{
  "day": "2026-07-23",
  "boundary": "UTC calendar day",
  "published_count": 376,
  "by_severity": {
    "CRITICAL": 63,
    "HIGH": 137,
    "MEDIUM": 166,
    "LOW": 10
  },
  "kev_count": 0,
  "exploit_reference_count": 16,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-6516",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.04729,
      "epss_percentile": 0.9112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zohocorp",
      "product": "ManageEngine ADAudit Plus",
      "cwe": "CWE-78",
      "title": "Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6516"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-47668",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.04339,
      "epss_percentile": 0.90422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dbgate",
      "product": "dbgate",
      "cwe": "CWE-20",
      "title": "DbGate: Unauthenticated Remote Code Execution via JSON Script Runner",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47668"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-65694",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.02456,
      "epss_percentile": 0.83126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microweber",
      "product": "microweber",
      "cwe": "CWE-22",
      "title": "Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65694"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-65919",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01837,
      "epss_percentile": 0.77226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "meshery",
      "product": "meshery",
      "cwe": "CWE-22",
      "title": "Meshery < 1.0.57 Unauthenticated Arbitrary File Read via fileView and fileDownload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65919"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-47670",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01714,
      "epss_percentile": 0.75555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dbgate",
      "product": "dbgate",
      "cwe": "CWE-77",
      "title": "DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47670"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-65700",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01269,
      "epss_percentile": 0.67454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "h2oai",
      "product": "h2ogpt",
      "cwe": "CWE-22",
      "title": "h2oGPT 0.2.1 Path Traversal via OpenAI-compatible Files API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65700"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2025-71389",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00928,
      "epss_percentile": 0.57739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "calcom",
      "product": "cal.diy",
      "cwe": "CWE-94",
      "title": "Cal.com before 5.9.9 Remote Code Execution via RSC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71389"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-65608",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00849,
      "epss_percentile": 0.55287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-470",
      "title": "Grav before 2.0.9 Remote Code Execution via FlexDirectory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65608"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-63732",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00744,
      "epss_percentile": 0.51922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9router",
      "cwe": "CWE-78",
      "title": "9router before 0.4.60 Remote Code Execution via default password",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63732"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-56165",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00721,
      "epss_percentile": 0.51096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Account",
      "cwe": "CWE-122",
      "title": "Microsoft Account Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56165"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-54120",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00709,
      "epss_percentile": 0.5068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Surface Management Services",
      "cwe": "CWE-20",
      "title": "Microsoft Surface Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54120"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-16763",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00703,
      "epss_percentile": 0.50449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "localstack",
      "product": "serverless-localstack",
      "cwe": "CWE-77",
      "title": "localstack serverless-localstack Configuration index.js os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16763"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-14282",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00671,
      "epss_percentile": 0.49234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rtcamp",
      "product": "GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more",
      "cwe": "CWE-434",
      "title": "GoDAM <= 1.12.2 - Unauthenticated Arbitrary File Upload via WPForms File Upload Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14282"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-16735",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00622,
      "epss_percentile": 0.47124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "release-it",
      "product": "conventional-changelog",
      "cwe": "CWE-77",
      "title": "release-it conventional-changelog Changelog File index.js writeChangelog os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16735"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-16078",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00613,
      "epss_percentile": 0.46675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kilbot",
      "product": "WCPOS – Point of Sale (POS) plugin for WooCommerce",
      "cwe": "CWE-22",
      "title": "WCPOS <= 1.9.8 - Authenticated (Shop Manager+) Path Traversal to Arbitrary File Read via 'type' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16078"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-16733",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00612,
      "epss_percentile": 0.46617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bahmutov",
      "product": "find-cypress-specs",
      "cwe": "CWE-77",
      "title": "bahmutov find-cypress-specs Branch index.js shell.exec os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16733"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-65690",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00599,
      "epss_percentile": 0.46062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bold Reports (By SyncFusion)",
      "product": "Standalone Report Designer",
      "cwe": "CWE-22",
      "title": "Bold Reports Standalone Report Designer < 14.1.12 Path Traversal RCE via File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65690"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-59543",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00597,
      "epss_percentile": 0.45911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPLake",
      "product": "Advanced Views",
      "cwe": "CWE-94",
      "title": "WordPress Advanced Views plugin <= 3.8.11 - Remote Code Execution (RCE) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59543"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-65688",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00594,
      "epss_percentile": 0.45784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bold Reports (By SyncFusion)",
      "product": "Standalone Report Designer",
      "cwe": "CWE-22",
      "title": "Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Font Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65688"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-56160",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00584,
      "epss_percentile": 0.45355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Red Hat OpenShift (ARO)",
      "cwe": "CWE-285",
      "title": "Azure Red Hat OpenShift (ARO) Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56160"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-65701",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00582,
      "epss_percentile": 0.45273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "svc-develop-team",
      "product": "so-vits-svc",
      "cwe": "CWE-22",
      "title": "SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65701"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-65687",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00581,
      "epss_percentile": 0.45227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bold Reports (By SyncFusion)",
      "product": "Standalone Report Designer",
      "cwe": "CWE-22",
      "title": "Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via SVG Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65687"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-65689",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00581,
      "epss_percentile": 0.45227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bold Reports (By SyncFusion)",
      "product": "Standalone Report Designer",
      "cwe": "CWE-22",
      "title": "Bold Reports Standalone Report Designer < 14.1.12 Arbitrary File Read via Database Download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65689"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-15981",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00547,
      "epss_percentile": 0.43485,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cyberlord92",
      "product": "SAML Single Sign On – SSO Login",
      "cwe": "CWE-287",
      "title": "SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15981"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-65605",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00516,
      "epss_percentile": 0.41746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan before v3.7.2 Stored XSS to RCE via Attribute View",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65605"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-65606",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00516,
      "epss_percentile": 0.41746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan before v3.7.2 Cross-Site Scripting to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65606"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-52439",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00515,
      "epss_percentile": 0.4168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-917",
      "title": "An issue in xiandafu beetl 3.20.2 allows a remote attacker to execute arbitrary code via the type.new function and the property reflection mechanism",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52439"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-44909",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00515,
      "epss_percentile": 0.41692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Facebook",
      "product": "proxygen",
      "cwe": null,
      "title": "Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP/2 flow-control by setting SETTINGS_INITIAL_WINDOW_SIZE to 0 or withholding WINDOW_UPDATE frames, causing the server to buffer complete response bodies in memory indefinitely for stalled streams. By opening many simultaneous streams requesting large resources while preventing the server from transmitting responses, an attacker could induce unbounded memory growth leading to service degradation, resource exhaustion, or denial of service. Versions v2017.01.16.00 through v2026.07.20.00 are affected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44909"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-15011",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00494,
      "epss_percentile": 0.40435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "emarket-design",
      "product": "Customer Support Ticket System & Helpdesk",
      "cwe": "CWE-94",
      "title": "Customer Support Ticket System & Helpdesk <= 6.0.5 - Unauthenticated Code Injection via 'path' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15011"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-64800",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00491,
      "epss_percentile": 0.40225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "GoLand",
      "cwe": "CWE-532",
      "title": "In JetBrains GoLand before 2026.2 sensitive configuration values written to log files by default",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64800"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-65702",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00487,
      "epss_percentile": 0.40006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vanna-ai",
      "product": "vanna",
      "cwe": "CWE-22",
      "title": "Vanna 2.0.2 Path Traversal via FileSystemConversationStore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65702"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-16653",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0048,
      "epss_percentile": 0.39571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boazsegev",
      "product": "facil.io",
      "cwe": "CWE-22",
      "title": "boazsegev facil.io Public Folder http.c http_sendfile2 path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16653"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-16767",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00479,
      "epss_percentile": 0.39493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ne-Lexa",
      "product": "php-zip",
      "cwe": "CWE-22",
      "title": "Ne-Lexa php-zip ZIP ZipFile.php extractTo path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16767"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-64600",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00474,
      "epss_percentile": 0.39139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-362",
      "title": "xfs: resample the data fork mapping after cycling ILOCK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64600"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-16287",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00473,
      "epss_percentile": 0.39134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TUBITAK BILGEM Software Technologies Research Institute",
      "product": "pardus-update",
      "cwe": "CWE-78",
      "title": "Root Command Injection via Offline Update in TÜBİTAK BİLGEM's pardus-update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16287"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-59542",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0045,
      "epss_percentile": 0.37551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Chill",
      "product": "Kali Forms",
      "cwe": "CWE-22",
      "title": "WordPress Kali Forms plugin <= 2.4.18 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59542"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-15074",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00448,
      "epss_percentile": 0.37444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "@fastify/static",
      "product": "@fastify/static",
      "cwe": "CWE-22",
      "title": "@fastify/static vulnerable to route guard bypass via path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15074"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-44210",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00448,
      "epss_percentile": 0.37472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kata-containers",
      "product": "kata-containers",
      "cwe": "CWE-88",
      "title": "Kata Containers have VM Escape via virtiofsd Argument Injection through Default-Enabled Pod Annotations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44210"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-65907",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00421,
      "epss_percentile": 0.35306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-94",
      "title": "In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65907"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-63359",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00418,
      "epss_percentile": 0.35043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Appriss Insights",
      "product": "Victim Information Notification Exchange (VINE)",
      "cwe": "CWE-89",
      "title": "Appriss Insights VINE SQLI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63359"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-65906",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00417,
      "epss_percentile": 0.34932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "TeamCity",
      "cwe": "CWE-94",
      "title": "In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65906"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-16756",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00417,
      "epss_percentile": 0.34997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "aws-smithy-http-server",
      "cwe": "CWE-770",
      "title": "Allocation of resources without limits in the default aws-smithy-http-server serve() path allows unauthenticated Slowloris denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16756"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-16723",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00413,
      "epss_percentile": 0.34653,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Alibaba",
