{
  "day": "2026-07-20",
  "boundary": "UTC calendar day",
  "published_count": 266,
  "by_severity": {
    "CRITICAL": 48,
    "HIGH": 99,
    "MEDIUM": 115,
    "LOW": 4
  },
  "kev_count": 0,
  "exploit_reference_count": 23,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-63108",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01919,
      "epss_percentile": 0.78248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RooCodeInc",
      "product": "Roo-Code",
      "cwe": "CWE-184",
      "title": "Roo Code 3.54.0 Command Injection via Parameter Expansion Parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63108"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-63766",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01749,
      "epss_percentile": 0.76025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RVC-Boss",
      "product": "GPT-SoVITS",
      "cwe": "CWE-78",
      "title": "GPT-SoVITS 20250606v2pro OS Command Injection via webui.py",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63766"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-27823",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01028,
      "epss_percentile": 0.60926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGroupware",
      "product": "egroupware",
      "cwe": "CWE-285",
      "title": "Remote Code Execution Vulnerability in EGroupware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27823"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-40187",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00933,
      "epss_percentile": 0.57939,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EGroupware",
      "product": "egroupware",
      "cwe": "CWE-78",
      "title": "Authenticated RCE via Malicious eTemplate Upload in EGroupware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40187"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-13147",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00912,
      "epss_percentile": 0.57244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Kirki",
      "cwe": null,
      "title": "Kirki < 6.0.12 - Unauthenticated Server-Side Request Forgery via kirki_get_apis",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13147"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-64620",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00851,
      "epss_percentile": 0.55356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-122",
      "title": "FreeRDP before 3.28.0 Heap Buffer Overflow via crypto_rsa_common",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64620"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-51026",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00848,
      "epss_percentile": 0.55244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-23",
      "title": "Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a crafted request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51026"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-64193",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00828,
      "epss_percentile": 0.54665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLNETLABS",
      "product": "Net::DNS",
      "cwe": "CWE-95",
      "title": "Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64193"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-16242",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00798,
      "epss_percentile": 0.53672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "multicluster engine for Kubernetes 2.1",
      "cwe": "CWE-306",
      "title": "Hypershift: konnectivity proxy-server accepts agent connections without validating client certificates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16242"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-14448",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00765,
      "epss_percentile": 0.52607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MB connect line",
      "product": "mbCONNECT24",
      "cwe": "CWE-78",
      "title": "Authenticated RCE in system_certificates view",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14448"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-12701",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00759,
      "epss_percentile": 0.524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-22",
      "title": "Pulpcore: pulpcore: relative_path_validator bypass via directory traversal in filesystemexport",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12701"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-63767",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00742,
      "epss_percentile": 0.51857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kvcache-ai",
      "product": "ktransformers",
      "cwe": "CWE-502",
      "title": "ktransformers Unauthenticated Pickle Deserialization RCE via ZMQ",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63767"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-16327",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00728,
      "epss_percentile": 0.51354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "D-Link",
      "product": "DNS-320",
      "cwe": "CWE-284",
      "title": "D-Link DNS-320 upload.php unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16327"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-53421",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00678,
      "epss_percentile": 0.49519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-653",
      "title": "Apache Syncope: Remote Code Execution via Scripted Connector",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53421"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-41252",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00609,
      "epss_percentile": 0.46482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "neutrinolabs",
      "product": "xrdp",
      "cwe": "CWE-122",
      "title": "xrdp: lib_palette_update Heap Buffer Overflow & RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41252"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-32820",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00603,
      "epss_percentile": 0.46236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "datacycle-engine",
      "product": "dataCycle-CORE",
      "cwe": "CWE-22",
      "title": "dataCycle Public Markdown Path Traversal Via /docs/*path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32820"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-56623",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00593,
      "epss_percentile": 0.45774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache MINA SSHD",
      "cwe": "CWE-22",
      "title": "Apache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56623"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-56452",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00569,
      "epss_percentile": 0.44616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache MINA SSHD",
      "cwe": "CWE-22",
      "title": "Apache MINA SSHD: Path traversal in SCP file reception",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56452"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-44178",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00512,
      "epss_percentile": 0.41463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "neutrinolabs",
      "product": "xrdp",
      "cwe": "CWE-122",
      "title": "xrdp: Channel Data Forwarding Fixed-Size Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44178"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-52656",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0051,
      "epss_percentile": 0.41359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary code via a crafted FEX file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52656"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-63090",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00502,
      "epss_percentile": 0.40915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "proftpd",
      "product": "proftpd",
      "cwe": "CWE-122",
      "title": "ProFTPD mod_sftp Heap Buffer Overflow via SFTP Packet Reassembly",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63090"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-57308",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00496,
      "epss_percentile": 0.40546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-89",
      "title": "Apache Syncope: SQL injection vulnerability in Audit Events search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57308"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-16248",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00466,
      "epss_percentile": 0.38643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenda",
      "product": "AC10",
      "cwe": "CWE-119",
      "title": "Tenda AC10 httpd/netctrl AdvSetLanip fromAdvSetLanip stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16248"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-53405",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00445,
      "epss_percentile": 0.37176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-653",
      "title": "Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53405"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-63071",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00439,
      "epss_percentile": 0.36738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-653",
      "title": "Apache Syncope: RCE via Groovy Sandbox bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63071"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-64194",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00433,
      "epss_percentile": 0.36248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLNETLABS",
      "product": "Net::DNS",
      "cwe": "CWE-674",
      "title": "Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64194"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2024-51311",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00427,
      "epss_percentile": 0.35828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-51311"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-8170",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00425,
      "epss_percentile": 0.35639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Extreme Networks",
      "product": "Switch Engine (EXOS)",
      "cwe": "CWE-59",
      "title": "ExtremeXOS Privilege Escalation via Symlink Following in File Utilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8170"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-46412",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00424,
      "epss_percentile": 0.35571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BeProduct",
      "product": "beproduct-org-nestjs-auth",
      "cwe": "CWE-506",
      "title": "Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46412"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-57852",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00424,
      "epss_percentile": 0.35552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Trilby Media",
      "product": "Grav CMS scheduler-webhook plugin",
      "cwe": "CWE-303",
      "title": "Authentication Bypass via Null Short-Circuit in Grav CMS Scheduler Webhook Token Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57852"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-58624",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00424,
      "epss_percentile": 0.35575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache MINA SSHD",
      "cwe": "CWE-20",
      "title": "Apache MINA SSHD: Remote execution of JGit commands can write files on the server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58624"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-55831",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-400",
      "title": "Netty SPDY SETTINGS frame count materializes unbounded settings map",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55831"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-55833",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-400",
      "title": "Netty SPDY zlib header block continues decoded expansion after maxHeaderSize truncation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55833"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-48824",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00421,
      "epss_percentile": 0.35331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axllent",
      "product": "mailpit",
