{
  "day": "2026-07-22",
  "boundary": "UTC calendar day",
  "published_count": 198,
  "by_severity": {
    "CRITICAL": 17,
    "HIGH": 103,
    "MEDIUM": 65,
    "LOW": 13
  },
  "kev_count": 1,
  "exploit_reference_count": 3,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-16232",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.73296,
      "epss_percentile": 0.99417,
      "kev": true,
      "kev_due_at": "2026-07-25",
      "vendor": "checkpoint",
      "product": "Quantum Security Management",
      "cwe": "CWE-287",
      "title": "Authentication Bypass in the SmartConsole Login Process Using an Application Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16232"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-62144",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.20623,
      "epss_percentile": 0.97318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "checkpoint",
      "product": "Quantum Security Management",
      "cwe": "CWE-287",
      "title": "Management Authentication Bypass and Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62144"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-62145",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0754,
      "epss_percentile": 0.94009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "checkpoint",
      "product": "Quantum Security Gateway",
      "cwe": "CWE-269",
      "title": "Local Privilege Escalation in Gaia Portal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62145"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-16492",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.01664,
      "epss_percentile": 0.74809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "umijs",
      "product": "umi",
      "cwe": "CWE-77",
      "title": "umijs umi GIT File Helper getFileGitIno.ts git.getFileCreateInfo os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16492"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-16606",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00651,
      "epss_percentile": 0.48446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fujitsu",
      "product": "Linux openFT",
      "cwe": "CWE-94",
      "title": "Unauthenticated remote code execution (pre-auth RCE) vulnerability in openFT for Linux and Oracle Solaris",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16606"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-16630",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00635,
      "epss_percentile": 0.477,
      "kev": false,
      "kev_due_at": null,
      "vendor": "syncfusion",
      "product": "ej2-javascript-ui-controls",
      "cwe": "CWE-77",
      "title": "syncfusion ej2-javascript-ui-controls package.json child_process.exec os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16630"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-16631",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00635,
      "epss_percentile": 0.47694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "publint",
      "cwe": "CWE-77",
      "title": "publint package-manager pack.js child_process.exec os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16631"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-16629",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00622,
      "epss_percentile": 0.47123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danger",
      "product": "danger-js",
      "cwe": "CWE-77",
      "title": "danger danger-js CLI localGetFileAtSHA.ts danger.git.diffForFile os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16629"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-16628",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00622,
      "epss_percentile": 0.47123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "oclif",
      "cwe": "CWE-77",
      "title": "oclif JIT Plugin Entry child_process.exec os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16628"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2025-50329",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0057,
      "epss_percentile": 0.44664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-693",
      "title": "An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-50329"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-44189",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00536,
      "epss_percentile": 0.42927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-88",
      "title": "Ansible-lightspeed: visual studio code ansible lightspeed extension: arbitrary code execution via malicious playbook filename",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44189"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-13186",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00532,
      "epss_percentile": 0.42713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Telerik UI for ASP.NET AJAX",
      "cwe": "CWE-22",
      "title": "AppDataStorageProvider Path Traversal Deserialization Vulnerability in Telerik UI for ASP.NET AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13186"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-11605",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00524,
      "epss_percentile": 0.42266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-408",
      "title": "Unnecessary validation of DNSSEC signed records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11605"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-15802",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00516,
      "epss_percentile": 0.41784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chimpstudio",
      "product": "WP Foodbakery",
      "cwe": "CWE-23",
      "title": "WP Foodbakery <= 4.9 - Authenticated (Subscriber+) Arbitrary File Deletion via via delete_locations_backup_file AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15802"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-11622",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00509,
      "epss_percentile": 0.41315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-770",
      "title": "Potential memory usage beyond configured limits",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11622"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-13204",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00509,
      "epss_percentile": 0.41314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-617",
      "title": "Unexpected exit in certain situations with NSEC and NSEC3 both present",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13204"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-64834",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00503,
      "epss_percentile": 0.40925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-835",
      "title": "FFmpeg 0.6.3 - 8.1.2 Infinite Loop DoS via RTP/ASF Demuxer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64834"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-12617",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00488,
      "epss_percentile": 0.40074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-617",
      "title": "Record ordering based unexpected exit with CNAME or DNAME",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12617"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-13185",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00486,
      "epss_percentile": 0.39908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Telerik UI for ASP.NET AJAX",
      "cwe": "CWE-502",
      "title": "PersistenceFramework Cookie Deserialization Vulnerability in Telerik UI for ASP.NET AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13185"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-13181",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00485,
      "epss_percentile": 0.39856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Telerik UI for ASP.NET AJAX",
      "cwe": "CWE-470",
      "title": "RadAsyncUpload AsyncUploadTypeName Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13181"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-13190",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00485,
      "epss_percentile": 0.39856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Telerik UI for ASP.NET AJAX",
      "cwe": "CWE-502",
      "title": "PersistenceFramework Unsafe Type Resolution Vulnerability in Telerik UI for ASP.NET AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13190"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-44191",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00473,
      "epss_percentile": 0.39065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-78",
      "title": "Ansible-lightspeed: visual studio code ansible lightspeed extension: remote code execution via command injection in configuration settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44191"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-65591",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00471,
      "epss_percentile": 0.38948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-917",
      "title": "n8n before 1.123.64 Sanitizer Bypass Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65591"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-65595",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.0047,
      "epss_percentile": 0.38853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-269",
      "title": "n8n before 2.29.8 and 2.30.1 Privilege Escalation via Token Exchange",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65595"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-64831",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00457,
      "epss_percentile": 0.3808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-121",
      "title": "FFmpeg 8.0 - 8.1.2 Stack Buffer Overflow in Vulkan HEVC Decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64831"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-44190",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-78",