      "product": "Fastjson",
      "cwe": "CWE-20",
      "title": "Remote Code Execution in fastjson 1.2.68–1.2.83",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16723"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-15786",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0041,
      "epss_percentile": 0.34296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gowebsmarty",
      "product": "WP Encryption – Lifetime Free SSL Cert & HTTPS, Force SSL / HTTPS Redirect, SSL Security",
      "cwe": "CWE-22",
      "title": "WP Encryption <= 7.8.6.6 - Authenticated (Administrator+) Arbitrary File Write via 'imploded' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15786"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-56167",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00406,
      "epss_percentile": 0.33964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure AI Search",
      "cwe": "CWE-918",
      "title": "Azure AI Search Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56167"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-65607",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00399,
      "epss_percentile": 0.33277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-22",
      "title": "SiYuan before v3.7.2 Path Traversal via /export/temp/",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65607"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-16806",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16806"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-64813",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00393,
      "epss_percentile": 0.32625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-602",
      "title": "In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64813"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-47752",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00392,
      "epss_percentile": 0.32467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quenary",
      "product": "tugtainer",
      "cwe": "CWE-1336",
      "title": "Tugtainer has Server-Side Template Injection in notification templates that leads to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47752"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2024-58354",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00386,
      "epss_percentile": 0.31886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "calcom",
      "product": "cal.diy",
      "cwe": "CWE-77",
      "title": "cal.com Repository Takeover via pull_request_target Workflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-58354"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-15015",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00381,
      "epss_percentile": 0.31368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cascadiawebservices",
      "product": "MountDev AI MCP Connector for WordPress",
      "cwe": "CWE-862",
      "title": "MountDev AI MCP Connector for WordPress <= 1.6.1 - Unauthenticated Privilege Escalation via OAuth Authorization Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15015"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-63765",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00381,
      "epss_percentile": 0.31384,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chatwoot",
      "product": "chatwoot",
      "cwe": "CWE-306",
      "title": "Chatwoot < 4.16.0 Unauthenticated ActiveStorage Direct Upload Arbitrary Blob Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63765"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-59555",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0038,
      "epss_percentile": 0.31347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roland Barker",
      "product": "Participants Database",
      "cwe": "CWE-22",
      "title": "WordPress Participants Database plugin <= 2.7.8.3 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59555"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-65431",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0038,
      "epss_percentile": 0.31348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "GeoIP extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - regularlabs.com - Zipslip in GeoIP extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65431"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-65493",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.30591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokan",
      "product": "Dokan Pro",
      "cwe": "CWE-502",
      "title": "WordPress Dokan Pro plugin <= 5.0.2 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65493"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-65497",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Complianz",
      "product": "Complianz",
      "cwe": "CWE-502",
      "title": "WordPress Complianz plugin <= 7.5.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65497"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-49035",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.3019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MZ Automation",
      "product": "libIEC61850",
      "cwe": "CWE-122",
      "title": "Stack-based Buffer Overflow in MZ Automation libIEC61850",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49035"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-65455",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00367,
      "epss_percentile": 0.29948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MapSVG",
      "product": "MapSVG",
      "cwe": "CWE-434",
      "title": "WordPress MapSVG plugin <= 8.14.0 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65455"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-65461",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00367,
      "epss_percentile": 0.29949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Webの相談所",
      "product": "Really Simple CSV Importer",
      "cwe": "CWE-434",
      "title": "WordPress Really Simple CSV Importer plugin <= 1.3 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65461"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-64812",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00363,
      "epss_percentile": 0.29594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-306",
      "title": "In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64812"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-15017",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mdjm",
      "product": "MDJM Event Management",
      "cwe": "CWE-269",
      "title": "MDJM Event Management <= 1.7.8.4 - Authenticated (Subscriber+) Privilege Escalation via 'set-permissions' and 'change_role' Handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15017"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-65897",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-269",
      "title": "Grav API Plugin 1.0.9 Privilege Escalation via Invitations groups",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65897"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-47769",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00361,
      "epss_percentile": 0.29343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Work90210",
      "product": "APIFold",
      "cwe": "CWE-306",
      "title": "APIFold Vulnerable to Unauthenticated Webhook Event Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47769"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-65917",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00356,
      "epss_percentile": 0.28883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "usmannasir",
      "product": "cyberpanel",
      "cwe": "CWE-639",
      "title": "CyberPanel IncBackups IDOR via Sequential Backup ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65917"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-47743",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shopperlabs",
      "product": "shopper",
      "cwe": "CWE-79",
      "title": "Shopper: Multiple data integrity and disclosure issues in admin Livewire components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47743"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-47724",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0035,
      "epss_percentile": 0.28208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "juev",
      "product": "nebula-mesh",
      "cwe": "CWE-862",
      "title": "nebula-mesh: API endpoints lack ownership checks, enabling cross-operator privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47724"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-65698",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00347,
      "epss_percentile": 0.27903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "voideditor",
      "product": "void",
      "cwe": "CWE-22",
      "title": "Void 1.3.4 Path Traversal via AI Agent File-Reading Tools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65698"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-47669",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00344,
      "epss_percentile": 0.2757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dbgate",
      "product": "dbgate",
      "cwe": "CWE-22",
      "title": "DbGate: Zip Slip in archive/unzip allows arbitrary file write leading to RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47669"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-14257",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "juliangruber",
      "product": "brace-expansion",
      "cwe": "CWE-400",
      "title": "brace-expansion DoS via unbounded expansion length causing an out-of-memory process crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14257"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-25800",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quinn-rs",
      "product": "quinn",
      "cwe": "CWE-770",
      "title": "quinn-proto has remote memory exhaustion from unbounded out-of-order stream reassembly",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25800"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-64611",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-835",
      "title": "Libcupsfilters: cups-filters: libcupsfilters: cpu exhaustion via infinite loop in cfieee1284normalizemakemodel()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64611"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-65762",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00339,
      "epss_percentile": 0.2696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phoca.cz",
      "product": "Phoca Guestbook extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65762"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-65763",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00339,
      "epss_percentile": 0.2696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phoca.cz",
      "product": "Phoca Maps extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65763"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-63313",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00336,
      "epss_percentile": 0.26638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decolua",
      "product": "9router",
      "cwe": "CWE-918",
      "title": "9Router before 0.4.72 Server-Side Request Forgery via /v1/web/fetch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63313"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-65916",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00336,
      "epss_percentile": 0.26674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "usmannasir",
      "product": "cyberpanel",
      "cwe": "CWE-862",
      "title": "CyberPanel Missing Authorization in cancelBackupCreation Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65916"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-65754",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.2657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "ReReplacer PRo extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65754"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-64815",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0033,
      "epss_percentile": 0.26016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-94",
      "title": "In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64815"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-15616",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00328,
      "epss_percentile": 0.25828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Logto",
      "product": "Logto",
      "cwe": "CWE-308",
      "title": "Local MFA not enforced during SSO sign-in",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15616"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-16796",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25644,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "bedrock-agentcore 1.18.1",
      "cwe": "CWE-88",
      "title": "Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16796"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-14291",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "security-ninja-premium",
      "cwe": "CWE-287",
      "title": "Security Ninja (Premium) < 5.290 - Two-Factor Authentication Bypass via secnin_skip_2fa",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14291"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-65920",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.25471,
      "kev": false,
      "kev_due_at": null,
      "vendor": "huggingface",
      "product": "diffusers",
      "cwe": "CWE-22",
      "title": "Diffusers Path Traversal via weight_map Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65920"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-61951",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00321,
      "epss_percentile": 0.25016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themetechmount",
      "product": "TrueBooker",
      "cwe": "CWE-266",
      "title": "WordPress TrueBooker plugin <= 1.2.3 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61951"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-65695",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.24994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GongRzhe",
      "product": "Office-Word-MCP-Server",
      "cwe": "CWE-22",
      "title": "Office-Word-MCP-Server 1.1.11 Path Traversal via document tools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65695"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-65477",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Select-Themes",
      "product": "Tonda Core",
      "cwe": "CWE-98",
      "title": "WordPress Tonda Core plugin <= 2.1.2 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65477"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-65481",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Elated-Themes",
      "product": "Vino",
      "cwe": "CWE-98",
      "title": "WordPress Vino theme <= 1.9 - Local File Inclusion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65481"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-15348",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0032,
      "epss_percentile": 0.24861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codename065",
      "product": "Premium Packages – Sell Digital Products Securely",
      "cwe": "CWE-287",
      "title": "Premium Packages <= 7.0.4 - Authentication Bypass to Non-Admin via 'wpdmppdl' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15348"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-59522",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00316,
      "epss_percentile": 0.24484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "weDevs",
      "product": "WP ERP",
      "cwe": "CWE-862",
      "title": "WordPress WP ERP plugin <= 1.17.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59522"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-59541",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.2436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hakan Ozevin",
      "product": "WP BASE Booking",
      "cwe": "CWE-266",
      "title": "WordPress WP BASE Booking plugin <= 6.3.1 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59541"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-64814",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.24322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-862",
      "title": "In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64814"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-57367",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.24365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Booking System .",
      "product": "WP Booking System",
      "cwe": "CWE-862",
      "title": "WordPress WP Booking System plugin < 5.12.8.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57367"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-16805",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.24265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16805"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-59544",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00313,
      "epss_percentile": 0.24153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thrive Themes Coupon",
      "product": "Thrive Quiz Builder",
      "cwe": "CWE-502",