      "cwe": "CWE-770",
      "title": "Mailpit: Sibling-endpoint memory-exhaustion DoS via unbounded JSON body on /api/v1/messages, /api/v1/tags, and /api/v1/message/{id}/release (incomplete fix of GHSA-fpxj-m5q8-fphw)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48824"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2024-51312",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00419,
      "epss_percentile": 0.35099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-51312"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2024-51313",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00419,
      "epss_percentile": 0.351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-51313"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2024-51314",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00419,
      "epss_percentile": 0.351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-51314"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2024-51315",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00419,
      "epss_percentile": 0.351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-51315"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-42210",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00418,
      "epss_percentile": 0.35035,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webmin",
      "product": "webmin",
      "cwe": "CWE-287",
      "title": "Webmin 2FA requirement bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42210"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-26080",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00416,
      "epss_percentile": 0.3487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HAProxy",
      "product": "HAProxy",
      "cwe": "CWE-252",
      "title": "HAProxy Community Edition 3.2.x through 3.3.x before 3.3.3 can enter a loop or crash because varint is mishandled. HAProxy Enterprise and ALOHA are also affected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26080"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-62183",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00411,
      "epss_percentile": 0.34449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-269",
      "title": "Apache Syncope: User self-service privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62183"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-64622",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00408,
      "epss_percentile": 0.34198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jovancoding",
      "product": "Network-AI",
      "cwe": "CWE-862",
      "title": "Network-AI 5.12.2 through 5.13.3 Missing Authorization via ApprovalInbox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64622"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-45797",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00404,
      "epss_percentile": 0.33803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "heyform",
      "product": "heyform",
      "cwe": "CWE-79",
      "title": "HeyForm Vulnerable to Stored XSS via Unauthenticated SVG File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45797"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-51385",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00401,
      "epss_percentile": 0.33505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fetch, _build_opener, _fetch_html and _download_binary functions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51385"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-16337",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.004,
      "epss_percentile": 0.33416,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dotCMS",
      "product": "dotCMS",
      "cwe": "CWE-269",
      "title": "Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a low-privileged authenticated backend user to self-assign the administrative layout and self-grant the CMS Administrator role, then achieve remote code execution via a crafted OSGi bundle upload whose BundleActivator executes arbitrary shell commands.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16337"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-28220",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.3294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wazuh",
      "product": "wazuh",
      "cwe": "CWE-502",
      "title": "Wazuh cluster DAPI arbitrary callable deserialization and RBAC context injection allow a cluster peer to execute privileged functions on the master node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28220"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-41521",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00392,
      "epss_percentile": 0.32461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "neutrinolabs",
      "product": "xrdp",
      "cwe": "CWE-190",
      "title": "xrdp: lib_framebuffer_update Has Integer Overflow Heap Info Leak & ASLR Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41521"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-45713",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00388,
      "epss_percentile": 0.3215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axllent",
      "product": "mailpit",
      "cwe": "CWE-400",
      "title": "Mailpit: Unauthenticated remote memory-exhaustion DoS via unlimited SMTP DATA and /api/v1/send body sizes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45713"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-15903",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00387,
      "epss_percentile": 0.32051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15903"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-54538",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "neutrinolabs",
      "product": "xrdp",
      "cwe": "CWE-835",
      "title": "xrdp: Pre-auth infinite loop via totalLength=0 in TS_SHARECONTROLHEADER",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54538"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-53595",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00374,
      "epss_percentile": 0.30663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "freescout-help-desk",
      "product": "freescout",
      "cwe": "CWE-178",
      "title": "FreeScout vulnerable to anonymous account takeover via /user-setup empty invite_hash on MySQL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53595"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-57311",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00374,
      "epss_percentile": 0.30654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JCD",
      "product": "Windu CMS",
      "cwe": "CWE-434",
      "title": "Unrestricted Upload of File with Dangerous Type in Windu CMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57311"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-54051",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0037,
      "epss_percentile": 0.30291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jovancoding",
      "product": "Network-AI",
      "cwe": "CWE-78",
      "title": "Network-AI has an an OS Command Injection issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54051"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-48812",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00368,
      "epss_percentile": 0.30054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "freescout-help-desk",
      "product": "freescout",
      "cwe": "CWE-287",
      "title": "FreeScout Allows Unauthenticated Access to Legacy Attachment Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48812"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-26081",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00363,
      "epss_percentile": 0.29509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HAProxy",
      "product": "HAProxy",
      "cwe": "CWE-130",
      "title": "HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN format. HAProxy Enterprise and ALOHA are also affected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26081"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-63747",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00359,
      "epss_percentile": 0.29111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-248",
      "title": "SurrealDB before 3.1.0 Denial of Service via malformed RPC use",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63747"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-63760",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00359,
      "epss_percentile": 0.29111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-674",
      "title": "SurrealDB before 3.1.0 Denial of Service via JSON Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63760"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-16235",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00357,
      "epss_percentile": 0.28951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DRSTEVE",
      "product": "Crypt::Password",
      "cwe": "CWE-338",
      "title": "Crypt::Password versions through 0.28 for Perl generate insecure random values for salts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16235"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-63739",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00356,
      "epss_percentile": 0.28854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-22",
      "title": "SurrealDB before 3.1.5 Arbitrary File Read via DEFINE ANALYZER",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63739"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-63757",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.28702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-306",
      "title": "SurrealDB before 3.1.0 Session Hijacking via /rpc sessions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63757"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-64625",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00351,
      "epss_percentile": 0.28344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-78",
      "title": "AVideo before 29.0 OS Command Injection via execAsync",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64625"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-53594",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00351,
      "epss_percentile": 0.28336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "freescout-help-desk",
      "product": "freescout",
      "cwe": "CWE-22",
      "title": "FreeScout has Arbitrary File Read in App Logs Viewer via Forged Encrypted Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53594"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-64612",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.28143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-248",
      "title": "Libcupsfilters: cups-filters: libcupsfilters: cups image filter process abort via malformed png",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64612"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-15902",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00349,
      "epss_percentile": 0.28044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15902"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-60027",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themexpert.com",
      "product": "Quix Page Builder Pro extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60027"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-63737",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-674",
      "title": "SurrealDB before 3.1.5 Denial of Service via deep operator chains",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63737"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-25039",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Scille",
      "product": "parsec-cloud",
      "cwe": "CWE-40",
      "title": "The application evaluate UNC path in workspace name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25039"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2024-51316",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /goform/SetOnlineDevName",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-51316"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-51027",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00342,
      "epss_percentile": 0.27384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51027"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-59238",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00332,
      "epss_percentile": 0.26165,
