{
  "day": "2026-07-17",
  "boundary": "UTC calendar day",
  "published_count": 288,
  "by_severity": {
    "CRITICAL": 38,
    "HIGH": 99,
    "MEDIUM": 131,
    "LOW": 20
  },
  "kev_count": 1,
  "exploit_reference_count": 17,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-9198",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.17352,
      "epss_percentile": 0.96864,
      "kev": true,
      "kev_due_at": "2026-08-07",
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9198"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-62241",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.06548,
      "epss_percentile": 0.93245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MohibShaikh",
      "product": "clawvet",
      "cwe": "CWE-306",
      "title": "clawvet < 0.7.5 Hard-coded JWT Secret Session Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62241"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-50289",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01873,
      "epss_percentile": 0.77689,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sebhildebrandt",
      "product": "systeminformation",
      "cwe": "CWE-78",
      "title": "systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50289"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-46420",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01538,
      "epss_percentile": 0.72863,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shivammathur",
      "product": "setup-php",
      "cwe": "CWE-78",
      "title": "setup-php: Command Injection in Repository-Derived PHP Version Resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46420"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-42168",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01232,
      "epss_percentile": 0.66566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. These fields are passed directly to os.system() in pyas2/utils.py without sanitization, allowing an authenticated admin user to execute arbitrary commands on the server when an AS2 message is received or sent.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42168"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-15457",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00766,
      "epss_percentile": 0.52677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Kirki – Freeform Page Builder, Website Builder & Customizer",
      "cwe": "CWE-22",
      "title": "Kirki <= 6.0.13 - Authenticated (Editor+) Path Traversal to Arbitrary Directory Deletion via 'family' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15457"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-52199",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00599,
      "epss_percentile": 0.46066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52199"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-13352",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00575,
      "epss_percentile": 0.44929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "properfraction",
      "product": "Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress",
      "cwe": "CWE-434",
      "title": "Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content <= 4.16.18 - Authenticated (Author+) Limited Unsafe File Upload via upload_mimes Filter Expansion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13352"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-45162",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00574,
      "epss_percentile": 0.44868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pimcore",
      "product": "pimcore",
      "cwe": "CWE-502",
      "title": "Pimcore: Unsafe PHP Deserialization in Multiple Locations Without allowed_classes Restriction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45162"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-36669",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00563,
      "epss_percentile": 0.44357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-434",
      "title": "An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the web-accessible /tmp/ directory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-36669"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-8505",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0056,
      "epss_percentile": 0.44167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-306",
      "title": "Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8505"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-63093",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00557,
      "epss_percentile": 0.43984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anysphere, Inc.",
      "product": "Cursor",
      "cwe": "CWE-426",
      "title": "Cursor for Windows 3.2.16 RCE via Malicious git.exe in Workspace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63093"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-45799",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00546,
      "epss_percentile": 0.43429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "square",
      "product": "wire",
      "cwe": "CWE-129",
      "title": "Wire: skipGroup() missing negative-length check allows 10-byte payload to crash any Wire-decoding service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45799"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-56741",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00527,
      "epss_percentile": 0.42444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jline",
      "product": "jline3",
      "cwe": "CWE-400",
      "title": "JLine: Unauthenticated Remote DoS via Unbounded Telnet NAWS Terminal Geometry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56741"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-56740",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00525,
      "epss_percentile": 0.42293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jline",
      "product": "jline3",
      "cwe": "CWE-400",
      "title": "JLine: Unauthenticated Remote Memory Exhaustion via Unbounded Telnet NEW-ENVIRON Variables",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56740"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-15094",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00511,
      "epss_percentile": 0.41455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thimpress",
      "product": "WP Hotel Booking",
      "cwe": "CWE-79",
      "title": "WP Hotel Booking <= 2.3.2 - Reflected Cross-Site Scripting via 'check_in_date' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15094"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-8476",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00493,
      "epss_percentile": 0.40384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-502",
      "title": "Disk Cache Deserialization Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8476"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-9135",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00488,
      "epss_percentile": 0.40075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Policies Component Dynamic CodeInput Fields Bypass Custom Component Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9135"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-50273",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00482,
      "epss_percentile": 0.39669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DataDog",
      "product": "dd-trace-dotnet",
      "cwe": "CWE-770",
      "title": "Datadog .NET Tracer: Improper parsing of W3C baggage headers may lead to DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50273"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-56171",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0048,
      "epss_percentile": 0.39546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Remote Desktop Web Client",
      "cwe": "CWE-359",
      "title": "Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56171"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-62764",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00471,
      "epss_percentile": 0.38897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Accumulo",
      "cwe": "CWE-274",
      "title": "Apache Accumulo: A user can trigger a graceful shutdown of services without the relevant system permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62764"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-13473",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0047,
      "epss_percentile": 0.38858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Storage Protect Client",
      "cwe": "CWE-122",
      "title": "IBM Storage Protect Client is vulnerable to Heap-Based Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13473"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-15160",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00459,
      "epss_percentile": 0.38194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SaturdayDrive",
      "product": "Ninja Forms - Excel Export",
      "cwe": "CWE-22",
      "title": "Ninja Forms - Excel Export <= 3.3.6 - Missing Authorization to Authenticated (Subscriber+) XLS Write via Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15160"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-8481",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00458,
      "epss_percentile": 0.38109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Remote Code Execution via Code Validation Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8481"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-13448",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00456,
      "epss_percentile": 0.38012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-184",
      "title": "Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13448"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-58195",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00456,
      "epss_percentile": 0.38018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ruvnet",
      "product": "agentic-flow",
      "cwe": "CWE-78",
      "title": "Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58195"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-14499",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00448,
      "epss_percentile": 0.37468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-78",
      "title": "Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14499"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-49835",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00447,
      "epss_percentile": 0.37348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sigstore",
      "product": "timestamp-authority",
      "cwe": "CWE-770",
      "title": "Sigstore Timestamp Authority: OOM due to unbounded metric label cardinality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49835"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-15343",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.37253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitHub",
      "product": "Enterprise Server",
      "cwe": "CWE-22",
      "title": "Path traversal vulnerability in GitHub Enterprise Server allowed writing files to arbitrary repository paths, including GitHub Actions workflow files, via unchecked Dependabot dependency-file paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15343"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-62229",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.37249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-22",
      "title": "OpenClaw < 2026.5.18 Authorization Bypass via Glob Matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62229"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-48049",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00446,
      "epss_percentile": 0.37304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hapijs",
      "product": "inert",
      "cwe": "CWE-22",
      "title": "@hapi/inert: Static-file confinement bypass via sibling-prefix path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48049"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-50271",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DataDog",
      "product": "dd-trace-py",
      "cwe": "CWE-770",
      "title": "dd-trace-py: Improper parsing of W3C baggage headers may lead to DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50271"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-50272",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DataDog",
      "product": "dd-trace-js",
      "cwe": "CWE-770",
      "title": "dd-trace: Improper parsing of W3C baggage headers may lead to DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50272"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-50274",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00441,
      "epss_percentile": 0.36895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DataDog",
      "product": "dd-trace-go",
      "cwe": "CWE-770",
