected by an Unencrypted Communication vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35146"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-61378",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AutomationDirect",
      "product": "Productivity Suite",
      "cwe": "CWE-369",
      "title": "AutomationDirect Productivity Suite Divide By Zero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61378"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-9494",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Canonical",
      "product": "ubuntu-pro-client (ubuntu-advantage-tools)",
      "cwe": "CWE-214",
      "title": "ubuntu-pro-client Information Disclosure via Cleartext Bearer Token Exposure in Process Command Line",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9494"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-13104",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "App Store",
      "cwe": "CWE-250",
      "title": "A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated user to execute arbitrary code with elevated privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13104"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-6424",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01557,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ESET, spol. s.r.o.",
      "product": "ESET Endpoint Antivirus for Linux",
      "cwe": "CWE-416",
      "title": "Use-after-free vulnerability in ESET security products for Linux",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6424"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-46378",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TomWright",
      "product": "dasel",
      "cwe": "CWE-835",
      "title": "Dasel: Denial of service in dasel selector lexer due to infinite loop on unterminated regex literal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46378"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-10590",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "Yoga Pro 7 15IPH11 BIOS",
      "cwe": null,
      "title": "A potential missing authentication vulnerability could allow a local privileged attacker to use WMI commands to arbitrarily trigger a System Management Interrupt handler.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10590"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-10589",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00109,
      "epss_percentile": 0.01436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "Yoga Pro 7 15IPH11 BIOS",
      "cwe": "CWE-787",
      "title": "A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10589"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-35143",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "DFXAnalytics",
      "cwe": "CWE-352",
      "title": "HCL DFXAnalytics is affected by a Missing SameSite Attribute vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35143"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-60063",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.01287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AutomationDirect",
      "product": "Productivity Suite",
      "cwe": "CWE-787",
      "title": "AutomationDirect Productivity Suite Out-of-bounds Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60063"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-61389",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.01287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AutomationDirect",
      "product": "Productivity Suite",
      "cwe": "CWE-787",
      "title": "AutomationDirect Productivity Suite Out-of-bounds Write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61389"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-10588",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "Yoga Pro 7 15IPH11 BIOS",
      "cwe": "CWE-497",
      "title": "A potential vulnerability could allow a local privileged attacker to disclose the address of protected System Management Mode memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10588"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-57896",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AutomationDirect",
      "product": "Productivity Suite",
      "cwe": "CWE-125",
      "title": "AutomationDirect Productivity Suite Out-of-bounds Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57896"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-60140",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AutomationDirect",
      "product": "Productivity Suite",
      "cwe": "CWE-125",
      "title": "AutomationDirect Productivity Suite Out-of-bounds Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60140"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-62290",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00104,
      "epss_percentile": 0.01176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cert-manager",
      "product": "cert-manager",
      "cwe": "CWE-863",
      "title": "cert-manager: Direct ACME Challenge resources can bypass Issuer DNS01 solver policy and use ClusterIssuer DNS credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62290"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-10587",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "Yoga Pro 7 15IPH11 BIOS",
      "cwe": "CWE-787",
      "title": "A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10587"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-15997",
      "cvss_base": 1.7,
      "cvss_severity": "LOW",
      "epss_score": 0.001,
      "epss_percentile": 0.00956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-LTS",
      "cwe": "CWE-787",
      "title": "Native ARM SHA3 / SHAKE `restoreFullState` fails to detect size_t underflow in a crafted encoded state",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15997"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-11866",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Appointment Booking Plugin",
      "cwe": "CWE-352",
      "title": "LatePoint < 5.6.3 - Multiple Privileged Actions via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11866"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-6511",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.00691,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "Smart Connect",
      "cwe": "CWE-306",
      "title": "During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that could allow a local authenticated user to access files owned by a different user on the same system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6511"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-53410",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00093,
      "epss_percentile": 0.00674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zoom Communications",
      "product": "Zoom Clients",
      "cwe": "CWE-367",
      "title": "Zoom Clients for Windows - Race Condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53410"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-9046",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00085,
      "epss_percentile": 0.00365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenovo",
      "product": "Legion Zone",
      "cwe": "CWE-277",
      "title": "A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in the Chinese market, that when installed on a non‑system partition, could allow a local user to execute arbitrary code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9046"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-15449",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00084,
      "epss_percentile": 0.00339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "illumos",
      "product": "illumos-gate",
      "cwe": "CWE-122",
      "title": "TOCTOU double copyin in illumos dld ioctl handling causes kernel heap corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15449"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33434",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33434 (wazuh). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-33754",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-33754 (wazuh). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-34150",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-34150 (wazuh). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-39359",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-39359 (wazuh). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-40106",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-40106 (wazuh). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44180",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44180 (jupyter-server enterprise_gateway). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44181",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44181 (jupyter-server enterprise_gateway). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44182",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44182 (jupyter-server enterprise_gateway). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44595",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44595 (yamcs). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44596",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44596 (yamcs). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44632",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44632 (yamcs). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44968",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44968 (dbt-labs dbt-mcp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44969",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44969 (dbt-labs dbt-mcp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44970",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44970 (dbt-labs dbt-mcp). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46338",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46338 (facelessuser pymdown-extensions). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46562",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46562 (yamcs). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46621",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46621 (yamcs). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54526",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54526 (argoproj argo-workflows). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55548",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55548 (yamcs). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-62290",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-62290 (cert-manager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-62299",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-62299 (coredns). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-62309",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-62309 (coredns). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-62994",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-62994 (coredns). Public exploit reference added."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