      "kev": false,
      "kev_due_at": null,
      "vendor": "maalfer",
      "product": "Pentestify",
      "cwe": "CWE-79",
      "title": "Stored XSS in Pentestify via unsanitized finding images and report client logo",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59238"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-15901",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00331,
      "epss_percentile": 0.26102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15901"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-63734",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00329,
      "epss_percentile": 0.25844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-20",
      "title": "SurrealDB before 3.2.0 Denial of Service via malformed SurrealML import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63734"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-61425",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00328,
      "epss_percentile": 0.25738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "balbooa.com",
      "product": "Gridbox extension for Joomla",
      "cwe": "CWE-288",
      "title": "Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61425"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-44583",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00326,
      "epss_percentile": 0.25523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paymenter",
      "product": "Paymenter",
      "cwe": "CWE-918",
      "title": "Paymenter: Blind Unauthenticated SSRF on the Paypal gateway module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44583"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-35048",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00322,
      "epss_percentile": 0.25067,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Piwigo",
      "product": "Piwigo",
      "cwe": "CWE-20",
      "title": "Piwigo RCE via PHP Code Injection into Config File in Installer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35048"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-11349",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.25023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Modern Event Calendar Pro",
      "cwe": "CWE-89",
      "title": "Modern Events Calendar (Lite & Pro) < 7.34.0 - Unauthenticated SQL Injection via mec_list_load_more",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11349"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-6656",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.24512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DRSTEVE",
      "product": "Crypt::Password",
      "cwe": "CWE-208",
      "title": "Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6656"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-57309",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00314,
      "epss_percentile": 0.24201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JCD",
      "product": "Windu CMS",
      "cwe": "CWE-89",
      "title": "Blind SQL Injection in Windu CMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57309"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-44978",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.24256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "neutrinolabs",
      "product": "xrdp",
      "cwe": "CWE-20",
      "title": "xrdp: Unchecked FIPS padding length in standard RDP Security causes heap out-of-bounds read in HMAC verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44978"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-60026",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.2391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themexpert.com",
      "product": "Quix Page Builder Pro extension for Joomla",
      "cwe": "CWE-94",
      "title": "Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60026"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-45711",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.2392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axllent",
      "product": "mailpit",
      "cwe": "CWE-22",
      "title": "Mailpit: Path traversal & arbitrary file write in mailpit dump --http via attacker-controlled message IDs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45711"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-12898",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "All-in-One WP Migration and Backup",
      "cwe": "CWE-22",
      "title": "All-in-One WP Migration and Backup < 7.106 - Unauthenticated Arbitrary-Location Log File Write via Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12898"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-54910",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23392,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gtsteffaniak",
      "product": "filebrowser",
      "cwe": "CWE-22",
      "title": "FileBrowser Quantum's path traversal issue in subtitle handler allows any authenticated user to read arbitrary files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54910"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-55238",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.23225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "neutrinolabs",
      "product": "xrdp",
      "cwe": "CWE-126",
      "title": "xrdp: Malformed Confirm Active capability sets cause out-of-bounds reads",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55238"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-64621",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00304,
      "epss_percentile": 0.2307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-415",
      "title": "FreeRDP before 3.28.0 Double-Free via selectedmonitors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64621"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-62418",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Syncope",
      "cwe": "CWE-918",
      "title": "Apache Syncope: Low-privileged authenticated SSRF in Connectors and Resources check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62418"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-15899",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00298,
      "epss_percentile": 0.22435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15899"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-15900",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00298,
      "epss_percentile": 0.22435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15900"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-15904",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15904"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-63429",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00298,
      "epss_percentile": 0.22436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "heyform",
      "product": "heyform",
      "cwe": "CWE-306",
      "title": "HeyForm has unauthenticated /api/upload endpoint that accepts arbitrary files with no auth/session/form context",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63429"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-32824",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "datacycle-engine",
      "product": "dataCycle-CORE",
      "cwe": "CWE-601",
      "title": "dataCycle User API Password Reset And Confirmation Flows Trust Attacker- Controlled Redirect Targets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32824"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-32825",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "datacycle-engine",
      "product": "dataCycle-CORE",
      "cwe": "CWE-307",
      "title": "dataCycle No Brute-Force Protection On Web And API Login Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32825"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-63091",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.22091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "proftpd",
      "product": "proftpd",
      "cwe": "CWE-126",
      "title": "ProFTPD mod_sftp Signed Integer Overflow via SCP Size-Record Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63091"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-10081",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Unlimited Elements For Elementor",
      "cwe": "CWE-79",
      "title": "Unlimited Elements for Elementor < 2.0.11 - Unauthenticated Stored XSS via Google Reviews Widget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10081"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-34239",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chamilo",
      "product": "chamilo-lms",
      "cwe": "CWE-285",
      "title": "Chamilo Authenticated Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34239"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-13577",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CROMEDOME",
      "product": "Dancer2",
      "cwe": "CWE-338",
      "title": "Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13577"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-51031",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-918",
      "title": "FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. This allows a remote attacker to obtain sensitive information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51031"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-47198",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paymenter",
      "product": "Paymenter",
      "cwe": "CWE-20",
      "title": "Paymenter: URL parameter injection bypasses paid plan limits at checkout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47198"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-32806",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "datacycle-engine",
      "product": "dataCycle-CORE",
      "cwe": "CWE-285",
      "title": "dataCycle Authorization Bypass Via /remote_render",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32806"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-32807",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "datacycle-engine",
      "product": "dataCycle-CORE",
      "cwe": "CWE-285",
      "title": "dataCycle Public DataLink Text File Download Ignores Validity And Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32807"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-63746",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-200",
      "title": "SurrealDB before 3.1.0 Permission Bypass via Graph Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63746"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-53593",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "freescout-help-desk",
      "product": "freescout",
      "cwe": "CWE-434",
      "title": "FreeScout Vulnerable to Authenticated Remote Code Execution via incomplete upload extension denylist (.pht) — bypass of CVE-2025-48471",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53593"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-55645",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00283,
      "epss_percentile": 0.2088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "neutrinolabs",
      "product": "xrdp",
      "cwe": "CWE-125",
      "title": "xrdp: Out-of-bounds read in Client Control PDU processing (xrdp_rdp_process_data_control)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55645"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-57495",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00281,
      "epss_percentile": 0.20673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "agenticmail",
      "product": "@agenticmail/core",
      "cwe": "CWE-306",
      "title": "AgenticMail: Unauthenticated inbound mail triggers bypassPermissions resume of the operator's Claude Code session (bridge-wake)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57495"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-46715",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.20479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pallets-eco",
      "product": "Flask-Security-Too",
      "cwe": "CWE-287",
      "title": "Flask-Security-Too OAuth reauthentication freshness bypass via cross- user OAuth identity acceptance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46715"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-8169",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Extreme Networks",
      "product": "Switch Engine (EXOS)",
      "cwe": "CWE-338",