      "title": "dd-trace-go: Improper parsing of W3C baggage headers may lead to DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50274"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-45309",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0044,
      "epss_percentile": 0.36796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ronf",
      "product": "asyncssh",
      "cwe": "CWE-22",
      "title": "AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45309"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-48062",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00438,
      "epss_percentile": 0.36663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codeigniter4",
      "product": "CodeIgniter4",
      "cwe": "CWE-434",
      "title": "CodeIgniter: Uploaded file extension validation bypass in `ext_in` rule",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48062"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2025-51677",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00432,
      "epss_percentile": 0.36144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-116",
      "title": "An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can lead to unexpected behavior.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-51677"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2025-51678",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-119",
      "title": "An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to unexpected behavior.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-51678"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-12283",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00432,
      "epss_percentile": 0.3621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "aws-athena-query-federation",
      "cwe": "CWE-89",
      "title": "SQL injection in Amazon Athena Synapse connector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12283"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-50197",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00429,
      "epss_percentile": 0.35961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zalando",
      "product": "skipper",
      "cwe": "CWE-444",
      "title": "Skipper: opaAuthorizeRequestWithBody filter bypasses OPA policy on Transfer-Encoding: chunked / HTTP/2 requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50197"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-16013",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00428,
      "epss_percentile": 0.35896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "liftoff-sr",
      "product": "CIPster",
      "cwe": "CWE-119",
      "title": "liftoff-sr CIPster cipepath.cc deserialize_symbolic out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16013"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-45260",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00427,
      "epss_percentile": 0.35817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pimcore",
      "product": "pimcore",
      "cwe": "CWE-862",
      "title": "Pimcore: Missing Authorization in WebDAV MOVE via unchecked asset move handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45260"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-44891",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-400",
      "title": "Netty: Denial of Service via Unbounded Headers in StompSubframeDecoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44891"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-7755",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00415,
      "epss_percentile": 0.34778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-20",
      "title": "MCP Server Configuration Validator Bypass via File Upload API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7755"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-9103",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-306",
      "title": "Unauthenticated Superuser Token Issuance via Auto-Login Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9103"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-9586",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sangoma",
      "product": "Switchvox SMB Edition",
      "cwe": "CWE-89",
      "title": "Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9586"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-54159",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00406,
      "epss_percentile": 0.34007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PrestaShop",
      "product": "ps_facetedsearch",
      "cwe": "CWE-74",
      "title": "ps_facetedsearch: PHP Object Injection in faceted search cache allows unauthenticated RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54159"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-13765",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00388,
      "epss_percentile": 0.32137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thimpress",
      "product": "LearnPress – WordPress LMS Plugin for Create and Sell Online Courses",
      "cwe": "CWE-862",
      "title": "LearnPress <= 4.4.1 - Missing Authorization to Unauthenticated Sensitive Information Exposure via /lp/v1/users/check-answer and /start-quiz REST Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13765"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-14979",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Engineering Lifecycle Management",
      "cwe": "CWE-776",
      "title": "IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML Entity Expansion attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14979"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-16015",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00384,
      "epss_percentile": 0.31765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "poco-ai",
      "product": "poco-claw",
      "cwe": "CWE-287",
      "title": "poco-ai poco-claw executor_manager API tasks.py create_task missing authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16015"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-52746",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00379,
      "epss_percentile": 0.3116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jsonata-js",
      "product": "jsonata",
      "cwe": "CWE-1333",
      "title": "JSONata: Malicious inputs to \"$toMillis\" function can cause resource exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52746"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-51833",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00377,
      "epss_percentile": 0.30952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-918",
      "title": "Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can enumerate internal services (ports) or expose the original IP address of the server.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51833"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-49485",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00371,
      "epss_percentile": 0.30407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hapifhir",
      "product": "org.hl7.fhir.core",
      "cwe": "CWE-400",
      "title": "HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49485"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-8859",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00368,
      "epss_percentile": 0.30023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Path Traversal in APIRequest Component via Content-Disposition Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8859"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-15007",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00366,
      "epss_percentile": 0.29825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitHub",
      "product": "Enterprise Server",
      "cwe": "CWE-770",
      "title": "Denial of service vulnerability in GitHub Enterprise Server allowed service disruption via deeply nested YAML in release notes configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15007"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-53727",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "premailer",
      "product": "css_parser",
      "cwe": "CWE-918",
      "title": "css_parser: SSRF and Local File Disclosure in `CssParser::Parser#read_remote_file`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53727"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-50162",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00365,
      "epss_percentile": 0.29778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oras-project",
      "product": "oras-go",
      "cwe": "CWE-73",
      "title": "oras-go: file store write outside workingDir via symlink traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50162"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-50151",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00364,
      "epss_percentile": 0.29701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oras-project",
      "product": "oras-go",
      "cwe": "CWE-918",
      "title": "oras-go: credential forwarding via unvalidated Location header in blob upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50151"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-7872",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Path Traversal Vulnerability in File Component Leading to Arbitrary File Read and Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7872"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-59252",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZenHive",
      "product": "mpp",
      "cwe": "CWE-1284",
      "title": "Missing gas_limit validation in mpp Tempo fee-payer enables wallet drain",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59252"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-44251",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00361,
      "epss_percentile": 0.2932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-122",
      "title": "Wazuh : size_t underflow in msgs.c ReadSecMSG causes wazuh-remoted DoS and potential heap overflow via crafted agent message",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44251"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-7667",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.29193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Path Traversal Vulnerability in API Request Component Content-Disposition Header Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7667"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-14741",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OALDERS",
      "product": "HTTP::Date",
      "cwe": "CWE-1333",
      "title": "HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14741"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-14956",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00351,
      "epss_percentile": 0.28349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bricksforge",
      "product": "Bricksforge",
      "cwe": "CWE-269",
      "title": "Bricksforge <= 3.1.8.6 - Unauthenticated Privilege Escalation via Pro Forms fieldIds Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14956"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-12692",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00346,
      "epss_percentile": 0.27756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Vimesoft Inc.",
      "product": "Enterprise Video Platform",
      "cwe": "CWE-620",
      "title": "Improper Authentication in Vimesoft's Enterprise Video Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12692"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-50163",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oras-project",
      "product": "oras-go",
      "cwe": "CWE-22",
      "title": "oras-go: Hardlink entry with relative Linkname escapes extract dir via process CWD resolution in `oras-go` tar extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50163"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-44974",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hapijs",
      "product": "content",
      "cwe": "CWE-436",
      "title": "Parameter smuggling in @hapi/content header parser allows upload-filter bypass via duplicate parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44974"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-54463",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00344,
      "epss_percentile": 0.27511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "faye",
      "product": "websocket-driver-ruby",
      "cwe": "CWE-770",
      "title": "websocket-driver: Memory exhaustion via abuse of protocol length headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54463"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-54465",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00344,
      "epss_percentile": 0.27511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "faye",
      "product": "websocket-driver-ruby",
      "cwe": "CWE-770",