      "title": "Ansible-lightspeed: ansible lightspeed visual studio code extension: arbitrary code execution via command injection in activation script setting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44190"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-11331",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-790",
      "title": "Potential wildcard CNAME RPZ policy bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11331"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-65600",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-22",
      "title": "Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65600"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-65650",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0039,
      "epss_percentile": 0.32329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elgg",
      "product": "Elgg",
      "cwe": "CWE-770",
      "title": "Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65650"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2025-50327",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-693",
      "title": "An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection mechanism",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-50327"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-11721",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00385,
      "epss_percentile": 0.31807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-1284",
      "title": "Cache poisoning possible with label count discrepancy, RRSIG, and wildcards",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11721"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-10822",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-617",
      "title": "Key Record using PRIVATEDNS algorithm may lead to unexpected exit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10822"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-65589",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-532",
      "title": "n8n before 1.123.64 Credential Exposure via LLM Node Execution Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65589"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2025-50324",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.2957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-693",
      "title": "An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-50324"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2025-50330",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.2957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-693",
      "title": "An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-50330"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-13189",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.29272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Telerik UI for ASP.NET AJAX",
      "cwe": "CWE-36",
      "title": "SpellChecker DictionaryLanguage Path Traversal Vulnerability in Telerik UI for ASP.NET AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13189"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-3821",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00355,
      "epss_percentile": 0.28729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SMCI",
      "product": "X14DBG-DAP,X14DBI",
      "cwe": "CWE-78",
      "title": "Supermicro SMASH service contain an Arbitrary code execution issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3821"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-2395",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xpoda Türkiye Informatics Technology Inc.",
      "product": "No Code Platform",
      "cwe": "CWE-89",
      "title": "SQLi in Xpoda Türkiye Informatics Technology's No Code Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2395"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-40712",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00349,
      "epss_percentile": 0.28126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect Data Manager",
      "cwe": "CWE-20",
      "title": "Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40712"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-46738",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00349,
      "epss_percentile": 0.28126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect Data Manager",
      "cwe": "CWE-20",
      "title": "Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46738"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-46737",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00348,
      "epss_percentile": 0.28002,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect Data Manager",
      "cwe": "CWE-20",
      "title": "Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46737"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-16544",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00347,
      "epss_percentile": 0.27872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-862",
      "title": "Awx: websocket eventconsumer missing authorization for inventory_update_events, project_update_events, and system_job_events allows cross-organization stdout disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16544"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-64830",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-122",
      "title": "FFmpeg 2.1 - 8.1.2 Heap Buffer Overflow via VobSub Subtitle Demuxer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64830"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-13187",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Telerik UI for ASP.NET AJAX",
      "cwe": "CWE-470",
      "title": "DialogHandler Provider Type Tampering Vulnerability in Telerik UI for ASP.NET AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13187"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-64832",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-415",
      "title": "FFmpeg 4.4 - 8.1.2 Double-Free in NVDEC Hardware Decoder via nvdec.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64832"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-65014",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00334,
      "epss_percentile": 0.26394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-306",
      "title": "n8n before 2.28.0 Authentication Bypass via test-webhook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65014"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-64835",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-787",
      "title": "FFmpeg 4.4 - 8.1.2 Out-of-Bounds Memory Access in ADX Audio Decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64835"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-65015",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-863",
      "title": "n8n before 2.30.1 Privilege Escalation via run_node_tool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65015"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-64829",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00322,
      "epss_percentile": 0.25112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "q2a",
      "product": "question2answer",
      "cwe": "CWE-613",
      "title": "Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64829"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-65590",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.25053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-78",
      "title": "n8n before 2.30.1 Shell Sandbox Bypass on Linux Windows",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65590"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-13182",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Telerik UI for ASP.NET AJAX",
      "cwe": "CWE-209",
      "title": "RadAsyncUpload Client-State Decrypt-vs-Parse Oracle Vulnerability in Telerik UI for ASP.NET AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13182"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-13183",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Telerik UI for ASP.NET AJAX",
      "cwe": "CWE-208",
      "title": "RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13183"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-4773",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Magarsus Consulting Ltd. Co.",
      "product": "IDM-MFA",
      "cwe": "CWE-1287",
      "title": "OTP Bypass in Magarsus' IDM-MFA",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4773"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-60367",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00317,
      "epss_percentile": 0.24524,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Platform Security for Java",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60367"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-13072",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00315,
      "epss_percentile": 0.24322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-122",
      "title": "MongoDB Improper Input Validation in Compute Mode External Data Processing Leading to Memory Corruption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13072"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-60366",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0031,
      "epss_percentile": 0.23803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Platform Security for Java",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60366"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-60372",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0031,
      "epss_percentile": 0.23803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Platform Security for Java",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60372"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-60368",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Platform Security for Java",
      "cwe": "CWE-1104",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60368"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-16632",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0031,
      "epss_percentile": 0.23802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boazsegev",