      "title": "ExtremeXOS Debug-Mode Privilege Escalation via Weak PRNG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8169"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-63750",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-770",
      "title": "SurrealDB before 3.1.0 Memory Amplification via /sql WebSocket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63750"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-16277",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-121",
      "title": "Rpcbind: rpcbind: stack buffer overflow in rpcinfo rpcbaddrlist()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16277"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-16324",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Metasoft 美特软件",
      "product": "MetaCRM",
      "cwe": "CWE-284",
      "title": "Metasoft 美特软件 MetaCRM upload.jsp unrestricted upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16324"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-15788",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.19875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "moby",
      "product": "BuildKit",
      "cwe": "CWE-59",
      "title": "WCOW cache mount source selector resolves NTFS junctions outside of cache root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15788"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-63763",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-639",
      "title": "SurrealDB before 2.5.0 Privilege Escalation via Future Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63763"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-16254",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Security 4",
      "cwe": "CWE-125",
      "title": "Claircore: claircore: denial of service via out-of-bounds slice in claircore's apk installed-database parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16254"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-63756",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0027,
      "epss_percentile": 0.19349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-362",
      "title": "SurrealDB before 3.1.0 Privilege Escalation via RPC Session Race Condition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63756"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-54685",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gtsteffaniak",
      "product": "filebrowser",
      "cwe": "CWE-208",
      "title": "FileBrowser Quantum has Username Enumeration via Authentication Timing Side-Channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54685"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-15813",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.1915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-787",
      "title": "Kronosnet: kronosnet: memory corruption and out-of-bounds access via malformed network packet defragmentation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15813"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-45139",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00267,
      "epss_percentile": 0.18928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ci4-cms-erp",
      "product": "ci4ms",
      "cwe": "CWE-73",
      "title": "CI4MS Fileeditor allows deletion and rename of critical application files due to missing extension allowlist on destructive operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45139"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-26197",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00267,
      "epss_percentile": 0.18945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HDFGroup",
      "product": "hdf5",
      "cwe": "CWE-125",
      "title": "Array full size, element count, and element size are not checked to make sure they match in H5Odtype.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26197"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-63741",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-862",
      "title": "SurrealDB before 3.1.0 Authentication Bypass via USE statement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63741"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-45709",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00265,
      "epss_percentile": 0.1854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axllent",
      "product": "mailpit",
      "cwe": "CWE-918",
      "title": "Mailpit has an incomplete fix for GHSA-6jxm: HTML check still permits SSRF to private/loopback/IMDS via missing IP-filter dialer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45709"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-61424",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00263,
      "epss_percentile": 0.18228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dj-extensions.com",
      "product": "DJ-Classifieds extension for Joomla",
      "cwe": "CWE-434",
      "title": "Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61424"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-61900",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00263,
      "epss_percentile": 0.18227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dj-extensions.com",
      "product": "jDownloads extension for Joomla",
      "cwe": "CWE-434",
      "title": "Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61900"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-46410",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gtsteffaniak",
      "product": "filebrowser",
      "cwe": "CWE-200",
      "title": "FileBrowser Quantum: unauthenticated user share share info",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46410"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-63735",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-639",
      "title": "SurrealDB before 3.2.0 Authentication Bypass via Custom API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63735"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-16252",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Beijing Shenzhou Shihan Technology",
      "product": "Multimedia Integrated Business Display System",
      "cwe": "CWE-74",
      "title": "Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System Staffshinel Ds.jsp sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16252"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-64206",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.1818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64206"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-46516",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.17974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mwtcmi",
      "product": "frogman",
      "cwe": "CWE-79",
      "title": "Frogman vulnerable to stored XSS in chat console formatter (escalation vector in multi-admin deployments)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46516"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-63740",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-863",
      "title": "SurrealDB before 3.1.4 Array Element Permission Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63740"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-26199",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00256,
      "epss_percentile": 0.17408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HDFGroup",
      "product": "hdf5",
      "cwe": "CWE-124",
      "title": "Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26199"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-63754",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.17196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-754",
      "title": "SurrealDB before 3.1.0 Denial of Service via LIVE Query",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63754"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-63759",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.17197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-674",
      "title": "SurrealDB before 3.1.0 Denial of Service nested type annotations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63759"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-63762",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-476",
      "title": "SurrealDB before v2.6.1 Denial of Service via scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63762"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-55639",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "neutrinolabs",
      "product": "xrdp",
      "cwe": "CWE-125",
      "title": "xrdp: Out-of-bounds read in GCC Conference Create Request CS_SECURITY processing (xrdp_sec_process_mcs_data_CS_SECURITY)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55639"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-52349",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.16999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-22",
      "title": "Directory Traversal vulnerability in Menyoo 2.0 Versions before commit 729aa48: fixed in commit 729aa48 allows a local attacker to execute arbitrary code via the Spooner file management, VehicleSpawner save/folder/rename functionality, WeaponOptions save/folder/rename functionality, PedComponentChanger create folder/createfile/rename functionality.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52349"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-60031",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.1699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themexpert.com",
      "product": "Quix Page Builder Pro extension for Joomla",
      "cwe": "CWE-200",
      "title": "Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60031"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-42218",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "neutrinolabs",
      "product": "xrdp",
      "cwe": "CWE-204",
      "title": "XRDP is vulnerable to a server timing attack, leading to user enumeration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42218"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-44231",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00249,
      "epss_percentile": 0.1651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bestpractical",
      "product": "rt",
      "cwe": "CWE-200",
      "title": "RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44231"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-63428",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "heyform",
      "product": "heyform",
      "cwe": "CWE-20",
      "title": "HeyForm: completeSubmission persists submitter-supplied hidden fields verbatim without validating against the form's declared hidden-field set",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63428"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-60034",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00247,
      "epss_percentile": 0.16245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themexpert.com",
      "product": "JMedia extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60034"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-60028",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00247,
      "epss_percentile": 0.16245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themexpert.com",
      "product": "Quix Page Builder Pro extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60028"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-45712",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axllent",
      "product": "mailpit",
      "cwe": "CWE-362",
      "title": "Mailpit: Concurrent map read & write in proxy CSS rewriter - remote unauth crash (fatal error: concurrent map read and map write)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45712"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-60029",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00247,
      "epss_percentile": 0.16245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themexpert.com",
      "product": "Quix Page Builder Pro extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60029"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-63102",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rConfig",
      "product": "rConfig v8 Core",
      "cwe": "CWE-915",
      "title": "rConfig Core < 8.2.8 Privilege Escalation via Users API role field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63102"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-63771",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vrana",
      "product": "adminer",
      "cwe": "CWE-113",