      "title": "WordPress Thrive Quiz Builder plugin <= 10.9.3.0 - PHP Object Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59544"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-64799",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.24095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Articles Anywhere Pro extension for Joomla",
      "cwe": "CWE-918",
      "title": "Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64799"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-65918",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.24048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pytorch",
      "product": "vision",
      "cwe": "CWE-125",
      "title": "PyTorch torchvision GIF Decoder Out-of-bounds Heap Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65918"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-15827",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0031,
      "epss_percentile": 0.23807,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ataurr",
      "product": "GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor",
      "cwe": "CWE-862",
      "title": "GutenKit <= 2.4.12 - Missing Authorization to Unauthenticated Sensitive Information Exposure via Mailchimp REST Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15827"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-57696",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.2336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "videowhisper",
      "product": "Picture Gallery",
      "cwe": "CWE-22",
      "title": "WordPress Picture Gallery plugin <= 1.6.5 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57696"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-14481",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.23374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "equalizedigital",
      "product": "Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance",
      "cwe": "CWE-79",
      "title": "Equalize Digital Accessibility Checker <= 1.46.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'html' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14481"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-47723",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "juev",
      "product": "nebula-mesh",
      "cwe": "CWE-1021",
      "title": "nebula-mesh: Web UI and API responses lack security headers (CSP, X-Frame-Options, HSTS, etc.)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47723"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-65495",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokan Multivendor Plugin",
      "product": "Dokan Pro",
      "cwe": "CWE-862",
      "title": "WordPress Dokan Pro plugin <= 5.0.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65495"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-57808",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.22591,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Saad Iqbal",
      "product": "WP EasyPay",
      "cwe": "CWE-862",
      "title": "WordPress WP EasyPay plugin <= 4.5.0 - Arbitrary Content Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57808"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2024-58353",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00298,
      "epss_percentile": 0.22393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "calcom",
      "product": "cal.diy",
      "cwe": "CWE-80",
      "title": "Cal.com through 4.7.15 Cross-Site Scripting via booking questions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-58353"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-59524",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22166,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sandhills Development, LLC",
      "product": "Easy Digital Downloads",
      "cwe": "CWE-288",
      "title": "WordPress Easy Digital Downloads plugin <= 3.6.7 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59524"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-59554",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.22,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ziina",
      "product": "Ziina",
      "cwe": "CWE-1390",
      "title": "WordPress Ziina plugin <= 1.2.21 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59554"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-10697",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00292,
      "epss_percentile": 0.21745,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress",
      "product": "MOVEit Transfer",
      "cwe": "CWE-287",
      "title": "MFA Bypass in MOVEit Transfer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10697"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2024-58355",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "calcom",
      "product": "cal.diy",
      "cwe": "CWE-80",
      "title": "Cal.com through 4.7.15 Cross-Site Scripting via booking questions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-58355"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2024-58330",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bosch",
      "product": "Camera Firmware",
      "cwe": "CWE-284",
      "title": "A missing authentication check in Bosch IP cameras of families CPP13 and CPP14 allows an unauthenticated attacker to retrieve video analytics event data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-58330"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-64874",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0029,
      "epss_percentile": 0.2158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Cache Cleaner Pro extension for Joomla",
      "cwe": "CWE-200",
      "title": "Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64874"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-65604",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.21584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zalando",
      "product": "skipper",
      "cwe": "CWE-20",
      "title": "Skipper Incomplete Fix for CVE-2026-50197 Policy Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65604"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-65500",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pixelacehq",
      "product": "Manual - Documentation, Knowledge Base & Education WordPress Theme",
      "cwe": "CWE-862",
      "title": "WordPress Manual - Documentation, Knowledge Base & Education WordPress theme theme <= 7.5.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65500"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-65463",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00287,
      "epss_percentile": 0.21294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "masteriyo",
      "product": "Masteriyo - LMS",
      "cwe": "CWE-639",
      "title": "WordPress Masteriyo - LMS plugin <= 2.3.1 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65463"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-42933",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00285,
      "epss_percentile": 0.2105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pronetiqs",
      "product": "Panduit Intravue",
      "cwe": "CWE-441",
      "title": "Unintended Proxy or Intermediary in Panduit IntraVUE by Pronetiqs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42933"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-61948",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shahjada",
      "product": "WPDM – Premium Packages",
      "cwe": "CWE-89",
      "title": "WordPress WPDM – Premium Packages plugin <= 6.2.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61948"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-61949",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bookly",
      "product": "Bookly",
      "cwe": "CWE-89",
      "title": "WordPress Bookly plugin <= 27.7 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61949"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-61950",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00283,
      "epss_percentile": 0.20871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themetechmount",
      "product": "TrueBooker",
      "cwe": "CWE-89",
      "title": "WordPress TrueBooker plugin <= 1.2.3 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61950"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-15906",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codename065",
      "product": "Premium Packages – Sell Digital Products Securely",
      "cwe": "CWE-89",
      "title": "Premium Packages <= 7.0.4 - Authenticated (Admin+) SQL Injection via 'orderby' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15906"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-15617",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00279,
      "epss_percentile": 0.2042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Logto",
      "product": "Logto",
      "cwe": "CWE-178",
      "title": "Principal/domain lookup without case normalization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15617"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-65462",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Uncanny Owl",
      "product": "Uncanny Automator",
      "cwe": "CWE-89",
      "title": "WordPress Uncanny Automator plugin <= 7.3.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65462"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-27064",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00278,
      "epss_percentile": 0.20273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EverPress",
      "product": "Mailster",
      "cwe": "CWE-434",
      "title": "WordPress Mailster plugin <= 4.1.17 - Arbitrary File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27064"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-61943",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shahjada",
      "product": "WPDM – Premium Packages",
      "cwe": "CWE-862",
      "title": "WordPress WPDM – Premium Packages plugin <= 6.2.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61943"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-57716",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "videowhisper",
      "product": "Broadcast Live Video",
      "cwe": "CWE-22",
      "title": "WordPress Broadcast Live Video plugin <= 7.2.4 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57716"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-27355",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "metaphorcreations",
      "product": "Ditty",
      "cwe": "CWE-862",
      "title": "WordPress Ditty plugin <= 3.1.66 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27355"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-25427",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DigitalME",
      "product": "eRoom",
      "cwe": "CWE-862",
      "title": "WordPress eRoom plugin <= 1.7.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25427"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-27391",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stylemix",
      "product": "uListing",
      "cwe": "CWE-862",
      "title": "WordPress uListing plugin <= 2.2.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27391"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-65479",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MVP Themes",
      "product": "Reviewer",
      "cwe": "CWE-862",
      "title": "WordPress Reviewer plugin <= 3.14.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65479"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-15611",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00274,
      "epss_percentile": 0.19904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Logto",
      "product": "Logto",
      "cwe": "CWE-287",
      "title": "Unverified email-based SSO account linking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15611"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-65494",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19818,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokan",
      "product": "Dokan Pro",
      "cwe": "CWE-89",
      "title": "WordPress Dokan Pro plugin <= 5.0.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65494"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-47755",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.19878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itflow-org",
      "product": "itflow",
      "cwe": "CWE-639",
      "title": "ITFlow Vulnerable to Authenticated Cross-Tenant Credential Disclosure via Unprotected Credential Modal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47755"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-9713",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "King-Theme",
      "product": "Product Designer for WooCommerce WordPress | Lumise",
      "cwe": "CWE-89",
      "title": "Product Designer for WooCommerce WordPress | Lumise <= 2.1.1 - Unauthenticated SQL Injection via 'id' Parameter in Cart JSON Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9713"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-27377",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "axiomthemes",
      "product": "QuickCal - Appointment Booking Calendar for WordPress",
      "cwe": "CWE-862",
      "title": "WordPress QuickCal - Appointment Booking Calendar for WordPress plugin <= 1.0.16 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27377"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-16745",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift AI 2.25",
      "cwe": "CWE-346",
      "title": "Odh-dashboard: odh-dashboard: backend port 8080 trusts x-forwarded-access-token without origin validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16745"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-47722",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "juev",
      "product": "nebula-mesh",
      "cwe": "CWE-94",
      "title": "nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47722"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-13009",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wupsales",
      "product": "AI Copilot – Content Generator",
      "cwe": "CWE-89",
      "title": "AI Copilot <= 1.5.4 - Authenticated (Subscriber+) SQL Injection via 'order[0][dir]' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13009"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-15761",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tickera",
      "product": "Tickera – Sell Tickets & Manage Events",
      "cwe": "CWE-89",
      "title": "Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_event_filter' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15761"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-59540",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00268,
      "epss_percentile": 0.19084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cozy Vision Technologies Pvt. Ltd.",
      "product": "SMS Alert Order Notifications",
      "cwe": "CWE-266",
      "title": "WordPress SMS Alert Order Notifications plugin <= 3.9.6 - Privilege Escalation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59540"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-64873",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00268,
      "epss_percentile": 0.19085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Cache Cleaner Pro extension for Joomla",
      "cwe": "CWE-918",
      "title": "Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64873"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-59545",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miniOrange",
      "product": "miniOrange Discord Integration",
      "cwe": "CWE-288",
      "title": "WordPress miniOrange Discord Integration plugin <= 2.2.4 - Broken Authentication vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59545"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-27372",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.1902,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepro Dev. Group",
      "product": "PeproDev Ultimate Invoice",
      "cwe": "CWE-201",
      "title": "WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27372"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-50039",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MZ Automation",
      "product": "libIEC61850",
      "cwe": "CWE-121",
      "title": "Stack-based Buffer Overflow in MZ Automation libIEC61850",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50039"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-65896",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00267,
      "epss_percentile": 0.18918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-73",
      "title": "Grav API Plugin before 1.0.10 Path Traversal via move",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65896"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-16807",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18219,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in Codecs in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16807"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-6924",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Silicon Labs",
      "product": "Silicon Labs Matter Github",
      "cwe": "CWE-336",
      "title": "Weak entropy initialization in Silicon Labs Matter SiWx917 TinyCrypt path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6924"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-50032",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.1824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MZ Automation",