      "product": "facil.io",
      "cwe": "CWE-20",
      "title": "boazsegev facil.io WebSocket Frame websocket_parser.h websocket_on_protocol_error input validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16632"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-65016",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00308,
      "epss_percentile": 0.23533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-639",
      "title": "n8n before 1.123.64, 2.29.8, and 2.30.1 Privilege Escalation via SSO Instance-Role",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65016"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-61391",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hikvision",
      "product": "DS-2CD Series",
      "cwe": "CWE-121",
      "title": "There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61391"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-48029",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strukturag",
      "product": "libheif",
      "cwe": "CWE-125",
      "title": "libheif: heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48029"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-65603",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.2301,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-269",
      "title": "Grav Login Plugin 3.8.11 Privilege Escalation via Profile Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65603"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-65013",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "onlook",
      "product": "repo",
      "cwe": "CWE-639",
      "title": "Onlook tRPC Insecure Direct Object Reference via multiple procedures",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65013"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-13065",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.2229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-476",
      "title": "MongoDB $linearFill Window Function Improper Input Validation Leading to Process Termination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13065"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2025-44090",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.21918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-693",
      "title": "An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-44090"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-40691",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.21902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-122",
      "title": "Packet of death for DNSCrypt over TCP",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40691"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-12968",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Product Addons and Product Options With Custom Fields",
      "cwe": "CWE-79",
      "title": "Product Addons – WowAddons < 1.6.15 - Unauthenticated Stored XSS via Arbitrary SVG Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12968"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-55973",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-20",
      "title": "'dns-error-reporting: yes' leads to stack buffer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55973"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-2406",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Universe Software Computer Marketing Trade and Industry Inc.",
      "product": "Online Registration and Workflow Management System",
      "cwe": "CWE-639",
      "title": "IDOR in Universe Software's Online Registration and Workflow Management System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2406"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2025-44089",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-693",
      "title": "An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-44089"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-49499",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.2117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect Data Manager",
      "cwe": "CWE-1270",
      "title": "Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49499"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-22049",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NETAPP",
      "product": "ONTAP 9",
      "cwe": "CWE-288",
      "title": "ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentication (MFA) configured are susceptible to a vulnerability related to the Relying Party ID which when successfully exploited could allow an attacker with valid credentials to bypass MFA.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22049"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2025-50325",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.21137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-693",
      "title": "BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of BandiZip",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-50325"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-64796",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00285,
      "epss_percentile": 0.2105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Sourcerer extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64796"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-32665",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00285,
      "epss_percentile": 0.21053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-1284",
      "title": "Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-32665"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-13055",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-617",
      "title": "Server crash via aggregation pipeline expression with compound wildcard index specification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13055"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-13056",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-1325",
      "title": "A user with read access can cause a DoS by executing a specifically crafted query to consume a large amount of RAM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13056"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-16624",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00281,
      "epss_percentile": 0.20659,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cal.com",
      "product": "Cal.diy",
      "cwe": "CWE-639",
      "title": "CVE-2026-16624",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16624"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-60369",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00279,
      "epss_percentile": 0.2047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Platform Security for Java",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60369"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-60373",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Platform Security for Java",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60373"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-40714",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect Data Manager",
      "cwe": "CWE-20",
      "title": "Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40714"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-16270",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Open Mercato",
      "product": "Open Mercato",
      "cwe": "CWE-1333",
      "title": "ReDoS in Open Mercato",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16270"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-50045",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-406",
      "title": "'max-global-quota' reset by DNSSEC validation restarts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50045"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2025-13146",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sevenspark",
      "product": "Contact Form 7 – Dynamic Text Extension",
      "cwe": "CWE-94",
      "title": "Contact Form 7 – Dynamic Text Extension <= 5.0.6 - Unauthenticated Arbitrary Shortcode Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-13146"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-14899",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mozilla",
      "product": "Thunderbird",
      "cwe": "CWE-193",
      "title": "Off-by-one out of bounds read in MIME header parser for forwarding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14899"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-65601",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.19864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-863",
      "title": "Traefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65601"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-13059",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.19639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-807",
      "title": "Improper Validation of Client-Supplied Command Parameters Allowing Role-Based Access Control Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13059"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-60439",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Platform Security for Java",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60439"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-14586",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-617",
      "title": "Assertion in libngtcp2 when under pressure in high concurrency DNS-over-QUIC environments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14586"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-65594",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-863",
      "title": "n8n before 2.30.1 Missing OAuth Authorization Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65594"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-12987",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Events Manager",
      "cwe": "CWE-89",
      "title": "Events Manager < 7.3.7 - Unauthenticated SQL Injection via PHP Object Injection in Booking Registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12987"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-10723",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-347",