      "title": "Adminer < 5.4.3 Cookie Injection via X-Forwarded-Prefix Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63771"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-60032",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00242,
      "epss_percentile": 0.15622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themexpert.com",
      "product": "JMedia extension for Joomla",
      "cwe": "CWE-434",
      "title": "Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60032"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-60030",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themexpert.com",
      "product": "Quix Page Builder Pro extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60030"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-50743",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Revive",
      "product": "Adserver",
      "cwe": "CWE-352",
      "title": "A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be triggered via crafted GET or POST requests without any verification of the CSRF token, allowing an attacker to perform these actions on behalf of an authenticated administrator.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50743"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-63731",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hyperdxio",
      "product": "hyperdx",
      "cwe": "CWE-918",
      "title": "HyperDX < 2.31.0 SSRF via ClickHouse Proxy Test Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63731"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-53596",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "freescout-help-desk",
      "product": "freescout",
      "cwe": "CWE-400",
      "title": "FreeScout has unrestricted file upload without rate limiting that leads to resource exhaustion (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53596"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-39878",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00236,
      "epss_percentile": 0.1486,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chamilo",
      "product": "chamilo-lms",
      "cwe": "CWE-79",
      "title": "Chamilo stored XSS via user registration leads to admin account takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39878"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-21824",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14852,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Commerce",
      "cwe": "CWE-266",
      "title": "A privilege escalation vulnerability affects HCL Commerce",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21824"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-13380",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00235,
      "epss_percentile": 0.14688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VSee",
      "product": "Clinic",
      "cwe": "CWE-201",
      "title": "VSee Clinic and API Exposes Cleartext SFTP Credentials in Unauthenticated HTTP Responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13380"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-47276",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nanomq",
      "product": "nanomq",
      "cwe": "CWE-476",
      "title": "NULL Pointer Dereference in REST API properties_parse via Malformed user_properties",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47276"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-35198",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00234,
      "epss_percentile": 0.14545,
      "kev": false,
      "kev_due_at": null,
      "vendor": "heyform",
      "product": "heyform",
      "cwe": "CWE-79",
      "title": "HeyForm vulnerable to stored XSS via form field titles",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35198"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-8825",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Elementor Website Builder",
      "cwe": "CWE-200",
      "title": "Elementor < 4.1.4 - Contributor+ Sensitive Information Disclosure via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8825"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-63730",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.14439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hyperdxio",
      "product": "hyperdx",
      "cwe": "CWE-918",
      "title": "HyperDX < 2.31.0 SSRF via Webhook Test Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63730"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-63744",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.14492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-918",
      "title": "SurrealDB before 3.1.5 SSRF via JWKS URL Redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63744"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-62414",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00232,
      "epss_percentile": 0.14346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomlack.fr",
      "product": "Page Builder CK extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62414"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-63769",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "huginn",
      "product": "huginn",
      "cwe": "CWE-918",
      "title": "Huginn 2022.08.18 SSRF via ScenarioImport fetch_url Method",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63769"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-60033",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themexpert.com",
      "product": "JMedia extension for Joomla",
      "cwe": "CWE-918",
      "title": "Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60033"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-13142",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Social Login, Passkeys, Magic Link & Email OTP",
      "cwe": "CWE-269",
      "title": "Passwordless Login by VentraConnect < 1.4.1 - Unauthenticated Account Takeover via Email OTP Brute Force",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13142"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-63736",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-918",
      "title": "SurrealDB before 3.2.0 SSRF via JWKS URL hostname resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63736"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-47129",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00223,
      "epss_percentile": 0.13142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pdovhomilja",
      "product": "nextcrm-app",
      "cwe": "CWE-862",
      "title": "NextCRM has Broken Access Control in Server Actions that allows any authenticated user to deactivate/activate arbitrary accounts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47129"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-46701",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00223,
      "epss_percentile": 0.13202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jovancoding",
      "product": "Network-AI",
      "cwe": "CWE-346",
      "title": "Network-AI: Unauthenticated Cross-Origin MCP Tool Invocation via Empty Default Secret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46701"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-39385",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.12755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "frappe",
      "product": "lms",
      "cwe": "CWE-288",
      "title": "Frappe LMS enrollment bypass in paid courses via unrelated batch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39385"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-57494",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.12754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "agenticmail",
      "product": "@agenticmail/api",
      "cwe": "CWE-639",
      "title": "AgenticMail: Cross-agent task authorization bypass in AgenticMail API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57494"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-12341",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00216,
      "epss_percentile": 0.12382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SailPoint Technologies",
      "product": "IdentityIQ",
      "cwe": "CWE-287",
      "title": "SailPoint IdentityIQ Improper Bearer Token Validation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12341"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-53591",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "freescout-help-desk",
      "product": "freescout",
      "cwe": "CWE-287",
      "title": "FreeScout Vulnerable to Unauthenticated Conversation Thread Injection via HMAC Length Bypass in FetchEmails",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53591"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-51025",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary code via the ClientMessageController.java file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51025"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-32822",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "datacycle-engine",
      "product": "dataCycle-CORE",
      "cwe": "CWE-80",
      "title": "dataCycle Unauthenticated Reflected DOM XSS Via flash[...] On Public Pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32822"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-63742",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-863",
      "title": "SurrealDB before 3.1.0 Field Permission Bypass via Indexed COUNT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63742"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-63755",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11552,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-863",
      "title": "SurrealDB before 3.1.0 Permission Bypass via WHERE Clause",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63755"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-63749",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-863",
      "title": "SurrealDB before 3.1.0 Authentication Bypass via LIVE SELECT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63749"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-13381",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.11314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VSee",
      "product": "Clinic",
      "cwe": "CWE-639",
      "title": "VSee Clinic and API Insecure Direct Object Reference in File API Allows Unauthorized File Access and Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13381"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-63107",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LimeSurvey",
      "product": "LimeSurvey",
      "cwe": "CWE-918",
      "title": "LimeSurvey SSRF via REST API Survey Template Host Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63107"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-45270",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.11118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ci4-cms-erp",
      "product": "ci4ms",
      "cwe": "CWE-79",
      "title": "CI4MS: Stored XSS in Pages Module Content via Broken html_purify Validation Rule",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45270"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-58484",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00207,
      "epss_percentile": 0.11161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jovancoding",
      "product": "Network-AI",
      "cwe": "CWE-22",
      "title": "Network-AI: Poisoned environment backup manifest allows arbitrary recursive deletion during backup pruning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58484"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-12592",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.10771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "SlimStat Analytics",
      "cwe": "CWE-79",
      "title": "SlimStat Analytics < 5.5.0 - Unauthenticated Stored XSS via CF-IPCountry Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12592"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-63738",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-863",
      "title": "SurrealDB 3.1.0 before 3.1.5 Field Permission Bypass via Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63738"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-63753",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.1074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-613",
      "title": "SurrealDB before 3.1.0 Authentication Bypass via LIVE Query",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63753"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-58481",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jovancoding",