      "title": "websocket-driver: Memory exhaustion in HTTP header parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54465"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-15982",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00339,
      "epss_percentile": 0.27013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeRevolution",
      "product": "Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit",
      "cwe": "CWE-269",
      "title": "Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit <= 2.8.4 - Unauthenticated Privilege Escalation via 'aiomatic_call_google_ai_function'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15982"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-62238",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00333,
      "epss_percentile": 0.26357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openremote",
      "product": "openremote",
      "cwe": "CWE-89",
      "title": "OpenRemote < 1.26.0 SQL Injection via Crosstab Export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62238"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-55518",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00331,
      "epss_percentile": 0.26045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "avo-hq",
      "product": "avo",
      "cwe": "CWE-639",
      "title": "Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55518"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-9585",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sangoma",
      "product": "Switchvox SMB Edition",
      "cwe": "CWE-79",
      "title": "Unauthenticated Reflected Cross-Site Scripting (XSS) in Switchvox SMB Web Portal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9585"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-22104",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hashtopolis",
      "product": "server",
      "cwe": "CWE-639",
      "title": "Improper access control in Hashtopolis server chunk activity component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22104"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-54464",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00324,
      "epss_percentile": 0.25349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "faye",
      "product": "websocket-driver-ruby",
      "cwe": "CWE-770",
      "title": "websocket-driver: Resource limit bypass via message compression",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54464"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-15091",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00321,
      "epss_percentile": 0.24947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Engineering AI Hub",
      "cwe": "CWE-79",
      "title": "Multiple Vulnerabilities in IBM Engineering AI hub.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15091"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-58148",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chronoengine.com",
      "product": "ChronoForms extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58148"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-63098",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00317,
      "epss_percentile": 0.24523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TheHive-Project",
      "product": "TheHive",
      "cwe": "CWE-306",
      "title": "TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63098"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-14501",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00315,
      "epss_percentile": 0.24307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2 Genius Hub",
      "cwe": "CWE-676",
      "title": "Use of Potentially Dangerous Functionthat in IBM Db2 Genius Hub",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14501"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-9171",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.24189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Novalink",
      "cwe": "CWE-400",
      "title": "Vulnerabilities in IBM WebSphere Application affects IBM PowerVM Novalink.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9171"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-45704",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.24184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pimcore",
      "product": "pimcore",
      "cwe": "CWE-862",
      "title": "Pimcore: CustomReports Share Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45704"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-62210",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.24174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-770",
      "title": "OpenClaw < 2026.6.1 Denial of Service via Remote Media URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62210"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-54498",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.24042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ViewComponent",
      "product": "view_component",
      "cwe": "CWE-79",
      "title": "view_component: around_render HTML-Safety Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54498"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-14871",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.24044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "osTicket",
      "product": "osTicket",
      "cwe": "CWE-863",
      "title": "osTicket v1.18.3 - v1.17.7 - BOLA/IDOR in ticket field viewing allows cross-department data disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14871"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-49209",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.2403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "symfony",
      "product": "ux",
      "cwe": "CWE-770",
      "title": "Symfony UX: Denial of service in symfony/ux-live-component via unbounded batch action requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49209"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-62214",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openclaw",
      "product": "msteams",
      "cwe": "CWE-522",
      "title": "OpenClaw < 2026.5.28 Bot Framework SSRF via serviceUrl Parameter Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62214"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-49211",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.23233,
      "kev": false,
      "kev_due_at": null,
      "vendor": "symfony",
      "product": "ux",
      "cwe": "CWE-200",
      "title": "Symfony UX: Information exposure via unescaped LIKE wildcards in EntitySearchUtil",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49211"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-54171",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00304,
      "epss_percentile": 0.23074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "excon",
      "product": "excon",
      "cwe": "CWE-201",
      "title": "Excon: redact additional sensitive/risky headers when following redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54171"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-48504",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00304,
      "epss_percentile": 0.23132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-telemetry",
      "product": "opentelemetry-rust",
      "cwe": "CWE-770",
      "title": "OpenTelemetry Rust: Unbounded memory allocation in W3C Baggage propagation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48504"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-9810",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.22971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "AI Copilot",
      "cwe": "CWE-269",
      "title": "AI Chatbot & Workflow Automation by AIWU < 1.5.4 - Unauthenticated Privilege Escalation via MCP OAuth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9810"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-60024",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.23005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomdonation.com",
      "product": "Events Booking extension for Joomla",
      "cwe": "CWE-1188",
      "title": "Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60024"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-15322",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.23054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Engineering AI Hub",
      "cwe": "CWE-598",
      "title": "Multiple Vulnerabilities in IBM Engineering AI hub.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15322"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-52203",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.23054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52203"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-63101",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fossasia",
      "product": "open-event-server",
      "cwe": "CWE-306",
      "title": "Open Event Server 1.19.1 Unauthenticated Member Roster Export via CSV Export Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63101"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-8635",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00301,
      "epss_percentile": 0.22706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Arbitrary Code Execution in Python Interpreter Component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8635"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-59694",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZenHive",
      "product": "mpp",
      "cwe": "CWE-1284",
      "title": "Unbounded access list in mpp Tempo fee-payer inflates gas cost per payment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59694"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-59695",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZenHive",
      "product": "mpp",
      "cwe": "CWE-1284",
      "title": "Unbounded max_fee_per_gas in mpp Tempo fee-payer enables single-request wallet drain",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59695"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-62207",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-862",
      "title": "OpenClaw < 2026.6.5 Authentication Bypass via Admin Tools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62207"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-12691",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00299,
      "epss_percentile": 0.22577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Vimesoft Inc.",
      "product": "Enterprise Video Platform",
      "cwe": "CWE-306",
      "title": "Authentication Bypass in Vimesoft's Enterprise Video Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12691"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-62202",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22478,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw 2026.6.1 < 2026.6.9 Privilege Escalation via Cron",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62202"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-62234",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.22334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-918",
      "title": "Grav < 2.0.4 SSRF via Unrestricted cURL Protocols",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62234"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-8056",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.22052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Parameter Injection Vulnerability in API Graph Execution Engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8056"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-62220",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-307",
      "title": "OpenClaw 2026.2.25 < 2026.5.26 WebSocket Rate Limit Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62220"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-62203",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-184",
      "title": "OpenClaw < 2026.6.6 Environment Variable Injection via rustup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62203"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-16016",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "poco-ai",
      "product": "poco-claw",
      "cwe": "CWE-918",
      "title": "poco-ai poco-claw task.py run_task server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16016"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-51080",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00287,
      "epss_percentile": 0.21299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-611",
      "title": "libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51080"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-14503",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.21284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ploudapp",
      "product": "pCloud WP Backup",
      "cwe": "CWE-200",