      "title": "Incorrect acceptance of NSEC3 records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10723"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-41637",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00265,
      "epss_percentile": 0.18571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-772",
      "title": "Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41637"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-61246",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00264,
      "epss_percentile": 0.18436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Platform Security for Java",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61246"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-13074",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-770",
      "title": "Awaitable Hello Command in Exhaust Mode Unthrottled Response Loop Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13074"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-3482",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Sterling B2B Integrator",
      "cwe": "CWE-639",
      "title": "IBM Sterling B2B Integrator and IBM Sterling File Gateway Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3482"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-63264",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshopping.com",
      "product": "JoomShopping extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63264"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-65012",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "invoke-ai",
      "product": "InvokeAI",
      "cwe": "CWE-306",
      "title": "InvokeAI < 6.13.7 Unauthenticated Directory Enumeration via scan_folder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65012"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-55990",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00257,
      "epss_percentile": 0.17517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-457",
      "title": "Packet of death for a DNSCrypt misconfigured Unbound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55990"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-45820",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "101arrowz",
      "product": "fflate",
      "cwe": "CWE-400",
      "title": "fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=0xFFFFFFFF (ZIP64 sentinel) but missing the required ZIP64 extra field tag 0x0001 causes z64e() to loop indefinitely due to out-of-bounds reads returning undefined, which coerces to 0, keeping the loop condition permanently true.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45820"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-14865",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Telerik UI for ASP.NET AJAX",
      "cwe": "CWE-776",
      "title": "XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14865"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-16615",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "librest",
      "cwe": "CWE-338",
      "title": "Librest: weak random number generation in pkce implementation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16615"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-50251",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-184",
      "title": "Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50251"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-16551",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.16989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thinkst Applied Research",
      "product": "OpenCanary",
      "cwe": "CWE-20",
      "title": "Denial-of-Service in OpenCanary's MongoDB module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16551"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-13057",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-20",
      "title": "Authorization Bypass via Client-Supplied $search.mergingPipeline Leaks Unauthorized Collection Data Through $$SEARCH_META",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13057"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-13071",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-416",
      "title": "Server-Side JavaScript Aggregation Expression Memory Safety Issue Leading to Process Termination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13071"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-13077",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-125",
      "title": "Out-of-Bounds Heap Read in BSON CodeWScope Element Parsing via Malformed BSONColumn Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13077"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-64792",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Articles Anywhere extension for Joomla",
      "cwe": "CWE-524",
      "title": "Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64792"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-57600",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hikvision",
      "product": "DS-2CD Series",
      "cwe": "CWE-20",
      "title": "Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57600"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-44621",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.16393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-754",
      "title": "Libunbound applications configured with 'unwanted-reply-threshold' could eventually be abruptly terminated",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44621"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-64793",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00246,
      "epss_percentile": 0.16215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Articles Anywhere extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64793"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-64798",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00245,
      "epss_percentile": 0.16027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "IP Login extension for Joomla",
      "cwe": "CWE-338",
      "title": "Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64798"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-16473",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.15987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Sbc: sbc: heap out-of-bounds read via crafted sbc audio frame",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16473"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-8152",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00244,
      "epss_percentile": 0.15915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unblu inc.",
      "product": "Unblu Spark",
      "cwe": "CWE-79",
      "title": "Unblu Spark Open Redirect leading to DOM-Based XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8152"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-60455",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00244,
      "epss_percentile": 0.15945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Platform Security for Java",
      "cwe": "CWE-269",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60455"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-13192",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.1589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Telerik UI for ASP.NET AJAX",
      "cwe": "CWE-918",
      "title": "RadEditor PDF Export SSRF Vulnerability in Telerik UI for ASP.NET AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13192"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-64794",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Articles Anywhere extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64794"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-16560",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11",
      "cwe": "CWE-1220",
      "title": "389-ds-base: 389-ds-base: heap-buffer-overflow in rdn_av_swap on quoted multivalued rdn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16560"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-65598",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-367",
      "title": "n8n before 1.123.64 Remote Code Execution via Git Clone",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65598"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-15787",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15538,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brainstormforce",
      "product": "Ultimate Addons for Elementor",
      "cwe": "CWE-79",
      "title": "Ultimate Addons for Elementor <= 2.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15787"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-13089",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RITOU",
      "product": "OIDC::Lite",
      "cwe": "CWE-347",
      "title": "OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature verification bypass via a token-controlled algorithm allowlist in verify",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13089"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-13075",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-770",
      "title": "$rankFusion and $scoreFusion Unbounded Memory Allocation During Error Suggestion Generation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13075"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-13076",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-770",
      "title": "Aggregation Framework Memory Exhaustion Leading to Process Termination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13076"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-50046",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.15021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-416",
      "title": "Possible heap use-after-free in an error path when a DoT forwarded query is jostled out",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50046"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-52863",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.15022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-416",