      "product": "libIEC61850",
      "cwe": "CWE-476",
      "title": "NULL Pointer Dereference in MZ Automation libIEC61850",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50032"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-16765",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeAstro",
      "product": "Online Classroom",
      "cwe": "CWE-74",
      "title": "CodeAstro Online Classroom loginlinkadmin.php sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16765"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-15037",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00262,
      "epss_percentile": 0.18153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Qt",
      "product": "Qt",
      "cwe": "CWE-91",
      "title": "XML injection vulnerability in QDom comment, CDATA and processing-instruction serialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15037"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-65450",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RomanCode",
      "product": "MapSVG",
      "cwe": "CWE-89",
      "title": "WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65450"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-65451",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RomanCode",
      "product": "MapSVG",
      "cwe": "CWE-89",
      "title": "WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65451"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-65454",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ExpressTech Systems",
      "product": "Quiz And Survey Master",
      "cwe": "CWE-89",
      "title": "WordPress Quiz And Survey Master plugin <= 11.2.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65454"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-65526",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeisle",
      "product": "Visualizer",
      "cwe": "CWE-89",
      "title": "WordPress Visualizer plugin <= 4.0.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65526"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-28698",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00259,
      "epss_percentile": 0.17769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pronetiqs",
      "product": "Panduit Intravue",
      "cwe": "CWE-497",
      "title": "Exposure of Sensitive System Information to an Unauthorized Control Sphere in Panduit IntraVUE by Pronetiqs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28698"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-65491",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Jonathan Daggerhart",
      "product": "Query Wrangler",
      "cwe": "CWE-862",
      "title": "WordPress Query Wrangler plugin <= 1.5.57 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65491"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-12353",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17662,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Certificate System 9",
      "cwe": "CWE-772",
      "title": "Rhcs: memory leak during https connection leads to denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12353"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-16002",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MZ Automation",
      "product": "lib60870",
      "cwe": "CWE-125",
      "title": "Out-of-bounds Read in MZ Automation lib60870",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16002"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-65759",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00257,
      "epss_percentile": 0.17551,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "Easy Store extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65759"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-43823",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "swift-crypto",
      "cwe": "CWE-415",
      "title": "When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on future memory allocations. This double-free manifests when BoringSSL cannot decode the public key from the bytes provided. This vulnerability is addressed in swift-crypto version 4.5.1.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43823"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-65490",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mischiefmarmot",
      "product": "Create by Mediavine",
      "cwe": "CWE-497",
      "title": "WordPress Create by Mediavine plugin <= 2.5.3 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65490"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-16804",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Input in Google Chrome prior to 150.0.7871.186 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16804"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-65760",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00249,
      "epss_percentile": 0.16534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "Easy Store extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65760"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-13119",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "roundupwp",
      "product": "Registrations for the Events Calendar – Event Registration Plugin",
      "cwe": "CWE-89",
      "title": "Registrations for the Events Calendar <= 3.2 - Authenticated (Contributor+) SQL Injection via 'standard' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13119"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-15448",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tickera",
      "product": "Tickera – Sell Tickets & Manage Events",
      "cwe": "CWE-89",
      "title": "Tickera <= 3.6.0.1 - Authenticated (Staff+) SQL Injection via 'tc_order_status_filter' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15448"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-57703",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sunshinephotocart",
      "product": "Sunshine Photo Cart",
      "cwe": "CWE-862",
      "title": "WordPress Sunshine Photo Cart plugin <= 3.6.10.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57703"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-15630",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00246,
      "epss_percentile": 0.16195,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Casdoor",
      "product": "Casdoor",
      "cwe": "CWE-269",
      "title": "CVE-2026-15630",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15630"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-59547",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Easy Payment",
      "product": "Payment Gateway for PayPal on WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Payment Gateway for PayPal on WooCommerce plugin <= 9.1.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59547"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-61954",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PayU India",
      "product": "PayU India",
      "cwe": "CWE-862",
      "title": "WordPress PayU India plugin <= 3.8.9 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61954"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-65430",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "GeoIP extension for Joomla",
      "cwe": "CWE-200",
      "title": "Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65430"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-65755",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Articles Anywhere extension for Joomla",
      "cwe": "CWE-524",
      "title": "Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65755"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-15404",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "niklaslindemann",
      "product": "Bulk Page Generator – LPagery",
      "cwe": "CWE-79",
      "title": "Bulk Page Generator <= 2.5.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15404"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-15646",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "berocket",
      "product": "Brands for WooCommerce",
      "cwe": "CWE-79",
      "title": "Brands for WooCommerce <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'style' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15646"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-27423",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roland Barker",
      "product": "Participants Database",
      "cwe": "CWE-862",
      "title": "WordPress Participants Database plugin <= 2.7.8.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27423"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-61973",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WooLentor",
      "product": "ShopLentor Pro",
      "cwe": "CWE-862",
      "title": "WordPress ShopLentor Pro plugin <= 2.8.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61973"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-65457",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yoomoney",
      "product": "ЮKassa для WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress ЮKassa для WooCommerce plugin <= 2.16.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65457"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-57717",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "knitpay",
      "product": "Knit Pay",
      "cwe": "CWE-862",
      "title": "WordPress Knit Pay plugin <= 9.6.0.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57717"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-12082",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Praison AI SEO",
      "cwe": "CWE-862",
      "title": "Praison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12082"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-65474",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPManageNinja",
      "product": "Ninja Tables",
      "cwe": "CWE-497",
      "title": "WordPress Ninja Tables plugin <= 5.2.10 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65474"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-65498",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Complianz",
      "product": "Complianz",
      "cwe": "CWE-497",
      "title": "WordPress Complianz plugin <= 7.5.0 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65498"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-65505",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bdthemes",
      "product": "Ultimate Store Kit Elementor Addons",
      "cwe": "CWE-497",
      "title": "WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65505"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-65521",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mahmudul Hasan Arif",
      "product": "WP Social Ninja",
      "cwe": "CWE-497",
      "title": "WordPress WP Social Ninja plugin <= 4.3.0 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65521"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-65761",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00237,
      "epss_percentile": 0.14945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "Easy Store extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65761"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-57699",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bqworks",
      "product": "Slider Pro",
      "cwe": "CWE-79",
      "title": "WordPress Slider Pro plugin <= 4.8.13 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57699"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-59525",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00236,
      "epss_percentile": 0.14907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roland Barker",
      "product": "Participants Database",
      "cwe": "CWE-89",
      "title": "WordPress Participants Database plugin <= 2.7.8.3 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59525"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-59526",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00236,
      "epss_percentile": 0.14907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RomanCode",
      "product": "MapSVG",
      "cwe": "CWE-89",
      "title": "WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59526"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-16768",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "gdk-pixbuf",
      "cwe": "CWE-125",
      "title": "Gdk-pixbuf: out-of-bounds read in ico parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16768"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-57425",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdesk",
      "product": "Autopay dla WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Autopay dla WooCommerce plugin <= 2.2.27 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57425"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-61946",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14703,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Easy Appointments",
      "product": "Easy Appointments",
      "cwe": "CWE-639",
      "title": "WordPress Easy Appointments plugin <= 3.12.27 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61946"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-15687",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00235,
      "epss_percentile": 0.14671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kubernetes",
      "product": "kubernetes-client/java",
      "cwe": "CWE-22",
      "title": "Path traversal via non-tar copyDirectoryFromPod",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15687"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-65895",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-862",
      "title": "Grav API Plugin before 1.0.10 Broken Access Control",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65895"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-16764",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00233,
      "epss_percentile": 0.14476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OWASP",
      "product": "DefectDojo",
      "cwe": "CWE-266",
      "title": "OWASP DefectDojo API/Web serializers.py UserSerializer privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16764"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-40430",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pronetiqs",
      "product": "Panduit Intravue",
      "cwe": "CWE-256",
      "title": "Plaintext Storage of a Password in Panduit IntraVUE by Pronetiqs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40430"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-65899",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cure53",
      "product": "DOMPurify",
      "cwe": "CWE-693",
      "title": "DOMPurify before 3.4.9 Trusted Types Policy State Contamination",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65899"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-15614",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Logto",
      "product": "Logto",
      "cwe": "CWE-294",
      "title": "IdP-initiated SAML sessions not reliably invalidated (replay)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15614"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-59514",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00229,
      "epss_percentile": 0.14014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MightyNetworks vs BuddyBoss",
      "product": "Buddyboss Platform",
      "cwe": "CWE-89",
      "title": "WordPress Buddyboss Platform plugin <= 3.0.5 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59514"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-21653",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00229,
      "epss_percentile": 0.13973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "CCure 9000 and victor application server",
      "cwe": "CWE-918",
      "title": "CCure and Victor Application Server - Server Side Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21653"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-25466",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPGMaps",
      "product": "WP Go Maps",
      "cwe": "CWE-862",
      "title": "WordPress WP Go Maps plugin <= 10.1.04 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25466"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-65452",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.1378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "motov.net",
      "product": "Ebook Store",
      "cwe": "CWE-862",
      "title": "WordPress Ebook Store plugin <= 6.19 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65452"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-65485",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13775,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Daniel Iser",
      "product": "Content Control",
      "cwe": "CWE-862",
      "title": "WordPress Content Control plugin <= 2.6.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65485"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-65486",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bastien Ho",
      "product": "Event post",
      "cwe": "CWE-862",
      "title": "WordPress Event post plugin <= 6.0.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65486"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-65489",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LA-Studio",
      "product": "LA-Studio Element Kit for Elementor",
      "cwe": "CWE-862",