      "title": "pCloud WP Backup <= 2.0.3 - Missing Authorization on the 'start_backup' AJAX Method to Authenticated (Subscriber+) Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14503"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-44739",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.21112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pimcore",
      "product": "pimcore",
      "cwe": "CWE-89",
      "title": "Pimcore: SQL Injection in Custom Reports Column Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44739"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-62230",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-178",
      "title": "Grav < 2.0.4 File Access Bypass via Case Variation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62230"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-62232",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0028,
      "epss_percentile": 0.20532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-862",
      "title": "Grav < 2.0.4 2FA Bypass via Secret Regeneration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62232"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2025-60357",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20545,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-943",
      "title": "AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEvent/list endpoint.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60357"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-11324",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0028,
      "epss_percentile": 0.20555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "evertec",
      "product": "WooCommerce Placetopay Gateway Belice",
      "cwe": "CWE-79",
      "title": "WooCommerce Placetopay Gateway <= 3.2.2 - Reflected Cross-Site Scripting via 'redirect-url'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11324"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-9202",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00279,
      "epss_percentile": 0.2048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-306",
      "title": "Unauthenticated User Registration Could Lead to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9202"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-48015",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shopware",
      "product": "shopware",
      "cwe": "CWE-79",
      "title": "Shopware: Stored XSS via SVG file upload — no SVG sanitization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48015"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-63308",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "helm",
      "product": "helm",
      "cwe": "CWE-129",
      "title": "Helm Files.Lines Denial of Service via Empty Chart Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63308"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-15783",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.19762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitHub",
      "product": "Enterprise Server",
      "cwe": "CWE-862",
      "title": "Missing Authorization vulnerability was identified in GitHub Enterprise Server that allowed reading private repository metadata via delegated bypass rule suites",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15783"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-48009",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shopware",
      "product": "shopware",
      "cwe": "CWE-200",
      "title": "Shopware: Admin Account Takeover via User Recovery Hash Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48009"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-15349",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wedevs",
      "product": "ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce",
      "cwe": "CWE-862",
      "title": "ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce <= 1.17.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Company Location Creation via wp_ajax_erp-company-location AJAX Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15349"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-62386",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-598",
      "title": "Grav < 1.0.0-rc.16 Authentication Bypass via token URL Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62386"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-12693",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00264,
      "epss_percentile": 0.18406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Vimesoft Inc.",
      "product": "Enterprise Video Platform",
      "cwe": "CWE-639",
      "title": "IDOR in Vimesoft's Enterprise Video Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12693"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-48008",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shopware",
      "product": "shopware",
      "cwe": "CWE-862",
      "title": "Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48008"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-48010",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shopware",
      "product": "shopware",
      "cwe": "CWE-269",
      "title": "Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accounts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48010"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-11763",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc.",
      "product": "GisLab Laboratory Management System",
      "cwe": "CWE-639",
      "title": "IDOR in GIS Informatics' GisLab Laboratory Management System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11763"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-54490",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.1826,
      "kev": false,
      "kev_due_at": null,
      "vendor": "faye",
      "product": "websocket-driver-node",
      "cwe": "CWE-770",
      "title": "websocket-driver: Resource limit bypass via message compression",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54490"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-16014",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code-projects",
      "product": "Hospital Bed Management System",
      "cwe": "CWE-74",
      "title": "code-projects Hospital Bed Management System Login Form sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16014"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-16008",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00262,
      "epss_percentile": 0.18123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sagold",
      "product": "json-schema-library",
      "cwe": "CWE-94",
      "title": "sagold json-schema-library propertyDependencies.ts parsePropertyDependencies prototype pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16008"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-8297",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc.",
      "product": "GisLab Laboratory Management System",
      "cwe": "CWE-89",
      "title": "SQLi in GIS Informatics' GisLab Laboratory Management System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8297"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-52348",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17939,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52348"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-13410",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GARU",
      "product": "Dancer::Plugin::Auth::Google",
      "cwe": "CWE-295",
      "title": "Dancer::Plugin::Auth::Google versions before 0.08 for Perl have TLS verification disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13410"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-8396",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Netcad Software Inc.",
      "product": "NetGIS",
      "cwe": "CWE-611",
      "title": "XXE in Netcad's NetGIS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8396"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-44979",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.1795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hapijs",
      "product": "wreck",
      "cwe": "CWE-200",
      "title": "@hapi/wreck : Sensitive `Proxy-Authorization` header leaked across cross-hostname redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44979"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-62201",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-918",
      "title": "OpenClaw < 2026.6.6 Network Policy Bypass via exec-server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62201"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-62387",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-942",
      "title": "Grav < 1.0.0-rc.16 CORS Misconfiguration via API Plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62387"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-7364",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Verify Identity Access",
      "cwe": "CWE-601",
      "title": "Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7364"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-54335",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00259,
      "epss_percentile": 0.1774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "feathersjs",
      "product": "feathers",
      "cwe": "CWE-1321",
      "title": "Feathersjs: Prototype pollution in @feathersjs/commons _.merge via JSON-parsed __proto__",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54335"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-62208",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-522",
      "title": "OpenClaw < 2026.6.5 Authorization Header Forwarding via SSE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62208"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-62213",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openclaw",
      "product": "msteams",
      "cwe": "CWE-522",
      "title": "OpenClaw < 2026.5.27 Token Leakage via MS Teams Outbound Requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62213"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-54497",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.1652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ViewComponent",
      "product": "view_component",
      "cwe": "CWE-362",
      "title": "view_component: Reused Component Instances Retain Stale Render Context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54497"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-62205",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-862",
      "title": "OpenClaw 2026.4.12-beta.1 < 2026.6.6 Authorization Bypass via message actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62205"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-62206",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-862",
      "title": "OpenClaw < 2026.6.9 Authentication Bypass via Moderation Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62206"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-62237",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-1333",
      "title": "Grav < 2.0.4 ReDoS via regex_replace in Sandbox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62237"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-62218",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-862",
      "title": "OpenClaw 2026.1.20 < 2026.5.27 Authorization Bypass via device.pair.approve",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62218"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-62223",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw < 2026.5.18 Authorization Bypass via Device-pair",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62223"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-62228",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw < 2026.6.5 Authorization Bypass via Node Exec Approvals",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62228"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-48487",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.16365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "python-zeroconf",
      "product": "python-zeroconf",
      "cwe": "CWE-130",
      "title": "Zeroconf: Unvalidated rdlength in record payload readers allows LAN-local cache corruption via crafted mDNS packet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48487"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-11961",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Registration & Membership",
      "cwe": "CWE-269",
      "title": "User Registration & Membership < 5.2.3 - Unauthenticated Privilege Escalation via Unbound members_data Membership ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11961"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-4942",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "i",
      "cwe": "CWE-757",
      "title": "IBM i is Affected by Algorithm Downgrade in Transport Layer Security []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4942"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-15395",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpchill",