      "product": "Network-AI",
      "cwe": "CWE-22",
      "title": "Network-AI: AgentRuntime sandbox path-prefix checks allow file access outside the configured base directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58481"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-58413",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jovancoding",
      "product": "Network-AI",
      "cwe": "CWE-22",
      "title": "EnvironmentManager.restore() backup ID path traversal copies arbitrary directories into environment data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58413"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-58414",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10576,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jovancoding",
      "product": "Network-AI",
      "cwe": "CWE-22",
      "title": "Network-AI: EnvironmentManager.backup() follows symlinked directories and copies files outside the environment root into backups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58414"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-12723",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Kirki",
      "cwe": "CWE-862",
      "title": "Kirki < 6.0.12 - Unauthenticated Arbitrary Comment Modification and Moderation Bypass via Component Library",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12723"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-64619",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vastsa",
      "product": "FileCodeBox",
      "cwe": "CWE-348",
      "title": "FileCodeBox < 2.4 Anti-bruteforce Rate Limit Bypass via Spoofed Headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64619"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-13724",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co.",
      "product": "Corporate Training Management System",
      "cwe": "CWE-602",
      "title": "Business Logic Bypass in Gobito's Corporate Training Management System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13724"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-32821",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.10307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "datacycle-engine",
      "product": "dataCycle-CORE",
      "cwe": "CWE-285",
      "title": "API Collection Impersonation Via user_email And Missing Object- Level Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32821"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-63733",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-863",
      "title": "SurrealDB before 3.2.0 Permissions Bypass via PERMISSIONS Clause",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63733"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-64623",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.002,
      "epss_percentile": 0.10149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jovancoding",
      "product": "Network-AI",
      "cwe": "CWE-347",
      "title": "Network-AI before 5.13.4 Cryptographic Signature Verification Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64623"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-45295",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "freescout-help-desk",
      "product": "freescout",
      "cwe": "CWE-639",
      "title": "FreeScout Vulnerable to Unauthenticated Thread Read-Status Manipulation and Conversation Enumeration via Open Tracking Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45295"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-16244",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.1025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System prescriptionorderreport.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16244"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-63770",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00197,
      "epss_percentile": 0.09899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "glanceapp",
      "product": "glance",
      "cwe": "CWE-348",
      "title": "Glance 0.8.5 IP Spoofing Authentication Brute-Force Protection Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63770"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-32819",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "datacycle-engine",
      "product": "dataCycle-CORE",
      "cwe": "CWE-285",
      "title": "dataCycle User Directory Enumeration Via /users/search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32819"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-63768",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "calcom",
      "product": "cal.diy",
      "cwe": "CWE-601",
      "title": "cal.diy 6.2.0 Conferencing OAuth Callback Open Redirect via Unsigned State",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63768"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-55550",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00195,
      "epss_percentile": 0.09532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pdovhomilja",
      "product": "nextcrm-app",
      "cwe": "CWE-269",
      "title": "NextCRM has RBAC Bypass in MCP Product Tools that Allows Low-Privileged Users to Modify the CRM Product Catalog",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55550"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-35217",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nanomq",
      "product": "nanomq",
      "cwe": "CWE-125",
      "title": "NanoMQ Incorrectly Accepts a Malformed SUBSCRIBE and Can Be Driven into an ASAN-Detectable Out-of-Bounds Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35217"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-63748",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-209",
      "title": "SurrealDB before 3.1.0 Information Disclosure via Error Messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63748"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-15588",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-770",
      "title": "Gdbusserver: glib2: gdbusserver pre-authentication dos via unbounded sasl line buffering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15588"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-46428",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00191,
      "epss_percentile": 0.09145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lettre",
      "product": "lettre",
      "cwe": "CWE-295",
      "title": "lettre has TLS hostname verification disabled when using Boring TLS backend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46428"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-46555",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "verygoodplugins",
      "product": "whatsapp-mcp",
      "cwe": "CWE-22",
      "title": "WhatsApp MCP: Unauthenticated bridge API allows message sending and arbitrary file exfiltration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46555"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-12900",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brainstormforce",
      "product": "Spectra Legacy – Gutenberg Blocks",
      "cwe": "CWE-79",
      "title": "Spectra Gutenberg Blocks <= 2.19.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via uagb/image Block",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12900"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-48389",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "DNG SDK",
      "cwe": "CWE-121",
      "title": "DNG SDK | Stack-based Buffer Overflow (CWE-121)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48389"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-64626",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08548,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WWBN",
      "product": "AVideo",
      "cwe": "CWE-918",
      "title": "AVideo Encoder downloadURL SSRF via unpinned retry fallback",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64626"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-11868",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Travel",
      "cwe": "CWE-862",
      "title": "WP Travel < 11.7.1 - Unauthenticated Arbitrary Booking Cancellation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11868"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-63758",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-862",
      "title": "SurrealDB before 3.1.0 Authorization Bypass via KILL Statement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63758"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-64624",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FreeRDP",
      "product": "FreeRDP",
      "cwe": "CWE-88",
      "title": "FreeRDP RDP File Parser Remote Code Execution via CLI Options",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64624"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-55544",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pdovhomilja",
      "product": "nextcrm-app",
      "cwe": "CWE-284",
      "title": "NextCRM has BOLA/IDOR in MCP Campaign Tools that Allows Cross-User Campaign Disclosure and Tampering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55544"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-63743",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-918",
      "title": "SurrealDB before 3.1.0 Port-Specific Deny Rule Bypass via HTTP Redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63743"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-63745",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-639",
      "title": "SurrealDB before 3.1.0 Authorization Bypass via Composite Record-id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63745"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-47255",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00178,
      "epss_percentile": 0.0765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "agenticmail",
      "product": "@agenticmail/api",
      "cwe": "CWE-20",
      "title": "AgenticMail API/storage and outbound relay hardening",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47255"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-56624",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00178,
      "epss_percentile": 0.07621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache MINA SSHD",
      "cwe": "CWE-295",
      "title": "Apache MINA SSHD: SSH certificate options lack validations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56624"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-44585",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paymenter",
      "product": "Paymenter",
      "cwe": "CWE-639",
      "title": "Paymenter: Broken object level authorization via service reference manipulation on ticket creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44585"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-12972",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "PayPlus Payment Gateway",
      "cwe": "CWE-284",
      "title": "PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Payment Metadata Tampering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12972"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-57310",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JCD",
      "product": "Windu CMS",
      "cwe": "CWE-916",
      "title": "Weak password hashing in Windu CMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57310"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-63751",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-863",
      "title": "SurrealDB before 3.1.0 Field Permission Bypass via JSON Patch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63751"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-39879",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "syslog-ng",
      "product": "syslog-ng",
      "cwe": "CWE-150",
      "title": "SQL injection in syslog-ng SQL destionation driver",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39879"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-13432",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06736,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ThumbPress",
      "cwe": "CWE-862",
      "title": "ThumbPress < 6.2.2 - Subscriber+ Plugin Deactivation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13432"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-47275",
      "cvss_base": 2.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00169,
      "epss_percentile": 0.0663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nanomq",