      "title": "Memory corruption could lead to crash and denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52863"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-55717",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.15021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-476",
      "title": "'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55717"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-55991",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.15022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-195",
      "title": "Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55991"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-56444",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.15021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-772",
      "title": "Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56444"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-13060",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-863",
      "title": "$graphLookup Aggregation Stage Authorization Check Inconsistency Allowing Unauthorized Collection Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13060"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-9737",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-617",
      "title": "Find command with $meta sort can lead to crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9737"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-63047",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomdonation.com",
      "product": "Events Booking extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63047"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-13058",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-617",
      "title": "Transaction Command Insufficient Input Validation Leading to Process Termination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13058"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-13064",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-407",
      "title": "MongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13064"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-13063",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-190",
      "title": "libmongocrypt Improper Input Validation Leading to Process Termination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13063"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-63685",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.13987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "DB Replacer extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63685"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-61390",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hikvision",
      "product": "DS-2CD Series",
      "cwe": "CWE-122",
      "title": "There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61390"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-13066",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-843",
      "title": "Server-Side JavaScript DBPointer BSON Serialization Memory Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13066"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-63048",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00226,
      "epss_percentile": 0.13534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomlack.fr",
      "product": "Page Builder CK extension for Joomla",
      "cwe": "CWE-434",
      "title": "Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63048"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-63683",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Advanced Module Manager extension for Joomla",
      "cwe": "CWE-290",
      "title": "Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63683"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-65011",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Graylog2",
      "product": "graylog2-server",
      "cwe": "CWE-862",
      "title": "Graylog2 Server Missing Permission Check on Event Definition Duplicate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65011"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-44687",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00218,
      "epss_percentile": 0.12527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-193",
      "title": "Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44687"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-13321",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00217,
      "epss_percentile": 0.12468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ISC",
      "product": "BIND 9",
      "cwe": "CWE-346",
      "title": "DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13321"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-13073",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-617",
      "title": "MongoDB Aggregation Command Invariant Assertion Failure Leading to Process Termination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13073"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-65597",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-79",
      "title": "n8n before 1.123.64 DOM-Based XSS via Unsandboxed iframe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65597"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-64833",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.1205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-125",
      "title": "FFmpeg 0.7.1 - 8.1.2 Out-of-Bounds Read via S/PDIF Muxer spdifenc.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64833"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-57599",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hikvision",
      "product": "DS-2CD Series",
      "cwe": "CWE-269",
      "title": "There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57599"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-64828",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.1164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Froiden",
      "product": "TableTrack",
      "cwe": "CWE-79",
      "title": "Froiden TableTrack 1.3.10 Stored XSS via Order Notes Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64828"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-13078",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-862",
      "title": "Local File Disclosure in MongoDB Server via MozJS Scripting Engine Module Loader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13078"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-14932",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Telerik UI for ASP.NET AJAX",
      "cwe": "CWE-321",
      "title": "Unauthenticated File Read and Deletion via Hardcoded Encryption Key in RadChart",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14932"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-65596",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.1135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-863",
      "title": "n8n before 1.123.64 Credential Exfiltration via GraphQL Node",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65596"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-61392",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.11018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hikvision",
      "product": "DS-2CD Series",
      "cwe": "CWE-200",
      "title": "There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61392"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-42955",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00203,
      "epss_percentile": 0.10617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-672",
      "title": "Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42955"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-13184",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Telerik UI for ASP.NET AJAX",
      "cwe": "CWE-321",
      "title": "RadAsyncUpload Default HMAC Key Fallback Vulnerability in Telerik UI for ASP.NET AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13184"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-64797",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "IP Login extension for Joomla",
      "cwe": "CWE-290",
      "title": "Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64797"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-60370",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.10299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Platform Security for Java",
      "cwe": "CWE-1021",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60370"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-16490",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.002,
      "epss_percentile": 0.10239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itsourcecode",
      "product": "Hospital Management System",
      "cwe": "CWE-74",
      "title": "itsourcecode Hospital Management System prescription.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16490"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-65602",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "traefik",
      "product": "traefik",
      "cwe": "CWE-863",
      "title": "Traefik before 3.6.23 IngressRouteTCP ServersTransport Namespace Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65602"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-14322",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Timetics",
      "cwe": "CWE-284",
      "title": "Timetics < 1.0.57 - Unauthenticated Booking Auto-Approval via Arbitrary payment_method",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14322"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-46582",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00181,
      "epss_percentile": 0.07987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-358",
      "title": "A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46582"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-54478",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00178,