      "product": "Kali Forms — Contact Form & Drag-and-Drop Builder",
      "cwe": "CWE-79",
      "title": "Kali Forms <= 2.4.18 - Unauthenticated Stored Cross-Site Scripting via 'digitalSignature' Field Value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15395"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-15415",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "aws-healthomics-mcp-server",
      "cwe": "CWE-23",
      "title": "Path traversal and arbitrary file write in the workflow linters of aws-healthomics-mcp-server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15415"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-62233",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-639",
      "title": "grav-plugin-api < 1.0.6 Privilege Escalation via createApiKey",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62233"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-62217",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw 2026.5.14-beta.1 < 2026.5.27 Authentication Bypass via exec approvals",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62217"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-7189",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Proliz Software Ltd. Co.",
      "product": "Proliz's OBS",
      "cwe": "CWE-201",
      "title": "Sensitive Data Exposure in Proliz's OBS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7189"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-7488",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IKAS Technology Inc.",
      "product": "E-Commerce",
      "cwe": "CWE-201",
      "title": "Sensitive Data Exposure in IKAS Technologies' E-Commerce",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7488"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-12694",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00243,
      "epss_percentile": 0.15763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Vimesoft Inc.",
      "product": "Enterprise Video Platform",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Vimesoft's Enterprise Video Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12694"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-62226",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15564,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-918",
      "title": "OpenClaw 2026.3.28 < 2026.5.19 Authorization Bypass via Browser Act Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62226"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-49208",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "symfony",
      "product": "ux",
      "cwe": "CWE-20",
      "title": "Symfony UX: Format-less date LiveProps parsed with the permissive DateTime constructor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49208"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-8075",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-754",
      "title": "Posting a malicious markdown image crashes the Mattermost Desktop App",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8075"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-9602",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.1538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-400",
      "title": "Mattermost Desktop App crashes when malformed arguments are provided to some exposed IPC methods",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9602"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-2594",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.1539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "inc2734",
      "product": "Smart Custom Fields",
      "cwe": "CWE-79",
      "title": "Smart Custom Fields <= 5.0.7 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2594"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-8861",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Verify Identity Access",
      "cwe": "CWE-209",
      "title": "Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8861"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-9588",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sangoma",
      "product": "Switchvox SMB Edition",
      "cwe": "CWE-79",
      "title": "Authenticated Stored Cross-Site Scripting (XSS) in Switchvox SMB Web Portal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9588"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-47183",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "python-zeroconf",
      "product": "python-zeroconf",
      "cwe": "CWE-400",
      "title": "Zeroconf: Unbounded exception-dedup state retains packet buffers via traceback frame locals, enabling LAN-local memory exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47183"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-47184",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "python-zeroconf",
      "product": "python-zeroconf",
      "cwe": "CWE-770",
      "title": "Zeroconf: Unbounded DNS record cache allows LAN-local memory exhaustion via multicast flood",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47184"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2024-23565",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Aftermarket EPC",
      "cwe": "CWE-799",
      "title": "HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b e a human or an automated process such as a virus or bot. This could be used to cause a denial of service, compromise program logic or other consequences.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23565"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2024-23568",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Aftermarket EPC",
      "cwe": "CWE-200",
      "title": "HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information of software could allow an attacker to determine which vulnerabilities are present in the software, particularly if an outdated software version is in use with published vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23568"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-48016",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shopware",
      "product": "shopware",
      "cwe": "CWE-639",
      "title": "Shopware: Unauthorized Payment Trigger for Foreign Orders via /store-api/handle-payment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48016"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-48014",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.1449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shopware",
      "product": "shopware",
      "cwe": "CWE-862",
      "title": "Shopware: Admin API ACL Bypass in Order State Transition Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48014"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-63307",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OtterMind",
      "product": "Chat2DB",
      "cwe": "CWE-639",
      "title": "Chat2DB < 5.3.0 Insecure Direct Object Reference via GET /api/connection/datasource",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63307"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-9587",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.13952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sangoma",
      "product": "Switchvox SMB Edition",
      "cwe": "CWE-73",
      "title": "Authenticated Local File Inclusion (LFI) in Switchvox SMB Web Portal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9587"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-62227",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.1392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-918",
      "title": "OpenClaw 2026.4.14 < 2026.5.26 SSRF via Browser Snapshot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62227"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-11575",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "PhonePe Payment Solutions",
      "cwe": "CWE-862",
      "title": "PhonePe Payment Solutions < 3.1.0 - Unauthenticated Payment Bypass via Forged Callback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11575"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-8616",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "devozon",
      "product": "Fense Proxy & VPN Blocker",
      "cwe": "CWE-862",
      "title": "Fense Proxy & VPN Blocker <= 3.0.1 - Missing Authorization to Unauthenticated Plugin Option/Transient Deletion via fense_bpvt_save_settings AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8616"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-9537",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.1383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JBERGER",
      "product": "Mojo::JWT",
      "cwe": "CWE-208",
      "title": "Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9537"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-13446",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00226,
      "epss_percentile": 0.13522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-798",
      "title": "Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13446"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-47180",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "python-zeroconf",
      "product": "python-zeroconf",
      "cwe": "CWE-674",
      "title": "Zeroconf: Unbounded recursion in DNS compression-pointer decoder allows LAN-local denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47180"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-48045",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "python-zeroconf",
      "product": "python-zeroconf",
      "cwe": "CWE-770",
      "title": "Zeroconf: Unbounded TC-deferred queue allows LAN-local memory exhaustion via spoofed-source flood",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48045"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-13402",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Royal Addons for Elementor",
      "cwe": "CWE-200",
      "title": "Royal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Template Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13402"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-57980",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-288",
      "title": "Microsoft Edge (Chromium-based) Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57980"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-54466",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00221,
      "epss_percentile": 0.1298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "faye",
      "product": "websocket-driver-node",
      "cwe": "CWE-130",
      "title": "websocket-driver: Message corruption via abuse of protocol length headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54466"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-62231",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-863",
      "title": "Grav < 1.0.6 API Key Scope Bypass via ApiKeyAuthenticator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62231"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-51082",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-362",
      "title": "A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4.19; qemu-server 9.x before 9.1.7 and 8.x before 8.4.7; and pve-container before 6.1.3 (PVE 9.x) and before 5.3.4 (PVE 8.x) allows an attacker with privileges to call \"vncproxy\" to hijack a VNC session that is established in parallel by a different user for a different VM.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51082"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-48819",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.1296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hey-api",
      "product": "openapi-ts",
      "cwe": "CWE-1321",
      "title": "Hey API: `buildClientParams` template: prototype chain substitution via unknown `$<slot>___proto__` key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48819"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-13082",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12342,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BURAK",
      "product": "GD::SecurityImage",
      "cwe": "CWE-338",
      "title": "GD::SecurityImage versions through 1.75 for Perl use rand to generate secrets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13082"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-15093",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Engineering AI Hub",
      "cwe": "CWE-601",
      "title": "Multiple Vulnerabilities in IBM Engineering AI hub.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15093"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-63096",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "matrix-org",
      "product": "dendrite",
      "cwe": "CWE-918",
      "title": "Dendrite 0.13.8 SSRF via Unauthenticated Legacy Media Download Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63096"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-16104",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-522",