      "product": "nanomq",
      "cwe": "CWE-476",
      "title": "nanomq NULL Pointer Dereference in MQTTv5 Client CONNECT Decoder Leading to Remote DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47275"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-10755",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00168,
      "epss_percentile": 0.06601,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "All in One SEO",
      "cwe": "CWE-863",
      "title": "All in One SEO < 4.9.9 – Contributor+ Incorrect Authorization via AI Integration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10755"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-63752",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-285",
      "title": "SurrealDB before 3.1.0 RELATE Statement Record Overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63752"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-9833",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Tag Groups is the Advanced Way to Display Your Taxonomy Terms",
      "cwe": "CWE-79",
      "title": "Tag Groups < 2.2.0 - Reflected XSS via 'tag_groups_task' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9833"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-26483",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.06042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. The application fails to properly sanitize user-supplied input in the content parameter of the /templates endpoint, allowing an attacker to persistently inject malicious JavaScript code that is executed in the browsers of users who access the affected template.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-26483"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-63761",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.05994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "surrealdb",
      "product": "surrealdb",
      "cwe": "CWE-327",
      "title": "SurrealDB before 3.1.0 Algorithm Downgrade via ES512",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63761"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-47130",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pdovhomilja",
      "product": "nextcrm-app",
      "cwe": "CWE-639",
      "title": "NextCRM has a BOLA/IDOR in PATCH /api/crm/contacts/[id] that allows Cross-Tenant CRM Data Tampering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47130"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-6793",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bifra Engineering Consulting Ltd.",
      "product": "Q-smart NexT Poll",
      "cwe": "CWE-79",
      "title": "Stored XSS in Bifra Engineering's Q-smart NexT Poll",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6793"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-46415",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JasonLovesDoggo",
      "product": "caddy-defender",
      "cwe": "CWE-284",
      "title": "Caddy Defender trusted proxy client IP bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46415"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-12973",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.0568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "PayPlus Payment Gateway",
      "cwe": "CWE-862",
      "title": "PayPlus Payment Gateway < 8.2.2 - Unauthenticated Order Key Disclosure and Order Status Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12973"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-58482",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jovancoding",
      "product": "Network-AI",
      "cwe": "CWE-352",
      "title": "Network-AI: ApprovalInbox HTTP server has no authentication — anyone can approve pending agent actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58482"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-44227",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bestpractical",
      "product": "rt",
      "cwe": "CWE-79",
      "title": "RT: Reflected Cross-Site Scripting via URL parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44227"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-44230",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bestpractical",
      "product": "rt",
      "cwe": "CWE-79",
      "title": "RT: Reflected Cross-Site Scripting in search results chart",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44230"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-46671",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "msiemens",
      "product": "onenote.rs",
      "cwe": "CWE-22",
      "title": "Rust OneNote File Parser: Path traversal in `Parser::parse_notebook` allows reading files outside the notebook directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46671"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-44228",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.04738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bestpractical",
      "product": "rt",
      "cwe": "CWE-79",
      "title": "RT: Stored Cross-Site Scripting via insufficient template escaping",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44228"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-2445",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WSO2",
      "product": "WSO2 API Manager",
      "cwe": "CWE-79",
      "title": "Reflected Cross-Site Scripting via URL Parameter in Multiple WSO2 Products Enables UI Redirection and Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2445"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-12970",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "LearnPress",
      "cwe": "CWE-79",
      "title": "LearnPress < 4.4.1 - Reflected XSS via c_search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12970"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-47144",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BKDDFS",
      "product": "shamefile",
      "cwe": "CWE-22",
      "title": "Shamefile has an arbitrary file read via shamefile.yaml in shame next",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47144"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-63728",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitleaks",
      "product": "gitleaks",
      "cwe": "CWE-1336",
      "title": "Gitleaks Secret Exfiltration via Non-Hermetic Sprig Template Functions in Report Template Feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63728"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-55219",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paymenter",
      "product": "Paymenter",
      "cwe": "CWE-362",
      "title": "Paymenter: Race condition in payWithCredit() enables credit double-spend",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55219"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-61901",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hikashop.com",
      "product": "Hikashop extension for Joomla",
      "cwe": "CWE-601",
      "title": "Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61901"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-44229",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bestpractical",
      "product": "rt",
      "cwe": "CWE-79",
      "title": "RT: Cross-Site Scripting via inline-served uploaded content",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44229"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-12080",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-61",
      "title": "Qemu-kvm: qemu-guest-agent: local privilege escalation via symlink attack in guest-ssh-add-authorized-keys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12080"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-33327",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libvips",
      "product": "libvips",
      "cwe": "CWE-190",
      "title": "Possible integer overflow leading to potential heap-based buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33327"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-35591",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libvips",
      "product": "libvips",
      "cwe": "CWE-122",
      "title": "Possible heap-based buffer overflow when decoding TIFF image containing well-crafted tile",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35591"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-13156",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MailerSend",
      "cwe": "CWE-352",
      "title": "MailerSend - Official SMTP Integration < 1.0.8 - Settings Deletion and Plugin Deactivation via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13156"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-64191",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "i2c: stub: Reject I2C block transfers with invalid length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64191"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-55626",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "neutrinolabs",
      "product": "xrdp",
      "cwe": "CWE-287",
      "title": "xrdp: No authentication required with Xvnc backend on RHEL 9",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55626"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-64205",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "i2c: i801: fix hardware state machine corruption in error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64205"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-15905",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15905"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-33328",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libvips",
      "product": "libvips",
      "cwe": "CWE-190",
      "title": "Possible integer overflow on 32-bit systems when reading GIF images",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33328"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-35590",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libvips",
      "product": "libvips",
      "cwe": "CWE-122",
      "title": "Possible out-of-bounds read leading to crash when decoding well-crafted EXIF metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35590"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-53592",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "freescout-help-desk",
      "product": "freescout",
      "cwe": "CWE-1321",
      "title": "FreeScout vulnerable to prototype pollution in getQueryParam",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53592"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-64192",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.02004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64192"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-64188",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64188"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-44584",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01786,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Paymenter",
      "product": "Paymenter",
      "cwe": "CWE-345",
      "title": "Paymenter doesn't reset email verification status after email change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44584"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-64187",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "xfs: fail recovery on a committed log item with no regions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64187"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-16246",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bizerba SE & Co. KG",
      "product": "BRAIN2",
      "cwe": "CWE-276",
      "title": "Insecure permission assignment due to execution of LogPathConfig.exe during setup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16246"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-64650",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vercel",
      "product": "@ai-sdk/harness-codex",
      "cwe": "CWE-863",
      "title": "AI SDK Codex Harness Tool Relay Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64650"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-64651",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vercel",
      "product": "@ai-sdk/harness-opencode",
      "cwe": "CWE-863",
      "title": "AI SDK OpenCode Harness Tool Relay Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64651"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-64207",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "net/sched: dualpi2: fix GSO backlog accounting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64207"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-32823",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "datacycle-engine",