      "epss_percentile": 0.07611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-290",
      "title": "DNS Cookie bypass when combined with proxy-protocol use",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54478"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-38763",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38763"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-14985",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.07159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Analog Way",
      "product": "Picturall Quad Compact Mark II",
      "cwe": "CWE-22",
      "title": "CVE-2026-14985",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14985"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-13069",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-770",
      "title": "Queryable Encryption FLE2 Find Payload Missing Input Validation Leading to Resource Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13069"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-65592",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-79",
      "title": "n8n before 1.123.64 Stored DOM XSS via cachedResultUrl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65592"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-38765",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-269",
      "title": "An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38765"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-38766",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06891,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-269",
      "title": "An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38766"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-60371",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Oracle Corporation",
      "product": "Oracle Platform Security for Java",
      "cwe": "CWE-200",
      "title": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Platform Security for Java executes to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60371"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-13061",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06313,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-863",
      "title": "Improper Access Control Allowing Cross-User Session Metadata Disclosure in $listSessions Aggregation Stage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13061"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-65599",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00153,
      "epss_percentile": 0.05017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-312",
      "title": "n8n before 1.123.64, 2.29.8, and 2.30.1 Credential Exposure via JWT Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65599"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-14881",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.04871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Compass",
      "cwe": "CWE-78",
      "title": "Compass connection import allows to override OIDC browser open command (usually set through settings), allowing for arbitrary shell commands execution when connecting to cluster using OIDC auth flow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14881"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-55708",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0015,
      "epss_percentile": 0.047,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-1188",
      "title": "Privacy/configuration issue when adding local data in views through 'unbound-control'",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55708"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-44192",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-22",
      "title": "Ansible-lightspeed: ansible lightspeed mcp server: remote code execution and data exfiltration via path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44192"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2025-60835",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-35",
      "title": "An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60835"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-13068",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00148,
      "epss_percentile": 0.04562,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-863",
      "title": "MongoDB mongos Improper Authorization Check in Cursor Termination Allowing Cross-Database Privilege Misuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13068"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-44690",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-345",
      "title": "Cross-zone wildcard cache poisoning via RRSIG.labels manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44690"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-65593",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00143,
      "epss_percentile": 0.04123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n8n-io",
      "product": "n8n",
      "cwe": "CWE-918",
      "title": "n8n before 1.123.64, 2.29.8, and 2.30.1 SSRF via Dynamic Node Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65593"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-63281",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.04034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Advanced Module Manager extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63281"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-50252",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-349",
      "title": "Possible cache poisoning attack by mapping source port population per thread",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50252"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-64795",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Modals extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64795"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-14551",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "servereye GmbH",
      "product": "servereye Windows Agent (Sensorhub)",
      "cwe": "CWE-73",
      "title": "Local Privilege Escalation in servereye client (sensorhub)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14551"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-56844",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Veeam",
      "product": "Backup and Replication",
      "cwe": "CWE-22",
      "title": "A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the underlying operating system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56844"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-50248",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-345",
      "title": "BOGUS configured primary hostname accepted for XFR in auth/rpz zones",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50248"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-63280",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Advanced Module Manager extension for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63280"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-63684",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Content Templater extension for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63684"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-64791",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Regular Labs Extension Manager extension for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64791"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-16157",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00119,
      "epss_percentile": 0.02044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Duplicati",
      "product": "Duplicati",
      "cwe": "CWE-732",
      "title": "Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16157"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-56416",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.01988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-354",
      "title": "Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56416"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-63265",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Advanced Module Manager extension for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63265"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-13062",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00114,
      "epss_percentile": 0.01713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-441",
      "title": "MongoDB mongos Improper Validation of Internal Flags in Queryable Encryption Write Commands on Sharded Clusters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13062"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-13188",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "Telerik UI for ASP.NET AJAX",
      "cwe": "CWE-345",
      "title": "DialogHandler Parameters Tampering Vulnerability in Telerik UI for ASP.NET AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13188"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-44276",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "PowerProtect Data Manager",
      "cwe": "CWE-200",
      "title": "Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the REST API. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44276"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-50243",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NLnet Labs",
      "product": "Unbound",
      "cwe": "CWE-348",
      "title": "'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50243"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-16607",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.001,
      "epss_percentile": 0.01011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Fujitsu",
      "product": "Linux openFT",
      "cwe": "CWE-269",
      "title": "Authenticated local root privilege escalation vulnerability in openFT for Linux and Oracle Solaris",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16607"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-7328",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00091,