      "title": "Keycloak-services: keycloak-services: authenticator config endpoint exposes raw recaptcha secrets to view-only admins",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16104"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-62216",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00211,
      "epss_percentile": 0.11645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-918",
      "title": "OpenClaw 2026.4.20 < 2026.5.28 Policy Bypass via Media Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62216"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-48978",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00211,
      "epss_percentile": 0.11631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oras-project",
      "product": "oras-go",
      "cwe": "CWE-319",
      "title": "oras-go: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48978"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-54496",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0021,
      "epss_percentile": 0.11553,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZcashFoundation",
      "product": "zebra",
      "cwe": "CWE-345",
      "title": "Missing copy constraint in halo2_gadgets variable-base scalar multiplication allows under-constrained base, breaking Orchard Action circuit soundness",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54496"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-62209",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw 2026.5.10-beta.1 < 2026.6.5 Authorization Bypass via agent-mode dispatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62209"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-63099",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.11318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TheHive-Project",
      "product": "TheHive",
      "cwe": "CWE-639",
      "title": "TheHive 4.1.24 Broken Object Level Authorization via Attachment Download Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63099"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-63100",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.11315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "maybe-finance",
      "product": "maybe",
      "cwe": "CWE-862",
      "title": "Maybe 0.6.0 Missing Authorization via HostingsController show/update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63100"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-16017",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00209,
      "epss_percentile": 0.11442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mosaxiv",
      "product": "clawlet",
      "cwe": "CWE-862",
      "title": "mosaxiv clawlet cron Chat Tool tool_cron.go remove authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16017"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-12715",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.11119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google Cloud",
      "product": "Firebase Studio",
      "cwe": "CWE-862",
      "title": "Missing Authorization in Firebase Studio allows Cross-Tenant Source Code Theft",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12715"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-58149",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.1102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomdonation.com",
      "product": "Events Booking extension for Joomla",
      "cwe": "CWE-200",
      "title": "Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58149"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-13445",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.1082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-639",
      "title": "Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13445"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-7754",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-918",
      "title": "SSRF Protection Configuration Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7754"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-51083",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privileges to obtain hashed passwords via the cloudinit/dump API.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51083"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-15759",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeatelier",
      "product": "ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form",
      "cwe": "CWE-79",
      "title": "ChatHelp <= 3.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'number' and 'group' Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15759"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-16072",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-284",
      "title": "Keycloak-services: keycloak-services: organization invitation link exposure allows unauthorized member creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16072"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-16074",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00201,
      "epss_percentile": 0.10401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AstrBotDevs",
      "product": "AstrBot",
      "cwe": "CWE-918",
      "title": "AstrBotDevs AstrBot Plugin Update plugin.py update_all_plugins server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16074"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-49977",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AmauriC",
      "product": "tarteaucitron.js",
      "cwe": "CWE-285",
      "title": "tarteaucitron.js: data-cookie attribute can be used to delete arbitrary cookies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49977"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-16009",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System prescriptionorderdetail.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16009"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-15943",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-1288",
      "title": "Keycloak-services: keycloak-services: oidc idp update reuses masked client secret after token url change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15943"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-11966",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.1002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Registration & Membership",
      "cwe": "CWE-639",
      "title": "User Registration & Membership < 5.2.3 - Unauthenticated Limited User Deletion via Stripe Subscription Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11966"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-16103",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-841",
      "title": "Keycloak-services: keycloak-services: incomplete fix for ciba brute-force lockout bypass at token redemption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16103"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2024-23574",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Aftermarket EPC",
      "cwe": "CWE-204",
      "title": "HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. Use renumeration is when a malicious actor can use brute-force techniques to either guess or confirm valid users in a system",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23574"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2024-23575",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Aftermarket EPC",
      "cwe": "CWE-209",
      "title": "HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may use the contents of error messages to help launch another ,more focused attack.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23575"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2024-42214",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Aftermarket EPC",
      "cwe": "CWE-692",
      "title": "HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify their efforts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-42214"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-16108",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.0945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-200",
      "title": "Keycloak-services: keycloak-services: realm default-group reads disclose hidden groups under fgap v2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16108"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-49210",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00194,
      "epss_percentile": 0.09431,
      "kev": false,
      "kev_due_at": null,
      "vendor": "symfony",
      "product": "ux",
      "cwe": "CWE-79",
      "title": "Symfony UX: XSS in symfony/ux-live-component via attacker-controlled child component tag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49210"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-63309",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-863",
      "title": "SurrealDB < 3.1.5 Information Disclosure via ORDER BY",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63309"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-16106",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: incorrect authorization in admin role-composite deletion allows delegated admin to remove privileged child roles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16106"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-55254",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ncalc",
      "product": "ncalc",
      "cwe": "CWE-190",
      "title": "NCalc: Denial of Service via Unbounded and Non-Terminating Factorial Evaluation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55254"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-54243",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "statamic",
      "product": "cms",
      "cwe": "CWE-1236",
      "title": "Statamic: CSV formula injection in form submission exports",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54243"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-16073",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00191,
      "epss_percentile": 0.09116,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AstrBotDevs",
      "product": "AstrBot",
      "cwe": "CWE-79",
      "title": "AstrBotDevs AstrBot T2I Feature base.py NetworkRenderStrategy.render cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16073"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2024-23564",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00188,
      "epss_percentile": 0.08807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "Aftermarket EPC",
      "cwe": "CWE-326",
      "title": "HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23564"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-45703",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pimcore",
      "product": "pimcore",
      "cwe": "CWE-862",
      "title": "Pimcore: WordExport Authorization Bypass for Unauthorized Document Export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45703"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-48373",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Acrobat Reader",
      "cwe": "CWE-122",
      "title": "Acrobat Reader | Heap-based Buffer Overflow (CWE-122)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48373"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-63095",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.0811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "matrix-org",
      "product": "dendrite",
      "cwe": "CWE-639",
      "title": "Dendrite 0.13.8 Improper Authorization via POST account/3pid/delete Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63095"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-58317",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.0802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TeraTerm Project",
      "product": "TTSSH2",
      "cwe": "CWE-196",
      "title": "Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58317"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-60060",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.08021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TeraTerm Project",
      "product": "TTSSH2",
      "cwe": "CWE-130",
      "title": "Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60060"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-16093",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-807",
      "title": "Keycloak-services: keycloak-services: required signed-jwt assertion policy can be bypassed with unsigned assertion headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16093"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2024-23567",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07895,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Aftermarket EPC",
      "cwe": "CWE-804",