      "title": "WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65489"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-65501",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.1378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vendidero",
      "product": "Shiptastic for WooCommerce",
      "cwe": "CWE-639",
      "title": "WordPress Shiptastic for WooCommerce plugin <= 5.1.0 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65501"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-65532",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PersianScript",
      "product": "Persian Woocommerce SMS",
      "cwe": "CWE-89",
      "title": "WordPress Persian Woocommerce SMS plugin <= 7.2.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65532"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-64872",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Cache Cleaner Pro extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64872"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-65713",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Modals Pro extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65713"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-63226",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ricoh Company",
      "product": "Ricoh printers and Multifunction Printers (MFPs)",
      "cwe": "CWE-923",
      "title": "Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinations. When SSH is enabled on an affected product, SSH port forwarding may be leveraged to connect to other node on the LAN.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63226"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-65530",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Templatespare",
      "product": "TemplateSpare",
      "cwe": "CWE-862",
      "title": "WordPress TemplateSpare plugin <= 4.2.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65530"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-65699",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00222,
      "epss_percentile": 0.13017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "reworkd",
      "product": "AgentGPT",
      "cwe": "CWE-639",
      "title": "AgentGPT 1.0.0 Authorization Bypass via Agent Task Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65699"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-7120",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12917,
      "kev": false,
      "kev_due_at": null,
      "vendor": "@fastify/static",
      "product": "@fastify/static",
      "cwe": "CWE-180",
      "title": "@fastify/static vulnerable to Authorization Bypass via Non-Canonical URL Paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7120"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-65478",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12855,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CridioStudio",
      "product": "ListingPro",
      "cwe": "CWE-862",
      "title": "WordPress ListingPro plugin <= 2.9.10 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65478"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-65458",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chouby",
      "product": "Polylang",
      "cwe": "CWE-497",
      "title": "WordPress Polylang and Polylang Pro plugins <= 3.8.5 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65458"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-64875",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.1213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "GeoIP extension for Joomla",
      "cwe": "CWE-290",
      "title": "Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64875"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-27399",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.1206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebWizards",
      "product": "MarketKing",
      "cwe": "CWE-862",
      "title": "WordPress MarketKing plugin <= 2.1.40 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27399"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-27418",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Epsiloncool",
      "product": "WP Fast Total Search",
      "cwe": "CWE-862",
      "title": "WordPress WP Fast Total Search plugin <= 1.81.282 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27418"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-27422",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.1206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bPlugins",
      "product": "YT Player",
      "cwe": "CWE-862",
      "title": "WordPress YT Player plugin <= 2.0.9 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27422"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-61972",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WooLentor",
      "product": "ShopLentor Pro",
      "cwe": "CWE-862",
      "title": "WordPress ShopLentor Pro plugin <= 2.8.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61972"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-65453",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "motov.net",
      "product": "Ebook Store",
      "cwe": "CWE-862",
      "title": "WordPress Ebook Store plugin <= 6.19 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65453"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-65468",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetBooking",
      "cwe": "CWE-862",
      "title": "WordPress JetBooking plugin <= 4.1.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65468"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-65469",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Strategy11 Team",
      "product": "AWP Classifieds",
      "cwe": "CWE-862",
      "title": "WordPress AWP Classifieds plugin <= 4.4.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65469"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-65472",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kit",
      "product": "Kit (formerly ConvertKit)",
      "cwe": "CWE-862",
      "title": "WordPress Kit (formerly ConvertKit) plugin <= 3.3.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65472"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-65476",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uxper",
      "product": "Civi",
      "cwe": "CWE-862",
      "title": "WordPress Civi theme <= 2.2.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65476"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-65487",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeGoods",
      "product": "Photography",
      "cwe": "CWE-862",
      "title": "WordPress Photography theme <= 7.7.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65487"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-65506",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sonaar",
      "product": "MP3 Audio Player for Music, Radio & Podcast by Sonaar",
      "cwe": "CWE-862",
      "title": "WordPress MP3 Audio Player for Music, Radio & Podcast by Sonaar plugin <= 5.12 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65506"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-48013",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.11969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shopware",
      "product": "shopware",
      "cwe": "CWE-918",
      "title": "Shopware: SSRF in Media External-Link Endpoint Bypasses IP Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48013"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-61945",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MultiVendorX",
      "product": "WooCommerce Product Stock Alert",
      "cwe": "CWE-497",
      "title": "WordPress WooCommerce Product Stock Alert plugin <= 3.0.6 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61945"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-8287",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BizimHesap Information Systems Industry and Trade Inc.",
      "product": "Online Pre-Accounting Software",
      "cwe": "CWE-770",
      "title": "Unrestricted File Upload in BizimHesap Information Systems' Online Pre-Accounting Software",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8287"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-24552",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "John-Michael L'Allier",
      "product": "Create",
      "cwe": "CWE-89",
      "title": "WordPress Create plugin <= 2.5.3 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24552"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-25405",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00211,
      "epss_percentile": 0.11675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DigitalME",
      "product": "eRoom",
      "cwe": "CWE-89",
      "title": "WordPress eRoom plugin <= 1.7.1 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25405"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-59513",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "masteriyo",
      "product": "Masteriyo - LMS",
      "cwe": "CWE-79",
      "title": "WordPress Masteriyo - LMS plugin <= 2.3.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59513"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-65902",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cure53",
      "product": "DOMPurify",
      "cwe": "CWE-501",
      "title": "DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65902"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-65537",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeisle",
      "product": "Cyr to Lat reloaded – transliteration of links and file names",
      "cwe": "CWE-862",
      "title": "WordPress Cyr to Lat reloaded – transliteration of links and file names plugin <= 1.3.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65537"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-7232",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.11042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FormCraft",
      "product": "FormCraft",
      "cwe": "CWE-79",
      "title": "FormCraft <= 3.9.14 - Unauthenticated Stored Cross-Site Scripting via Matrix Field Sub-Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7232"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-44955",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.11019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pronetiqs",
      "product": "Panduit Intravue",
      "cwe": "CWE-497",
      "title": "Exposure of Sensitive System Information to an Unauthorized Control Sphere in Panduit IntraVUE by Pronetiqs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44955"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-34496",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00205,
      "epss_percentile": 0.1079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "victor Web",
      "cwe": "CWE-269",
      "title": "victor Web - Priviledge Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34496"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-57384",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Membership Software",
      "product": "WishList Member X",
      "cwe": "CWE-79",
      "title": "WordPress WishList Member X plugin <= 3.32.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57384"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-15966",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00204,
      "epss_percentile": 0.10716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress",
      "product": "MOVEit Transfer",
      "cwe": "CWE-942",
      "title": "Improper CORS handling in MOVEit Transfer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15966"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-15967",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00204,
      "epss_percentile": 0.10716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress",
      "product": "MOVEit Transfer",
      "cwe": "CWE-613",
      "title": "MOVEit Transfer refresh-token processing does not enforce updated account restrictions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15967"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-65903",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cure53",
      "product": "DOMPurify",
      "cwe": "CWE-697",
      "title": "DOMPurify before 3.4.0 ADD_TAGS Function Bypasses FORBID_TAGS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65903"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-65484",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AnalogWP",
      "product": "Style Kits",
      "cwe": "CWE-862",
      "title": "WordPress Style Kits plugin <= 2.6.5 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65484"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-21723",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.10013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana OSS",
      "cwe": "CWE-400",
      "title": "CVE-2026-21723 Record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21723"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-65703",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00197,
      "epss_percentile": 0.09838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-787",
      "title": "FFmpeg 2.7 - 8.1.2 Out-of-Bounds Write in TDSC Video Decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65703"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-65758",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00197,
      "epss_percentile": 0.09767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tassos.gr",
      "product": "Convert Forms extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65758"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-65456",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PickPlugins",
      "product": "Product Slider for WooCommerce",
      "cwe": "CWE-639",
      "title": "WordPress Product Slider for WooCommerce plugin <= 1.13.62 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65456"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-65529",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.0962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Iqonic Design",
      "product": "Graphina",
      "cwe": "CWE-862",
      "title": "WordPress Graphina plugin <= 3.1.12 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65529"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-15647",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "berocket",
      "product": "Brands for WooCommerce",
      "cwe": "CWE-79",
      "title": "Brands for WooCommerce <= 3.8.8 - Authenticated (Shop Manager+) Stored Cross-Site Scripting via 'br_brand_tooltip' Term Meta Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15647"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-65516",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.09455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepro Dev. Group",
      "product": "PeproDev Ultimate Invoice",
      "cwe": "CWE-918",
      "title": "WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65516"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-65499",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepro Dev. Group",
      "product": "PeproDev Ultimate Invoice",
      "cwe": "CWE-862",
      "title": "WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65499"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-9729",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webpushr",
      "product": "Web Push Notifications – Webpushr",
      "cwe": "CWE-79",
      "title": "Web Push Notifications <= 4.39.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'webpushr_notification_title' Post Meta Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9729"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-15394",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mahethekiller",
      "product": "Header Footer Script Adder",
      "cwe": "CWE-79",
      "title": "Header Footer Script Adder <= 2.1 - Authenticated (Author+) Stored Cross-Site Scripting via 'asm_code' Snippet Meta",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15394"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-15794",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "berocket",
      "product": "Grid/List View for WooCommerce",
      "cwe": "CWE-79",
      "title": "Grid/List View for WooCommerce <= 3.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'position' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15794"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-59512",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.09144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PI Web Solution",
      "product": "Product Enquiry for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Product Enquiry for WooCommerce plugin <= 2.2.34.43 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59512"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-65911",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00191,
      "epss_percentile": 0.09076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cure53",
      "product": "DOMPurify",
      "cwe": "CWE-79",
      "title": "DOMPurify before 3.4.0 XSS via ADD_ATTR/ADD_TAGS State Leakage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65911"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-7534",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.09025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FantasticPlugins",
      "product": "SUMO Reward Points for WooCommerce",
      "cwe": "CWE-79",