      "product": "dataCycle-CORE",
      "cwe": "CWE-352",
      "title": "dataCycle State-Changing GET Endpoints Enable CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32823"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-47133",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craigjbass",
      "product": "clearancekit",
      "cwe": "CWE-294",
      "title": "ClearanceKit's signed policy tables lack monotonic counter, allowing replay of older legitimately-signed snapshots",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47133"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-47134",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "craigjbass",
      "product": "clearancekit",
      "cwe": "CWE-732",
      "title": "ClearanceKit: Policy signing key in System Keychain has permissive ACL allowing any local-root process to forge signed policy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47134"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-64190",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.01158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "net: team: fix NULL pointer dereference in team_xmit during mode change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64190"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-16247",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00103,
      "epss_percentile": 0.01142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bizerba SE & Co. KG",
      "product": "_connect.BRAIN",
      "cwe": "CWE-276",
      "title": "Insecure permission overwrite due to execution of LogPathConfig.exe while installing _connect.BRAIN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16247"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-12724",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.0104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Kirki",
      "cwe": "CWE-345",
      "title": "Kirki < 6.0.12 - Unauthenticated HTML Injection in Password Reset Email via kirki-forgot-password",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12724"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-64189",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00097,
      "epss_percentile": 0.00846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "netfilter: ipset: fix race between dump and ip_set_list resize",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64189"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-10724",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00092,
      "epss_percentile": 0.00596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Reviews Feed",
      "cwe": "CWE-345",
      "title": "Reviews Feed < 2.6.5 - Unauthenticated Stored Arbitrary Shortcode Execution via Google Reviews",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10724"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-47128",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00089,
      "epss_percentile": 0.00477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "always-further",
      "product": "nono",
      "cwe": "CWE-863",
      "title": "nono: Sandbox escape on Linux via D-Bus: `systemd-run --user`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47128"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-1014",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-1014 (SE-elektronic GmbH E-DDC3.3). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-26197",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-26197 (HDFGroup hdf5). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-26199",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-26199 (HDFGroup hdf5). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-28220",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-28220 (wazuh). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-32286",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-32286 (github.com/jackc/pgproto3/v2). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45709",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45709 (axllent mailpit). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45711",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45711 (axllent mailpit). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45712",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45712 (axllent mailpit). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45713",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45713 (axllent mailpit). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-46701",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-46701 (Jovancoding Network-AI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47774",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47774 (envoyproxy envoy). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48824",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48824 (axllent mailpit). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58413",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58413 (Jovancoding Network-AI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58414",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58414 (Jovancoding Network-AI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58481",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58481 (Jovancoding Network-AI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58482",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58482 (Jovancoding Network-AI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58484",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58484 (Jovancoding Network-AI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-64620",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-64620 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-64621",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-64621 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-25089",
      "detail": "DUE DATE PASSED — CVE-2026-25089 (Fortinet FortiSandbox). CISA remediation deadline was July 19, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-39808",
      "detail": "DUE DATE PASSED — CVE-2026-39808 (Fortinet FortiSandbox). CISA remediation deadline was July 19, 2026; still in catalog."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-58644",
      "detail": "DUE DATE PASSED — CVE-2026-58644 (Microsoft SharePoint Enterprise Server 2016). CISA remediation deadline was July 19, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-1014",
      "detail": "RESCORED — CVE-2024-1014 (SE-elektronic GmbH E-DDC3.3). CVSS 6.2 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-35260",
      "detail": "RESCORED — CVE-2024-35260 (Microsoft Power Platform). CVSS 8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16074",
      "detail": "RESCORED — CVE-2026-16074 (AstrBotDevs AstrBot). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16076",
      "detail": "RESCORED — CVE-2026-16076 (AstrBotDevs AstrBot). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16077",
      "detail": "RESCORED — CVE-2026-16077 (AstrBotDevs AstrBot). CVSS 4.8 → 1.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16081",
      "detail": "RESCORED — CVE-2026-16081 (Sipeed PicoClaw). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16083",
      "detail": "RESCORED — CVE-2026-16083 (Sipeed PicoClaw). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16085",
      "detail": "RESCORED — CVE-2026-16085 (Sipeed PicoClaw). CVSS 4.8 → 1.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16088",
      "detail": "RESCORED — CVE-2026-16088 (halo-dev halo). CVSS 5.1 → 2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16120",
      "detail": "RESCORED — CVE-2026-16120 (nextlevelbuilder GoClaw). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16121",
      "detail": "RESCORED — CVE-2026-16121 (nextlevelbuilder GoClaw). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16122",
      "detail": "RESCORED — CVE-2026-16122 (nextlevelbuilder GoClaw). CVSS 4.8 → 1.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16124",
      "detail": "RESCORED — CVE-2026-16124 (nextlevelbuilder GoClaw). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16126",
      "detail": "RESCORED — CVE-2026-16126 (zevorn rt-claw). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16127",
      "detail": "RESCORED — CVE-2026-16127 (zevorn rt-claw). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16128",
      "detail": "RESCORED — CVE-2026-16128 (zevorn rt-claw). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16130",
      "detail": "RESCORED — CVE-2026-16130 (nearai ironclaw). CVSS 4.8 → 1.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16133",
      "detail": "RESCORED — CVE-2026-16133 (LiuMengxuan04 MiniCode). CVSS 2.3 → 1.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16154",
      "detail": "RESCORED — CVE-2026-16154 (SourceCodester Class and Exam Timetabling System). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16194",
      "detail": "RESCORED — CVE-2026-16194 (zhayujie CowAgent). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16195",
      "detail": "RESCORED — CVE-2026-16195 (Sipeed PicoClaw). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16197",
      "detail": "RESCORED — CVE-2026-16197 (Sipeed PicoClaw). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16199",
      "detail": "RESCORED — CVE-2026-16199 (nextlevelbuilder GoClaw). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16200",
      "detail": "RESCORED — CVE-2026-16200 (zevorn rt-claw). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16201",
      "detail": "RESCORED — CVE-2026-16201 (zevorn rt-claw). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16203",
      "detail": "RESCORED — CVE-2026-16203 (SourceCodester Class and Exam Timetabling System). CVSS 5.1 → 2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16205",
      "detail": "RESCORED — CVE-2026-16205 (Pluck CMS). CVSS 4.8 → 1.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16209",
      "detail": "RESCORED — CVE-2026-16209 (Gerapy). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16211",
      "detail": "RESCORED — CVE-2026-16211 (allegro). CVSS 2.1 → 1.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16212",
      "detail": "RESCORED — CVE-2026-16212 (awesto django-shop). CVSS 2.3 → 1.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16215",
      "detail": "RESCORED — CVE-2026-16215 (geex-arts django-jet). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16217",
      "detail": "RESCORED — CVE-2026-16217 (guohongze adminset). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16219",
      "detail": "RESCORED — CVE-2026-16219 (Croogo CMS). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16222",
      "detail": "RESCORED — CVE-2026-16222 (1Panel-dev CordysCRM). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16225",
      "detail": "RESCORED — CVE-2026-16225 (davenardella snap7). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16228",
      "detail": "RESCORED — CVE-2026-16228 (SourceCodester Class and Exam Timetabling System). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-33845",
      "detail": "RESCORED — CVE-2026-33845 (gnutls). CVSS 7.5 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-3602",
      "detail": "RESCORED — CVE-2026-3602 (IBM App Connect Enterprise). CVSS 4.7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-49790",
      "detail": "RESCORED — CVE-2026-49790 (Microsoft Windows 10 Version 1607). CVSS 7.3 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50374",
      "detail": "RESCORED — CVE-2026-50374 (Microsoft Windows 10 Version 1809). CVSS 6.3 → 6.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-54991",
      "detail": "RESCORED — CVE-2026-54991 (Microsoft Windows 11 Version 24H2). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-54992",
      "detail": "RESCORED — CVE-2026-54992 (Microsoft Windows 10 Version 1607). CVSS 8.4 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-54995",
      "detail": "RESCORED — CVE-2026-54995 (Microsoft Windows 10 Version 1607). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-57973",
      "detail": "RESCORED — CVE-2026-57973 (Microsoft Windows Subsystem for Linux (WSL2)). CVSS 6.3 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-7872",
      "detail": "RESCORED — CVE-2026-7872 (IBM Langflow OSS). CVSS 7.5 → 8.1 (NVD)."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