      "title": "HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data passed in this manner can be exposed because it may end up stored in unintended locations, including server logs, local browser history and proxy logs.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23567"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-15159",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.0761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SaturdayDrive",
      "product": "Ninja Forms - Excel Export",
      "cwe": "CWE-639",
      "title": "Ninja Forms - Excel Export <= 3.3.6 - Insecure Direct Object Reference to Authenticated (Subscriber+) Sensitive Data Disclosure via 'spreadsheet_export_form_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15159"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-15069",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Engineering AI Hub",
      "cwe": "CWE-78",
      "title": "Multiple Vulnerabilities in IBM Engineering AI hub.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15069"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-49216",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "symfony",
      "product": "ux",
      "cwe": "CWE-79",
      "title": "Symfony UX: XSS in symfony/ux-autocomplete via unescaped AJAX response data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49216"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2024-23569",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Aftermarket EPC",
      "cwe": "CWE-692",
      "title": "HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection\" header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23569"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2024-23571",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Aftermarket EPC",
      "cwe": "CWE-525",
      "title": "HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be cached. If sensitive information in application responses is stored in the local cache, then this may be retrieved by other users who have access to the same computer at a future time.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23571"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2024-23577",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Aftermarket EPC",
      "cwe": "CWE-20",
      "title": "HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol. When an application doesn’t adequately validate or sanitize this header, it can lead to several security risks, including Host header poisoning, server misconfigurations.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23577"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-4938",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.0723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Verify Identity Access",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in IBM Verify Identity Access and IBM Security Verify Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4938"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-10525",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.0716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "NEX-Forms",
      "cwe": "CWE-79",
      "title": "NEX-Forms < 9.2.3 - Unauthenticated Stored XSS via Form Submission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10525"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-54163",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "github",
      "product": "secure_headers",
      "cwe": "CWE-79",
      "title": "secure_headers: CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54163"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-54244",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00174,
      "epss_percentile": 0.07144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "statamic",
      "product": "cms",
      "cwe": "CWE-863",
      "title": "Statamic: Incorrect authorization lets view-only users submit Live Preview content reserved for editors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54244"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-62219",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw 2026.2.12 < 2026.5.26 Authorization Bypass via Blank Agent IDs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62219"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-62215",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-345",
      "title": "OpenClaw < 2026.6.5 Authentication Bypass via HTTP Canvas",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62215"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-63094",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06919,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SigNoz",
      "product": "signoz",
      "cwe": "CWE-345",
      "title": "SigNoz < 0.134.0 SSO OAuth State Manipulation Session Token Theft",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63094"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-21762",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "DevOps Loop",
      "cwe": "CWE-644",
      "title": "Missing HTTP Security Headers in DevOps Loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21762"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-62212",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-367",
      "title": "OpenClaw < 2026.5.28 Authentication Bypass via safeFetch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62212"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-12393",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPS Bookings for WooCommerce",
      "cwe": "CWE-639",
      "title": "WPS Bookings for WooCommerce < 3.11.7 - Subscriber+ Arbitrary Booking Order Cancellation via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12393"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-62235",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00169,
      "epss_percentile": 0.06719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-636",
      "title": "Grav Flex-Objects < 1.4.3 Authorization Bypass via API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62235"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-53712",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00167,
      "epss_percentile": 0.06437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ongres",
      "product": "scram",
      "cwe": "CWE-636",
      "title": "SCRAM: Silent channel-binding authentication downgrade via unsupported certificate algorithms",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53712"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-9762",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-94",
      "title": "IBM® Data Server driver for JDBC and SQLJ is vulnerable to remote code execution when jdbc url is under user control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9762"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2024-23570",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Aftermarket EPC",
      "cwe": "CWE-200",
      "title": "HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on his malicious site. The attacker can then launch a Clickjacking attack, which may lead to Phishing, Cross-Site Request Forgery, sensitive information leakage and more.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23570"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-49212",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "symfony",
      "product": "ux",
      "cwe": "CWE-345",
      "title": "Symfony UX: LiveComponentHydrator HMAC checksum lacks component and slot binding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49212"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-63097",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "matrix-org",
      "product": "dendrite",
      "cwe": "CWE-863",
      "title": "Dendrite 0.13.8 syncapi /context Endpoint Post-Leave State Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63097"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2024-23566",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Aftermarket EPC",
      "cwe": "CWE-804",
      "title": "HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force , automated attacks & account enumeration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23566"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-9656",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hubspotdev",
      "product": "HubSpot All-In-One Marketing – Forms, Popups, Live Chat",
      "cwe": "CWE-200",
      "title": "HubSpot All-In-One Marketing <= 11.3.62 - Authenticated (Contributor+) Sensitive Information Exposure via Block Editor Localized Script",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9656"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-50185",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00157,
      "epss_percentile": 0.0539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RustCrypto",
      "product": "utils",
      "cwe": "CWE-758",
      "title": "RustCrypto Cmov/CmovEq on aarch64 can produce wrong results if high-bits of registers are set",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50185"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-15161",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SaturdayDrive",
      "product": "Ninja Forms - Excel Export",
      "cwe": "CWE-79",
      "title": "Ninja Forms - Excel Export <= 3.3.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'filter' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15161"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2024-23573",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00155,
      "epss_percentile": 0.05199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Aftermarket EPC",
      "cwe": "CWE-425",
      "title": "HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be considered a type of man-in-the-middle attack.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23573"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-62224",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00155,
      "epss_percentile": 0.05218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openclaw",
      "product": "msteams",
      "cwe": "CWE-290",
      "title": "OpenClaw MS Teams < 2026.5.12 Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62224"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-9592",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00153,
      "epss_percentile": 0.04986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SEPPmail",
      "product": "SEPPmail Secure Email Gateway & SEPPmail Cloud",
      "cwe": "CWE-598",
      "title": "Sensitive Information Disclosure in HTTP header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9592"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-51081",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04614,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51081"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-49284",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "simplesamlphp",
      "product": "simplesamlphp",
      "cwe": "CWE-345",
      "title": "SimpleSAMLphp SP accepts a response from an unexpected IdP when unsigned `Response/InResponseTo` is combined with a signed assertion lacking `SubjectConfirmationData/InResponseTo`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49284"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-21760",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04567,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "DevOps Loop",
      "cwe": "CWE-425",
      "title": "Unauthorized Access to Admin Functionality via Forced Browsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21760"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-62225",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00148,
      "epss_percentile": 0.04503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw < 2026.5.18 Authorization Bypass via Skill Command Dispatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62225"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-54242",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00147,
      "epss_percentile": 0.04447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "statamic",
      "product": "cms",
      "cwe": "CWE-367",
      "title": "Statamic: Server-Side Request Forgery via Glide (DNS rebinding)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54242"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-21761",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "DevOps Loop",
      "cwe": "CWE-942",
      "title": "CORS Misconfiguration in DevOps Loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21761"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-49852",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00143,
      "epss_percentile": 0.04095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "authlib",
      "product": "joserfc",
      "cwe": "CWE-287",
      "title": "joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49852"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-62221",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00143,
      "epss_percentile": 0.04105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-863",