      "title": "SUMO Reward Points for WooCommerce <= 32.7.0 - Unauthenticated Stored Cross-Site Scripting via 'reason' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7534"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-12421",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.09025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "ARforms",
      "cwe": "CWE-79",
      "title": "ARforms <= 7.2.1 - Unauthenticated Stored Cross-Site Scripting via 'password' Field Values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12421"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-9635",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mythemeshop",
      "product": "WP Shortcode by MyThemeShop",
      "cwe": "CWE-79",
      "title": "WP Shortcode by MyThemeShop <= 1.4.17 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'title' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9635"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-61944",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bookly",
      "product": "Bookly",
      "cwe": "CWE-79",
      "title": "WordPress Bookly plugin <= 27.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61944"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-38764",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00185,
      "epss_percentile": 0.0845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-269",
      "title": "An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38764"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-65913",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cure53",
      "product": "DOMPurify",
      "cwe": "CWE-1321",
      "title": "DOMPurify before 3.3.2 Prototype Pollution via USE_PROFILES",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65913"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-25424",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mediavine",
      "product": "Mediavine Control Panel",
      "cwe": "CWE-862",
      "title": "WordPress Mediavine Control Panel plugin <= 2.10.10 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25424"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-27392",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08431,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Stylemix",
      "product": "uListing",
      "cwe": "CWE-862",
      "title": "WordPress uListing plugin <= 2.2.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27392"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-65535",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00184,
      "epss_percentile": 0.08331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Takayuki Miyauchi",
      "product": "TinyMCE Templates",
      "cwe": "CWE-497",
      "title": "WordPress TinyMCE Templates plugin <= 4.8.1 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65535"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-15612",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00182,
      "epss_percentile": 0.08106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Logto",
      "product": "Logto",
      "cwe": "CWE-345",
      "title": "LOIDC nonce validation bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15612"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-15615",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.0816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Logto",
      "product": "Logto",
      "cwe": "CWE-345",
      "title": "SAML <Conditions> element not validated",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15615"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-15968",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.08003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress",
      "product": "MOVEit Transfer",
      "cwe": "CWE-79",
      "title": "Stored XSS vulnerability in MOVEit Transfer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15968"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-64785",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "swift-nio-http2",
      "cwe": "CWE-444",
      "title": "SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend through NIOHTTP2's HTTP/2-to-HTTP/1 codec, enabling HTTP request smuggling or response splitting. This vulnerability is addressed in swift-nio-http2 version 1.45.0.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64785"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-57370",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07847,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CODEPRESS IT Solutions LLC",
      "product": "Visitor Traffic Real Time Statistics Pro",
      "cwe": "CWE-79",
      "title": "WordPress Visitor Traffic Real Time Statistics Pro plugin <= 11.9.1 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57370"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-57701",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebCodingPlace",
      "product": "Real Estate Manager Pro",
      "cwe": "CWE-79",
      "title": "WordPress Real Estate Manager Pro plugin <= 12.8.5 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57701"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-57704",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StoreApps",
      "product": "Smart Manager",
      "cwe": "CWE-79",
      "title": "WordPress Smart Manager plugin <= 8.90.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57704"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-57769",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07855,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeGoods",
      "product": "Grand Photography",
      "cwe": "CWE-79",
      "title": "WordPress Grand Photography theme <= 5.7.8 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57769"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-57809",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AffiliateWP",
      "product": "AffiliateWP",
      "cwe": "CWE-79",
      "title": "WordPress AffiliateWP plugin <= 2.34.0 - Reflected Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57809"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-59517",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hassantafreshi",
      "product": "Easy Form Builder",
      "cwe": "CWE-79",
      "title": "WordPress Easy Form Builder plugin <= 4.0.12 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59517"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-65492",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dokan WordPress Plugin",
      "product": "Dokan Pro",
      "cwe": "CWE-79",
      "title": "WordPress Dokan Pro plugin <= 5.0.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65492"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-65510",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.0785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pepro Dev. Group",
      "product": "PeproDev Ultimate Invoice",
      "cwe": "CWE-79",
      "title": "WordPress PeproDev Ultimate Invoice plugin <= 2.2.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65510"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-65511",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pixelacehq",
      "product": "Manual - Documentation, Knowledge Base & Education WordPress Theme",
      "cwe": "CWE-79",
      "title": "WordPress Manual - Documentation, Knowledge Base & Education WordPress Theme theme <= 7.5.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65511"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-65900",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cure53",
      "product": "DOMPurify",
      "cwe": "CWE-79",
      "title": "DOMPurify before 3.4.8 Template Expression Injection via RETURN_DOM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65900"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-65525",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uxper",
      "product": "Civi Framework",
      "cwe": "CWE-862",
      "title": "WordPress Civi Framework plugin <= 2.2.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65525"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-57374",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wisetr INC.",
      "product": "Funnel Kit Funnel Builder PRO",
      "cwe": "CWE-79",
      "title": "WordPress Funnel Kit Funnel Builder PRO plugin <= 3.15.0.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57374"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-57397",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThimPress.",
      "product": "Coaching",
      "cwe": "CWE-79",
      "title": "WordPress Coaching theme <= 3.9.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57397"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-57427",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Download Monitor",
      "product": "Download Monitor - WPForms Lock",
      "cwe": "CWE-79",
      "title": "WordPress Download Monitor - WPForms Lock plugin <= 1.0.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57427"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-57428",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BoldGrid",
      "product": "Sprout Clients",
      "cwe": "CWE-79",
      "title": "WordPress Sprout Clients plugin <= 3.2.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57428"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-57735",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Soflyy",
      "product": "Breakdance",
      "cwe": "CWE-79",
      "title": "WordPress Breakdance plugin <= 2.7.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57735"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-57767",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodeCabin.io",
      "product": "WP Google Maps Pro",
      "cwe": "CWE-79",
      "title": "WordPress WP Google Maps Pro plugin <= 10.1.02 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57767"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-61947",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPVibes",
      "product": "Form Vibes – Database Manager for Forms",
      "cwe": "CWE-79",
      "title": "WordPress Form Vibes – Database Manager for Forms plugin <= 1.5.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61947"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-65912",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cure53",
      "product": "DOMPurify",
      "cwe": "CWE-79",
      "title": "DOMPurify before 3.3.2 URI Validation Bypass via ADD_ATTR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65912"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-60122",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.07205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gpsd",
      "product": "gpsd",
      "cwe": "CWE-94",
      "title": "gpsd gpsprof Code Injection via SKY.satellites used Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60122"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2025-68081",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lester Chan",
      "product": "WP-Polls",
      "cwe": "CWE-79",
      "title": "WordPress WP-Polls plugin <= 2.77.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68081"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-24628",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Supsystic",
      "product": "Photo Gallery by Supsystic",
      "cwe": "CWE-79",
      "title": "WordPress Photo Gallery by Supsystic plugin <= 1.16.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24628"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-65483",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hashthemes",
      "product": "HashThemes Demo Importer",
      "cwe": "CWE-79",
      "title": "WordPress HashThemes Demo Importer plugin <= 1.4.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65483"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-65473",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "Virtue/Ascend/Pinnacle Toolkit",
      "cwe": "CWE-79",
      "title": "WordPress Virtue/Ascend/Pinnacle Toolkit plugin <= 4.9.12 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65473"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-65898",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cure53",
      "product": "DOMPurify",
      "cwe": "CWE-79",
      "title": "DOMPurify before 3.4.11 Permanent Attribute Allowlist Pollution via setConfig",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65898"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-65914",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cure53",
      "product": "DOMPurify",
      "cwe": "CWE-79",
      "title": "DOMPurify before 3.3.2 Mutation XSS via Re-Contextualization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65914"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-65901",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cure53",
      "product": "DOMPurify",
      "cwe": "CWE-79",
      "title": "DOMPurify 3.4.6 Cross-Site Scripting via IN_PLACE nodeName",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65901"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-21655",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Control",
      "product": "victor",
      "cwe": "CWE-502",
      "title": "C-CURE 9000 and Victor application server - Deserialization of Untrusted Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21655"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-50103",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MZ Automation",
      "product": "libIEC61850",
      "cwe": "CWE-228",
      "title": "Improper Handling of Syntactically Invalid Structure in MZ Automation libIEC61850",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50103"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-65904",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00165,
      "epss_percentile": 0.06207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cure53",
      "product": "DOMPurify",
      "cwe": "CWE-754",
      "title": "DOMPurify through 3.3.3 Cross-Site Scripting via IN_PLACE mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65904"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-65696",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sct",
      "product": "overseerr",
      "cwe": "CWE-639",
      "title": "Overseerr 1.35.0 Authorization Bypass via pushSubscriptions API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65696"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-48012",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.0589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shopware",
      "product": "shopware",
      "cwe": "CWE-601",
      "title": "Shopware SSO referer trust leading to an arbitrary redirect target",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48012"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-65524",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeFusion",
      "product": "Avada Custom Branding",
      "cwe": "CWE-862",
      "title": "WordPress Avada Custom Branding plugin <= 1.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65524"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-27403",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05778,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NerdPress",
      "product": "Hubbub Lite",
      "cwe": "CWE-79",
      "title": "WordPress Hubbub Lite plugin <= 1.36.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-27403"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-65449",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.0577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RomanCode",
      "product": "MapSVG",
      "cwe": "CWE-79",
      "title": "WordPress MapSVG plugin <= 8.14.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65449"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-65465",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetElements For Elementor",
      "cwe": "CWE-79",
      "title": "WordPress JetElements For Elementor plugin <= 2.9.1.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65465"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-65470",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05773,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPManageNinja",
      "product": "Fluent Support",
      "cwe": "CWE-79",
      "title": "WordPress Fluent Support plugin <= 2.3.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65470"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-65480",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CodexThemes",
      "product": "TheGem",
      "cwe": "CWE-79",
      "title": "WordPress TheGem theme < 5.12.1.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65480"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-65482",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.0577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LA-Studio",
      "product": "LA-Studio Element Kit for Elementor",
      "cwe": "CWE-79",
      "title": "WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65482"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-65503",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bdthemes",
      "product": "Ultimate Store Kit Elementor Addons",
      "cwe": "CWE-79",
      "title": "WordPress Ultimate Store Kit Elementor Addons plugin <= 3.0.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65503"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-65514",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codepeople",