      "epss_percentile": 0.00559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Caliptra",
      "product": "Core Runtime Firmware",
      "cwe": "CWE-862",
      "title": "Unverified AXI Address in Subsystem Mode Commands Enables Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7328"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-13070",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00089,
      "epss_percentile": 0.00474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-476",
      "title": "Improper Validation of OCSP Response During Outbound TLS Handshake Leading to Process Termination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13070"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-44187",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00089,
      "epss_percentile": 0.005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2",
      "cwe": "CWE-256",
      "title": "Ansible-lightspeed: ansible lightspeed extension for visual studio code: information disclosure of google gemini api key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44187"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-13067",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00067,
      "epss_percentile": 0.00029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MongoDB",
      "product": "MongoDB Server",
      "cwe": "CWE-863",
      "title": "tlsCATrusts Role Restriction Not Enforced via PROXY Protocol v2 on Unix Domain Socket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13067"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2016-20096",
      "detail": "EXPLOIT PUBLISHED — CVE-2016-20096 (Kunshi Network Technology Co., Ltd. Linknat VOS3000). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-27137",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-27137 (DD-WRT). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-60689",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-60689. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16329",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16329 (D-Link DNS-320). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16331",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16331 (D-Link DNS-320). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16332",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16332 (D-Link DNS-320). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16334",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16334 (itsourcecode Hospital Management System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16447",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16447 (D-Link DNS-320). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16449",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16449 (zsadmin2025 ZS-Admin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16450",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16450 (zsadmin2025 ZS-Admin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16451",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16451 (zsadmin2025 ZS-Admin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16484",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16484 (SourceCodester Class and Exam Timetabling System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16485",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16485 (SourceCodester Class and Exam Timetabling System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16486",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16486 (SourceCodester Class and Exam Timetabling System). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-20230",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-20230 (Cisco Unified Communications Manager). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-3833",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-3833 (gnutls). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-48029",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-48029 (strukturag libheif). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50475",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50475 (Microsoft Windows 10 Version 1607). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-5497",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-5497 (vllm-project/vllm). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-58613",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-58613 (Microsoft Windows 10 Version 1809). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63080",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63080 (aptabase). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63107",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63107 (LimeSurvey). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-64821",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-64821 (thiagopena djangoSIGE). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-64822",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-64822 (thiagopena djangoSIGE). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2022-2712",
      "detail": "RESCORED — CVE-2022-2712 (The Eclipse Foundation Eclipse GlassFish). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16073",
      "detail": "RESCORED — CVE-2026-16073 (AstrBotDevs AstrBot). CVSS 5.1 → 2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16082",
      "detail": "RESCORED — CVE-2026-16082 (Sipeed PicoClaw). CVSS 4.8 → 1.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16123",
      "detail": "RESCORED — CVE-2026-16123 (nextlevelbuilder GoClaw). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16129",
      "detail": "RESCORED — CVE-2026-16129 (princezuda SafestClaw). CVSS 4.8 → 1.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16152",
      "detail": "RESCORED — CVE-2026-16152 (SourceCodester Class and Exam Timetabling System). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16196",
      "detail": "RESCORED — CVE-2026-16196 (Sipeed PicoClaw). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16202",
      "detail": "RESCORED — CVE-2026-16202 (SourceCodester Class and Exam Timetabling System). CVSS 5.1 → 2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16214",
      "detail": "RESCORED — CVE-2026-16214 (geex-arts django-jet). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16220",
      "detail": "RESCORED — CVE-2026-16220 (code-projects Online Examination System). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16227",
      "detail": "RESCORED — CVE-2026-16227 (SourceCodester Class and Exam Timetabling System). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16488",
      "detail": "RESCORED — CVE-2026-16488 (QUSETIONS MiniCode-Python). CVSS 2.3 → 1.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16489",
      "detail": "RESCORED — CVE-2026-16489 (jsforce). CVSS 4.8 → 1.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-28369",
      "detail": "RESCORED — CVE-2026-28369 (Red Hat JBoss Enterprise Application Platform 8.1). CVSS 8.7 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-3833",
      "detail": "RESCORED — CVE-2026-3833 (gnutls). CVSS 6.5 → 7.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-44806",
      "detail": "RESCORED — CVE-2026-44806 (Microsoft Windows 10 Version 1607). CVSS 5.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-49164",
      "detail": "RESCORED — CVE-2026-49164 (Microsoft Windows 10 Version 1607). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-49167",
      "detail": "RESCORED — CVE-2026-49167 (Microsoft Windows 10 Version 1809). CVSS 4.7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-49171",
      "detail": "RESCORED — CVE-2026-49171 (Microsoft Windows 10 Version 1607). CVSS 7.5 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-49184",
      "detail": "RESCORED — CVE-2026-49184 (Microsoft Windows 10 Version 1607). CVSS 8.4 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-49789",
      "detail": "RESCORED — CVE-2026-49789 (Microsoft Windows 10 Version 1607). CVSS 7.3 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-49791",
      "detail": "RESCORED — CVE-2026-49791 (Microsoft Windows 10 Version 1607). CVSS 7.1 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50302",
      "detail": "RESCORED — CVE-2026-50302 (Microsoft Windows 10 Version 21H2). CVSS 4.2 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50307",
      "detail": "RESCORED — CVE-2026-50307 (Microsoft Windows 10 Version 1809). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50312",
      "detail": "RESCORED — CVE-2026-50312 (Microsoft Windows 10 Version 1607). CVSS 4.7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50321",
      "detail": "RESCORED — CVE-2026-50321 (Microsoft Windows 10 Version 1607). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50330",
      "detail": "RESCORED — CVE-2026-50330 (Microsoft Windows 10 Version 1607). CVSS 7.5 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50340",
      "detail": "RESCORED — CVE-2026-50340 (Microsoft Windows 11 Version 24H2). CVSS 8.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50348",
      "detail": "RESCORED — CVE-2026-50348 (Microsoft Windows 10 Version 1809). CVSS 7 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50358",
      "detail": "RESCORED — CVE-2026-50358 (Microsoft Windows 10 Version 1607). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50359",
      "detail": "RESCORED — CVE-2026-50359 (Microsoft Windows 10 Version 1607). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50375",
      "detail": "RESCORED — CVE-2026-50375 (Microsoft Windows 10 Version 1809). CVSS 6.3 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50378",
      "detail": "RESCORED — CVE-2026-50378 (Microsoft Windows 10 Version 1809). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50383",
      "detail": "RESCORED — CVE-2026-50383 (Microsoft Windows 10 Version 1809). CVSS 6.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50390",