      "title": "OpenClaw 2026.5.12 < 2026.5.26 Authorization Bypass via allowFrom",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62221"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-16089",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.03995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-384",
      "title": "Keycloak-services: keycloak-services: authorization codes can be retargeted to another client session",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16089"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-57860",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tailcallhq",
      "product": "forgecode",
      "cwe": "CWE-829",
      "title": "ForgeCode Arbitrary Code Execution via Unvetted .mcp.json in Untrusted Repository",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57860"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-16118",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.0339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xdg",
      "product": "xdgmime",
      "cwe": "CWE-122",
      "title": "Xdgmime: heap-based buffer overflow in _xdg_mime_magic_parse_magic_line() in xdgmimemagic.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16118"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-45784",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00134,
      "epss_percentile": 0.03364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rust-openssl",
      "product": "rust-openssl",
      "cwe": "CWE-131",
      "title": "rust-openssl: Potential out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45784"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-21764",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "DevOps Loop",
      "cwe": "CWE-754",
      "title": "Insufficient Input Validation in DevOps Loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21764"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-60025",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.0311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomdonation.com",
      "product": "Events Booking extension for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60025"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-45785",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.03043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openmcdf",
      "product": "openmcdf",
      "cwe": "CWE-835",
      "title": "OpenMcdf: Uncatchable infinite loop in DirectoryTree.TryGetDirectoryEntry on crafted CFB directory cycle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45785"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2024-23578",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Aftermarket EPC",
      "cwe": "CWE-942",
      "title": "HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any domain (*-Wildcard).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23578"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-48022",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hapijs",
      "product": "wreck",
      "cwe": "CWE-319",
      "title": "@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48022"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-62222",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.02002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-829",
      "title": "OpenClaw < 2026.5.22 Untrusted Plugin Loading via Setup-mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62222"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-52584",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive information via the DecodeImageAPNG function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52584"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-15380",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Broadcom",
      "product": "Symantec Management Suite",
      "cwe": "CWE-269",
      "title": "Local privilege escalation in Symantec ITMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15380"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-49215",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00117,
      "epss_percentile": 0.01978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "symfony",
      "product": "ux",
      "cwe": "CWE-352",
      "title": "Symfony UX: CSRF Protection Bypass in symfony/ux-live-component — Accept Header is CORS-Safelisted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49215"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-49834",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sigstore",
      "product": "sigstore-go",
      "cwe": "CWE-347",
      "title": "sigstore-go: Multi-log threshold bypass via single compromised log",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49834"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-21770",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "HCL Traveler for Microsoft Outlook (HTMO)",
      "cwe": "CWE-427",
      "title": "HCL Traveler for Microsoft Outlook (HTMO) is susceptible to DLL hijacking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21770"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-62211",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenClaw",
      "product": "OpenClaw",
      "cwe": "CWE-532",
      "title": "OpenClaw < 2026.6.1 Credential Redaction Bypass via Trajectory Export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62211"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-7771",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-835",
      "title": "IBM® Db2® is vulnerable to a trap when compiling specially crafted statements containing subqueries could lead to a denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7771"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-41993",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TXOne Networks",
      "product": "SafePortAgent",
      "cwe": "CWE-284",
      "title": "Improper Access Control vulnerability in the Removable Media Validation function of TXOne Networks products allows a local attacker with administrator privileges to bypass the file lockdown mechanism, resulting in unauthorized file transfer to the victim device. The attacker needs to deploy unauthorized file on the removable media in advance. This issue affects SafePortAgent: before 3.2.5024; StellarProtect: from 3.2.4011 before 5.0.1083.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41993"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-15379",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Broadcom",
      "product": "Symantec IT Management Suite",
      "cwe": "CWE-269",
      "title": "Arbitrary File Read as SYSTEM in Symantec ITMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15379"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-14971",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00101,
      "epss_percentile": 0.01016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Novalink",
      "cwe": "CWE-16",
      "title": "This PowerVM Novalink update is being released to address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14971"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-15995",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.01048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Cognos Analytics",
      "cwe": "CWE-362",
      "title": "IBM Cognos Analytics 12.1.3 general availability package contains a data integrity issue in the Agentic AI assistant that may cause incorrect report summaries or report-processing errors under concurrent use",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15995"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-62236",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00099,
      "epss_percentile": 0.00921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-352",
      "title": "grav-plugin-login < 3.8.11 CSRF via regenerate2FASecret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62236"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-12705",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00098,
      "epss_percentile": 0.009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ABB",
      "product": "KNX Update Tool (ABB)",
      "cwe": "CWE-353",
      "title": "Integrity mechanism of KNX-device FW-files can be bypassed in ABB Update Tool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12705"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2019-25764",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0009,
      "epss_percentile": 0.00515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "AURA SYNC",
      "cwe": "CWE-782",
      "title": "**UNSUPPORTED WHEN ASSIGNED** Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's verification and invoke arbitrary IOCTLs, resulting in privilege escalation. Refer to the 'End-of-Life Notice and Driver Update for Legacy ASUS Drivers ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2019-25764"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-44722",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00087,
      "epss_percentile": 0.00435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danifus",
      "product": "pyzipper",
      "cwe": "CWE-480",
      "title": "pyzipper: Encryption bypass for small files encrypted with pyzipper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44722"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2024-23572",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00086,
      "epss_percentile": 0.00383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Aftermarket EPC",
      "cwe": "CWE-614",
      "title": "HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of the cookie to determine its function.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-23572"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2025-59866",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00074,
      "epss_percentile": 0.00093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "DFMPro for CATIA",
      "cwe": "CWE-732",
      "title": "The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables any logged-in non-administrative user to overwrite or replace the executable file with a malicious binary.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59866"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-60357",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-60357. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16014",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16014 (code-projects Hospital Bed Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16073",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16073 (AstrBotDevs AstrBot). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16074",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16074 (AstrBotDevs AstrBot). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44251",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44251 (wazuh). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44891",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44891 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45309",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45309 (ronf asyncssh). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45799",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45799 (square wire). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50185",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50185 (RustCrypto utils). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50289",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50289 (sebhildebrandt systeminformation). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-53727",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-53727 (premailer css_parser). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54497",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54497 (ViewComponent view_component). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54498",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54498 (ViewComponent view_component). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56740",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56740 (jline3). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56741",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56741 (jline3). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-62238",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-62238 (openremote). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-62241",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-62241 (MohibShaikh clawvet). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63094",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63094 (signoz). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63100",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63100 (maybe-finance maybe). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2008-4128",
      "detail": "DUE DATE PASSED — CVE-2008-4128 (Cisco IOS). CISA remediation deadline was July 16, 2026; still in catalog."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