      "product": "Appointment Hour Booking",
      "cwe": "CWE-79",
      "title": "WordPress Appointment Hour Booking plugin <= 1.5.86 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65514"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-65518",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Scott Paterson",
      "product": "Accept Donations with PayPal & Stripe",
      "cwe": "CWE-79",
      "title": "WordPress Accept Donations with PayPal & Stripe plugin <= 1.5.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65518"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-65519",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gt3themes",
      "product": "Photo Gallery",
      "cwe": "CWE-79",
      "title": "WordPress Photo Gallery plugin <= 2.7.7.29 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65519"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-65522",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pixelacehq",
      "product": "Manual - Documentation, Knowledge Base & Education WordPress Theme",
      "cwe": "CWE-79",
      "title": "WordPress Manual - Documentation, Knowledge Base & Education WordPress theme theme <= 7.5.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65522"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-24639",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ronald Huereca",
      "product": "Photo Block",
      "cwe": "CWE-918",
      "title": "WordPress Photo Block plugin <= 1.7.1 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24639"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-65496",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Complianz",
      "product": "Complianz",
      "cwe": "CWE-918",
      "title": "WordPress Complianz plugin <= 7.5.0 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65496"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-65697",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.0574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "usefathom",
      "product": "fathom",
      "cwe": "CWE-79",
      "title": "Fathom Lite 1.3.1 Stored XSS via /collect Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65697"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-16584",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.05515,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "aws-api-mcp-server",
      "cwe": "CWE-455",
      "title": "AWS API MCP Server Security Policy Bypass via Startup Failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16584"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-15212",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.05405,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpo365",
      "product": "WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)",
      "cwe": "CWE-352",
      "title": "WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 43.2 - Cross-Site Request Forgery to Privilege Escalation via Plugin Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15212"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-57373",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wisetr INC.",
      "product": "Funnel Kit Funnel Builder PRO",
      "cwe": "CWE-79",
      "title": "WordPress Funnel Kit Funnel Builder PRO plugin <= 3.15.0.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57373"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-65466",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetBooking",
      "cwe": "CWE-918",
      "title": "WordPress JetBooking plugin <= 4.1.2 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65466"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-39155",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.04708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-345",
      "title": "Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability in mod-onlinesign where the next NSEC owner name can be computed incorrectly. This can create an overly broad authenticated denial interval, allowing downstream validating resolvers using aggressive negative caching to synthesize negative answers for legitimate names and causing resolver-side denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39155"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-11804",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.04739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tridium",
      "product": "Niagara Framework",
      "cwe": "CWE-280",
      "title": "Program Module Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11804"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-9066",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Compress",
      "cwe": "CWE-79",
      "title": "WP Compress < 7.10.04 - Reflected XSS via test_zone",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9066"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-64810",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-79",
      "title": "In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activity tracking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64810"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-65756",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Keyboard Shortcuts extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65756"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-65534",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04573,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Charlie Etienne",
      "product": "Custom links in Elementor Image Carousel",
      "cwe": "CWE-79",
      "title": "WordPress Custom links in Elementor Image Carousel plugin <= 1.1.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65534"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-65538",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nilo Velez",
      "product": "Machete",
      "cwe": "CWE-79",
      "title": "WordPress Machete plugin <= 5.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65538"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-65550",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpshopmart",
      "product": "Tabs",
      "cwe": "CWE-79",
      "title": "WordPress Tabs plugin <= 2.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65550"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-65712",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.0429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "CDN for Joomla Pro extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65712"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-65467",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Crocoblock. Jetimpex Inc.",
      "product": "JetEngine",
      "cwe": "CWE-918",
      "title": "WordPress JetEngine plugin <= 3.8.11 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65467"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-65531",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeum",
      "product": "Qubely",
      "cwe": "CWE-862",
      "title": "WordPress Qubely plugin <= 1.8.14 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65531"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-65471",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00143,
      "epss_percentile": 0.0407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Avada Studio",
      "product": "Avada Core",
      "cwe": "CWE-352",
      "title": "WordPress Avada Core plugin <= 5.15.6 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65471"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-64802",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00143,
      "epss_percentile": 0.04121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "GoLand",
      "cwe": "CWE-94",
      "title": "In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust in the Go Modules integration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64802"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-64803",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00143,
      "epss_percentile": 0.04121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "GoLand",
      "cwe": "CWE-94",
      "title": "In JetBrains GoLand before 2026.2 arbitrary code execution was possible before granting project trust via the configured Go SDK",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64803"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-52684",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00143,
      "epss_percentile": 0.04089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "Recursor",
      "cwe": null,
      "title": "Prefetch Feature Allows Persistent Ghost Domain Cache Poisoning Attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52684"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-57785",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.04038,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ApusTheme",
      "product": "ApusListing",
      "cwe": "CWE-352",
      "title": "WordPress ApusListing theme <= 1.2.63 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57785"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-9577",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.04035,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Post Status Notifier Lite",
      "cwe": "CWE-79",
      "title": "Post Status Notifier Lite < 1.13.0 - Reflected XSS via mod Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9577"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-64804",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.03825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "WebStorm",
      "cwe": "CWE-829",
      "title": "In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local linter tooling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64804"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-64805",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.03824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "WebStorm",
      "cwe": "CWE-829",
      "title": "In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via project-local package-manager tooling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64805"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-64806",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.03824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "WebStorm",
      "cwe": "CWE-829",
      "title": "In JetBrains WebStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured Node.js interpreter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64806"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-64808",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.03824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "PhpStorm",
      "cwe": "CWE-829",
      "title": "In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via project tooling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64808"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-64809",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.03825,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "PhpStorm",
      "cwe": "CWE-829",
      "title": "In JetBrains PhpStorm before 2026.2 arbitrary code execution was possible before granting project trust via the configured interpreter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64809"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-65528",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.03719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bannersky",
      "product": "BSK PDF Manager",
      "cwe": "CWE-79",
      "title": "WordPress BSK PDF Manager plugin <= 3.8 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65528"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-65533",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00139,
      "epss_percentile": 0.0372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wbolt.com",
      "product": "Smart SEO Tool",
      "cwe": "CWE-79",
      "title": "WordPress Smart SEO Tool plugin <= 4.1.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65533"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-48530",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GFI Software",
      "product": "GFI Archiver",
      "cwe": "CWE-79",
      "title": "GFI Archiver < 15.13 Stored XSS via CategorizationPolicyWizard.aspx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48530"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-48531",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.0368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GFI Software",
      "product": "GFI Archiver",
      "cwe": "CWE-79",
      "title": "GFI Archiver < 15.13 Stored XSS via RetentionPolicyWizard.aspx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48531"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-48532",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GFI Software",
      "product": "GFI Archiver",
      "cwe": "CWE-79",
      "title": "GFI Archiver < 15.13 Stored XSS via FAARetentionPolicyWizard.aspx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48532"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-48534",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GFI Software",
      "product": "GFI Archiver",
      "cwe": "CWE-79",
      "title": "GFI Archiver < 15.13 Stored XSS via ImapServerWizard.aspx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48534"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-48535",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03674,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GFI Software",
      "product": "GFI Archiver",
      "cwe": "CWE-79",
      "title": "GFI Archiver < 15.13 Stored XSS via CallHomeSettingsWizard.aspx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48535"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-48536",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GFI Software",
      "product": "GFI Archiver",
      "cwe": "CWE-79",
      "title": "GFI Archiver < 15.13 Stored XSS via GeneralSettingsWizard.aspx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48536"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-48537",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.0368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GFI Software",
      "product": "GFI Archiver",
      "cwe": "CWE-79",
      "title": "GFI Archiver < 15.13 Stored XSS via FileArchiveAssistantWizard.aspx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48537"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-48538",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GFI Software",
      "product": "GFI Archiver",
      "cwe": "CWE-79",
      "title": "GFI Archiver < 15.13 Stored XSS via ImportSettingsWizard.ashx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48538"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-48539",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.0368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GFI Software",
      "product": "GFI Archiver",
      "cwe": "CWE-79",
      "title": "GFI Archiver < 15.13 Stored XSS via MailInsights.aspx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48539"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-65010",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "huggingface",
      "product": "datasets",
      "cwe": "CWE-61",
      "title": "Datasets Symlink-following Arbitrary File Write via Extractor.extract()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65010"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-57784",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0013,
      "epss_percentile": 0.0311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ninja Forms",
      "product": "Ninja Forms File Uploads Extension",
      "cwe": "CWE-352",
      "title": "WordPress Ninja Forms File Uploads Extension plugin <= 3.3.26 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57784"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-65757",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.03111,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Modules Anywhere extension for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65757"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-65475",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Chill",
      "product": "Modula Image Gallery",
      "cwe": "CWE-79",
      "title": "WordPress Modula Image Gallery plugin 2.14.25-2.14.30 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65475"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-65527",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lqd",
      "product": "LIQUID SPEECH BALLOON",
      "cwe": "CWE-79",
      "title": "WordPress LIQUID SPEECH BALLOON plugin <= 1.2.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65527"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-64876",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "GeoIP extension for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64876"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-65706",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-131",
      "title": "FFmpeg 3.0 - 8.1.2 vf_swaprect Out-of-Bounds Write via NV12 Frame Processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65706"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-52688",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "Recursor",
      "cwe": "CWE-295",
      "title": "RRSIGs with too few labels can lead to bypass of DNSSEC wildcard validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52688"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-65705",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-131",