      "detail": "RESCORED — CVE-2026-50390 (Microsoft Windows 10 Version 1607). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50393",
      "detail": "RESCORED — CVE-2026-50393 (Microsoft Windows 11 Version 24H2). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50396",
      "detail": "RESCORED — CVE-2026-50396 (Microsoft Windows 11 Version 24H2). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50398",
      "detail": "RESCORED — CVE-2026-50398 (Microsoft Windows 11 Version 24H2). CVSS 8.8 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50413",
      "detail": "RESCORED — CVE-2026-50413 (Microsoft Windows 11 Version 24H2). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50414",
      "detail": "RESCORED — CVE-2026-50414 (Microsoft Windows 11 Version 24H2). CVSS 7.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50415",
      "detail": "RESCORED — CVE-2026-50415 (Microsoft Windows 10 Version 1809). CVSS 5.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50418",
      "detail": "RESCORED — CVE-2026-50418 (Microsoft Windows 11 Version 24H2). CVSS 5.1 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50420",
      "detail": "RESCORED — CVE-2026-50420 (Microsoft Windows 11 Version 24H2). CVSS 6.2 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50428",
      "detail": "RESCORED — CVE-2026-50428 (Microsoft Windows 11 version 26H1). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50432",
      "detail": "RESCORED — CVE-2026-50432 (Microsoft Windows 10 Version 1607). CVSS 5.3 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50439",
      "detail": "RESCORED — CVE-2026-50439 (Microsoft Windows 10 Version 1607). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50445",
      "detail": "RESCORED — CVE-2026-50445 (Microsoft Windows 10 Version 1607). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50450",
      "detail": "RESCORED — CVE-2026-50450 (Microsoft Windows 10 Version 1809). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50451",
      "detail": "RESCORED — CVE-2026-50451 (Microsoft Windows 10 Version 1607). CVSS 7.1 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50452",
      "detail": "RESCORED — CVE-2026-50452 (Microsoft Windows 10 Version 1809). CVSS 7 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50453",
      "detail": "RESCORED — CVE-2026-50453 (Microsoft Windows 10 Version 1607). CVSS 6.1 → 4.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50459",
      "detail": "RESCORED — CVE-2026-50459 (Microsoft Windows 10 Version 21H2). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50477",
      "detail": "RESCORED — CVE-2026-50477 (Microsoft Windows 10 Version 1607). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50482",
      "detail": "RESCORED — CVE-2026-50482 (Microsoft Windows 10 Version 1607). CVSS 7.3 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50487",
      "detail": "RESCORED — CVE-2026-50487 (Microsoft Windows 11 Version 24H2). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50490",
      "detail": "RESCORED — CVE-2026-50490 (Microsoft Windows 10 Version 1607). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50495",
      "detail": "RESCORED — CVE-2026-50495 (Microsoft Windows 10 Version 1809). CVSS 6.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50497",
      "detail": "RESCORED — CVE-2026-50497 (Microsoft Windows 10 Version 1607). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50502",
      "detail": "RESCORED — CVE-2026-50502 (Microsoft Windows 10 Version 1607). CVSS 8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50504",
      "detail": "RESCORED — CVE-2026-50504 (Microsoft Windows 10 Version 1607). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50505",
      "detail": "RESCORED — CVE-2026-50505 (Microsoft Windows 10 Version 1607). CVSS 7.5 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50526",
      "detail": "RESCORED — CVE-2026-50526 (Microsoft .NET 10.0). CVSS 7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50657",
      "detail": "RESCORED — CVE-2026-50657 (Microsoft Defender for Endpoint for Mac). CVSS 4.7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50661",
      "detail": "RESCORED — CVE-2026-50661 (Microsoft Windows 10 Version 1607). CVSS 6.1 → 4.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50667",
      "detail": "RESCORED — CVE-2026-50667 (Microsoft Windows 10 Version 1607). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50674",
      "detail": "RESCORED — CVE-2026-50674 (Microsoft Windows 11 Version 24H2). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50676",
      "detail": "RESCORED — CVE-2026-50676 (Microsoft Windows 11 Version 24H2). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50680",
      "detail": "RESCORED — CVE-2026-50680 (Microsoft Windows 10 Version 1809). CVSS 8.2 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50687",
      "detail": "RESCORED — CVE-2026-50687 (Microsoft Windows 11 Version 24H2). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50694",
      "detail": "RESCORED — CVE-2026-50694 (Microsoft Windows 10 Version 1607). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-54127",
      "detail": "RESCORED — CVE-2026-54127 (Microsoft Windows 11 Version 24H2). CVSS 7.4 → 8.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-54129",
      "detail": "RESCORED — CVE-2026-54129 (Microsoft Windows 10 Version 1809). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-54990",
      "detail": "RESCORED — CVE-2026-54990 (Microsoft Windows 11 Version 24H2). CVSS 9.8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-55145",
      "detail": "RESCORED — CVE-2026-55145 (Microsoft Copilot). CVSS 6.3 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-56171",
      "detail": "RESCORED — CVE-2026-56171 (Microsoft Remote Desktop Web Client). CVSS 7.1 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-56178",
      "detail": "RESCORED — CVE-2026-56178 (Microsoft Defender for Endpoint for Mac). CVSS 5.5 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-56186",
      "detail": "RESCORED — CVE-2026-56186 (Microsoft Windows 10 Version 1607). CVSS 8.1 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-56188",
      "detail": "RESCORED — CVE-2026-56188 (Microsoft Windows 10 Version 1607). CVSS 9.8 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-56189",
      "detail": "RESCORED — CVE-2026-56189 (Microsoft Windows 10 Version 1607). CVSS 7.8 → 8.4 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-56649",
      "detail": "RESCORED — CVE-2026-56649 (Microsoft Windows 10 Version 1607). CVSS 5.9 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-57085",
      "detail": "RESCORED — CVE-2026-57085 (Microsoft Windows 10 Version 1607). CVSS 5.5 → 3.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-57087",
      "detail": "RESCORED — CVE-2026-57087 (Microsoft Windows 10 Version 1607). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-57090",
      "detail": "RESCORED — CVE-2026-57090 (Microsoft Windows 10 Version 1607). CVSS 8.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-57093",
      "detail": "RESCORED — CVE-2026-57093 (Microsoft Windows 10 Version 1607). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-57095",
      "detail": "RESCORED — CVE-2026-57095 (Microsoft Windows 10 Version 1607). CVSS 6.2 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-57097",
      "detail": "RESCORED — CVE-2026-57097 (Microsoft Windows 10 Version 1607). CVSS 6.4 → 6.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-57979",
      "detail": "RESCORED — CVE-2026-57979 (Microsoft Windows 10 Version 1607). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58526",
      "detail": "RESCORED — CVE-2026-58526 (Microsoft Windows 10 Version 1809). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58527",
      "detail": "RESCORED — CVE-2026-58527 (Microsoft Windows 11 Version 24H2). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58528",
      "detail": "RESCORED — CVE-2026-58528 (Microsoft Windows 10 Version 1809). CVSS 6.8 → 4.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58533",
      "detail": "RESCORED — CVE-2026-58533 (Microsoft Windows 10 Version 1607). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58534",
      "detail": "RESCORED — CVE-2026-58534 (Microsoft Windows 10 Version 1607). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58535",
      "detail": "RESCORED — CVE-2026-58535 (Microsoft Windows 10 Version 1607). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58539",
      "detail": "RESCORED — CVE-2026-58539 (Microsoft Windows 10 Version 1607). CVSS 6.5 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58547",
      "detail": "RESCORED — CVE-2026-58547 (Microsoft Windows 10 Version 1809). CVSS 5.5 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58594",
      "detail": "RESCORED — CVE-2026-58594 (Microsoft Windows 10 Version 1607). CVSS 8.8 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58608",
      "detail": "RESCORED — CVE-2026-58608 (Microsoft Windows 10 Version 1607). CVSS 8.8 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58638",
      "detail": "RESCORED — CVE-2026-58638 (Microsoft Windows 10 Version 1809). CVSS 6 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-58640",
      "detail": "RESCORED — CVE-2026-58640 (Microsoft Windows 10 Version 1607). CVSS 7.3 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-62826",
      "detail": "RESCORED — CVE-2026-62826 (Microsoft SharePoint Enterprise Server 2016). CVSS 4.6 → 5.4 (NVD)."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-48595",
      "detail": "ENRICHED — CVE-2025-48595 (Android Framework). Received CVSS 8.4 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-20230",
      "detail": "ENRICHED — CVE-2026-20230 (Cisco Unified Communications Manager). Received CVSS 8.6 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-28318",
      "detail": "ENRICHED — CVE-2026-28318 (SolarWinds Serv-U). Received CVSS 7.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