      "title": "FFmpeg 3.4 - 8.1.2 vf_floodfill Out-of-Bounds Write via filter_frame()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65705"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-65908",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "PyCharm",
      "cwe": "CWE-829",
      "title": "In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on untrusted project open",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65908"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-64807",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02693,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "WebStorm",
      "cwe": "CWE-829",
      "title": "In JetBrains WebStorm before 2026.2 arbitrary code execution was possible via a project-supplied linter configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64807"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-64811",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "JetBrains",
      "product": "IntelliJ IDEA",
      "cwe": "CWE-829",
      "title": "In JetBrains IntelliJ IDEA before 2026.2 arbitrary code execution was possible before granting project trust via development container configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64811"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-65536",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mahdi Yousefi",
      "product": "افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری)",
      "cwe": "CWE-352",
      "title": "WordPress افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) plugin <= 4.4.5 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65536"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-65704",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-191",
      "title": "FFmpeg 8.1.2 Out-of-Bounds Write via TY Demuxer and Shorten Decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65704"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-59678",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux-Gaming",
      "product": "PortProtonQt",
      "cwe": "CWE-863",
      "title": "portprotonqt allows any users to mount and unmount arbitrary file systems and modify the network configuration via NetworkManager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59678"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-52686",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00113,
      "epss_percentile": 0.01645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PowerDNS",
      "product": "Recursor",
      "cwe": "CWE-347",
      "title": "Wildcard CNAME proof validation bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52686"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-65512",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.0138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Melapress",
      "product": "WP Activity Log",
      "cwe": "CWE-352",
      "title": "WordPress WP Activity Log and WP Activity Log Premium plugins <= 5.6.4 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65512"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-6390",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-134",
      "title": "Nano: gnu nano: arbitrary memory writes, information disclosure, or denial of service via format string vulnerability in error handling.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6390"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-59677",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SELinuxProject",
      "product": "selinux",
      "cwe": "CWE-862",
      "title": "Process Kill Attack Vector in killall() in seunshare",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59677"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-24537",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01314,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Alex Volkov",
      "product": "WP Accessibility Helper (WAH)",
      "cwe": "CWE-352",
      "title": "WordPress WP Accessibility Helper (WAH) plugin <= 0.6.6 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24537"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-65460",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01315,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zarinpal",
      "product": "Zarinpal Gateway",
      "cwe": "CWE-352",
      "title": "WordPress Zarinpal Gateway plugin <= 5.1.0 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65460"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-61981",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.01173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuantumCloud",
      "product": "Simple Link Directory Pro",
      "cwe": "CWE-352",
      "title": "WordPress Simple Link Directory Pro plugin <= 15.0.8 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61981"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-65464",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.01174,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "GiveWP",
      "cwe": "CWE-352",
      "title": "WordPress GiveWP plugin <= 4.16.3 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65464"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-65488",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00097,
      "epss_percentile": 0.00857,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LA-Studio",
      "product": "LA-Studio Element Kit for Elementor",
      "cwe": "CWE-352",
      "title": "WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Cross Site Request Forgery (CSRF) to Stored XSS vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65488"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-65539",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00094,
      "epss_percentile": 0.00716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bimal Rekhadiya",
      "product": "Kwayy HTML Sitemap",
      "cwe": "CWE-352",
      "title": "WordPress Kwayy HTML Sitemap plugin <= 4.0 - CSRF to Stored XSS vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65539"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-65540",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00094,
      "epss_percentile": 0.00716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Metin Saraç",
      "product": "Popup for CF7 with Sweet Alert",
      "cwe": "CWE-352",
      "title": "WordPress Popup for CF7 with Sweet Alert plugin <= 1.6.5 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65540"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-64871",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "regularlabs.com",
      "product": "Cache Cleaner extension for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64871"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-57626",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00089,
      "epss_percentile": 0.00479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MailPoet",
      "product": "MailPoet",
      "cwe": "CWE-352",
      "title": "WordPress MailPoet plugin 5.30.0-5.33.0 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57626"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-59676",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00087,
      "epss_percentile": 0.00421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SELinuxProject",
      "product": "selinux",
      "cwe": "CWE-367",
      "title": "Local File Deletion Attack Vector in rm_rf() in seunshare",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59676"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-50044",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00084,
      "epss_percentile": 0.00341,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pronetiqs",
      "product": "Panduit Intravue",
      "cwe": "CWE-326",
      "title": "Inadequate Encryption Strength in Panduit IntraVUE by Pronetiqs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50044"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2024-58023",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00079,
      "epss_percentile": 0.00182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bosch",
      "product": "Bosch Configuration Manager",
      "cwe": "CWE-312",
      "title": "Information disclosure in Bosch Configuration Manager in Version 7.72.0106 allows an attacker to access sensitive information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-58023"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-43820",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00078,
      "epss_percentile": 0.00158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "swift-nio-ssl",
      "cwe": "CWE-125",
      "title": "NIOSSLCertificate._subjectAlternativeNames provides access to the raw bytes for a cert's SANs. NIOSSL provides access to a buffer assumed to be backed by an ASN1_STRING, but not all SANs are backed by ASN1_STRING, so accessing the buffer for such a type can lead to out-of-bounds memory access. This vulnerability is addressed in swift-nio-ssl version 2.37.2.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43820"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16489",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16489 (jsforce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16628",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16628 (oclif). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16630",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16630 (syncfusion ej2-javascript-ui-controls). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-20253",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-20253 (Splunk Enterprise). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-26740",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-26740. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-34908",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-34908 (Ubiquiti UniFi OS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-34909",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-34909 (Ubiquiti UniFi OS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-34910",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-34910 (Ubiquiti UniFi OS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-42999",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-42999 (OpenStack Keystone). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43000",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43000 (OpenStack Keystone). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44210",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44210 (kata-containers). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44891",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44891 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55831",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55831 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56292",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56292 (acymailing.com AcyMailing extension for Joomla). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57827",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57827 (rsjoomla.com RSFiles extension for Joomla). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-57828",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-57828 (phoca.cz Phoca Download extension for Joomla). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-64600",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-64600 (Linux). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65012",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65012 (invoke-ai InvokeAI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65013",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65013 (onlook repo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65898",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65898 (cure53 DOMPurify). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65899",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65899 (cure53 DOMPurify). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65900",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65900 (cure53 DOMPurify). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65901",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65901 (cure53 DOMPurify). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65902",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65902 (cure53 DOMPurify). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65903",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65903 (cure53 DOMPurify). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65904",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65904 (cure53 DOMPurify). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65911",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65911 (cure53 DOMPurify). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65914",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65914 (cure53 DOMPurify). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-10732",
      "detail": "RESCORED — CVE-2026-10732 (decompress). CVSS 6.1 → 5.6 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-13448",
      "detail": "RESCORED — CVE-2026-13448 (IBM Langflow OSS). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16631",
      "detail": "RESCORED — CVE-2026-16631 (publint). CVSS 4.8 → 1.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-16632",
      "detail": "RESCORED — CVE-2026-16632 (boazsegev facil.io). CVSS 6.9 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-42010",
      "detail": "RESCORED — CVE-2026-42010 (Red Hat Enterprise Linux 10). CVSS 7.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-42975",
      "detail": "RESCORED — CVE-2026-42975 (Microsoft Windows 10 Version 1607). CVSS 8 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-42999",
      "detail": "RESCORED — CVE-2026-42999 (OpenStack Keystone). CVSS 6 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-43000",
      "detail": "RESCORED — CVE-2026-43000 (OpenStack Keystone). CVSS 6 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-44930",
      "detail": "RESCORED — CVE-2026-44930 (Apache Software Foundation Apache CXF). CVSS 4.3 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50317",
      "detail": "RESCORED — CVE-2026-50317 (Microsoft Windows 11 Version 24H2). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50406",
      "detail": "RESCORED — CVE-2026-50406 (Microsoft Windows 10 Version 21H2). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50440",
      "detail": "RESCORED — CVE-2026-50440 (Microsoft Windows 11 Version 24H2). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50491",
      "detail": "RESCORED — CVE-2026-50491 (Microsoft Windows 10 Version 1607). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-54989",
      "detail": "RESCORED — CVE-2026-54989 (Microsoft Windows 10 Version 1607). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-56187",
      "detail": "RESCORED — CVE-2026-56187 (Microsoft Windows 11 Version 24H2). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-57089",
      "detail": "RESCORED — CVE-2026-57089 (Microsoft Windows 10 Version 1607). CVSS 7.5 → 9.8 (NVD)."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-10520",
      "detail": "ENRICHED — CVE-2026-10520 (Ivanti Sentry). Received CVSS 10.0 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-11645",
      "detail": "ENRICHED — CVE-2026-11645 (Google Chromium V8). Received CVSS 8.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-20253",
      "detail": "ENRICHED — CVE-2026-20253 (Splunk Enterprise). Received CVSS 9.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-25089",
      "detail": "ENRICHED — CVE-2026-25089 (Fortinet FortiSandbox). Received CVSS 9.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-34908",
      "detail": "ENRICHED — CVE-2026-34908 (Ubiquiti UniFi OS). Received CVSS 10.0 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-34909",
      "detail": "ENRICHED — CVE-2026-34909 (Ubiquiti UniFi OS). Received CVSS 10.0 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-34910",
      "detail": "ENRICHED — CVE-2026-34910 (Ubiquiti UniFi OS). Received CVSS 10.0 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-34926",
      "detail": "ENRICHED — CVE-2026-34926 (Trend Micro Apex One). Received CVSS 6.7 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-35273",
      "detail": "ENRICHED — CVE-2026-35273 (Oracle  PeopleSoft Enterprise PeopleTools). Received CVSS 9.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-45498",
      "detail": "ENRICHED — CVE-2026-45498 (Microsoft Defender). Received CVSS 7.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-45659",
      "detail": "ENRICHED — CVE-2026-45659 (Microsoft SharePoint Server). Received CVSS 8.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-48172",
      "detail": "ENRICHED — CVE-2026-48172 (LiteSpeed cPanel Plugin). Received CVSS 10.0 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-48907",
      "detail": "ENRICHED — CVE-2026-48907 (Widget Factory Joomla Content Editor ). Received CVSS 10.0 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-54420",
      "detail": "ENRICHED — CVE-2026-54420 (LiteSpeed cPanel Plugin). Received CVSS 8.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-9082",
      "detail": "ENRICHED — CVE-2026-9082 (Drupal Core). Received CVSS 9.8 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
