{
  "day": "2026-07-24",
  "boundary": "UTC calendar day",
  "published_count": 192,
  "by_severity": {
    "CRITICAL": 18,
    "HIGH": 91,
    "MEDIUM": 79,
    "LOW": 4
  },
  "kev_count": 0,
  "exploit_reference_count": 10,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-65711",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.02406,
      "epss_percentile": 0.82743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxsmin",
      "product": "sysPass",
      "cwe": "CWE-78",
      "title": "sysPass 3.2.11 Authenticated OS Command Injection via Backup Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65711"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-50517",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01254,
      "epss_percentile": 0.6709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Copilot",
      "cwe": "CWE-502",
      "title": "Microsoft M365 Copilot Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50517"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-62835",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00973,
      "epss_percentile": 0.59261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Portal",
      "cwe": "CWE-285",
      "title": "Azure Portal Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62835"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-56163",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00901,
      "epss_percentile": 0.56904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Kubernetes Service",
      "cwe": "CWE-306",
      "title": "Microsoft Azure Kubernetes Service Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56163"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-57106",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00901,
      "epss_percentile": 0.56903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Purview Data Governance",
      "cwe": "CWE-918",
      "title": "Data Quality Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57106"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-58630",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00865,
      "epss_percentile": 0.55843,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure App Service for Linux",
      "cwe": "CWE-284",
      "title": "Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58630"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-16634",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00768,
      "epss_percentile": 0.52739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FELIPE",
      "product": "TOML::XS",
      "cwe": "CWE-1104",
      "title": "TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16634"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-62825",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00708,
      "epss_percentile": 0.50649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Key Vault",
      "cwe": "CWE-287",
      "title": "Azure Key Vault Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62825"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-58275",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00684,
      "epss_percentile": 0.49747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure DNS",
      "cwe": "CWE-862",
      "title": "Azure DNS Elevation of Privilege Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58275"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-24727",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0067,
      "epss_percentile": 0.49204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SUNNET Technology Co., Ltd.",
      "product": "Corporate Training Management System",
      "cwe": "CWE-434",
      "title": "SUNNET Corporate Training Management System - Unrestricted Upload of File with Dangerous Type",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24727"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-56191",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00667,
      "epss_percentile": 0.49058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Exchange Online",
      "cwe": "CWE-287",
      "title": "Microsoft Exchange Online Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56191"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-61884",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00664,
      "epss_percentile": 0.4896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tycon Systems",
      "product": "TPDIN-Monitor-WEB2",
      "cwe": "CWE-288",
      "title": "Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path or Channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61884"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-45816",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00615,
      "epss_percentile": 0.46774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache NimBLE",
      "cwe": "CWE-476",
      "title": "Apache NimBLE: NULL pointer dereference vulnerability in SMP LTK request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45816"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-45815",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00602,
      "epss_percentile": 0.46181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache NimBLE",
      "cwe": "CWE-617",
      "title": "Apache NimBLE: Remote reachable assertion in ATT Read Multiple Variable Response handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45815"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-15420",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00586,
      "epss_percentile": 0.45461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "posimyththemes",
      "product": "Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder",
      "cwe": "CWE-22",
      "title": "Nexter Blocks <= 5.0.0 - Authenticated (Subscriber+) Path Traversal to Arbitrary CSS/JS File Deletion via 'plus_name' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15420"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-46452",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00561,
      "epss_percentile": 0.44186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache NimBLE",
      "cwe": "CWE-20",
      "title": "Apache NimBLE: Mesh Proxy SAR reassembly unbounded append and unchecked failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46452"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-49159",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00552,
      "epss_percentile": 0.43767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Graph",
      "cwe": "CWE-200",
      "title": "Microsoft Graph Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49159"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-35425",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00529,
      "epss_percentile": 0.42507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure API Management (APIM)",
      "cwe": "CWE-284",
      "title": "Azure API Management (APIM) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35425"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-66007",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00524,
      "epss_percentile": 0.42234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "huggingface",
      "product": "datasets",
      "cwe": "CWE-22",
      "title": "Datasets Path Traversal via Unsanitized file_name Metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66007"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-66040",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0052,
      "epss_percentile": 0.42018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-122",
      "title": "FFmpeg Heap Out-of-Bounds Write via PNG/APNG eXIf Encoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66040"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-66143",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00513,
      "epss_percentile": 0.41528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Neethi",
      "cwe": "CWE-400",
      "title": "Apache Neethi: Missing global alternative-output budget across policy computation paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66143"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-63317",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00511,
      "epss_percentile": 0.41457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache OpenNLP",
      "cwe": "CWE-470",
      "title": "Apache OpenNLP: Arbitrary Class Instantiation in GeneratorFactory via Feature Descriptor XML",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63317"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-65693",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00484,
      "epss_percentile": 0.39756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microweber",
      "product": "microweber",
      "cwe": "CWE-94",
      "title": "Microweber CMS 2.0.20 Server-Side Template Injection via Mail Templates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65693"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-66142",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00478,
      "epss_percentile": 0.39401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Neethi",
      "cwe": "CWE-400",
      "title": "Apache Neethi: Uncontrolled recursion in policy processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66142"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-66144",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00478,
      "epss_percentile": 0.39401,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Neethi",
      "cwe": "CWE-400",
      "title": "Apache Neethi: Remote PolicyReference fetch lacks resource bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66144"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-64232",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00463,
      "epss_percentile": 0.38441,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "block: recompute nr_integrity_segments in blk_insert_cloned_request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64232"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-64216",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00448,
      "epss_percentile": 0.3744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "netfs: Fix potential UAF in netfs_unlock_abandoned_read_pages()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64216"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-64208",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto/krb5, rxrpc: Fix lack of pre-decrypt/pre-verify length checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64208"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-66138",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00423,
      "epss_percentile": 0.35511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Ironic Python Agent",
      "cwe": "CWE-78",
      "title": "In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic-Python-Agent via a maliciously constructed configuration, because the value of ntp_server is passed to a shell.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66138"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-45812",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00419,
      "epss_percentile": 0.35154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache NimBLE",
      "cwe": "CWE-131",
      "title": "Apache NimBLE: OOB Read via sizeof(pointer) in Legacy Advertising Report Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45812"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-58586",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00408,
      "epss_percentile": 0.34161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZAPAD",
      "product": "Image::WebP",
      "cwe": "CWE-1395",
      "title": "Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58586"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-65623",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mtrudel",
      "product": "bandit",
      "cwe": "CWE-407",
      "title": "Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65623"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-66033",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libssh2",
      "product": "libssh2",
      "cwe": "CWE-125",
      "title": "libssh2 Integer Underflow DoS via AES-GCM Cipher Negotiation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66033"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-16870",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Snowflake",
      "product": "Snowflake libsnowflakeclient",
      "cwe": "CWE-121",
      "title": "Multiple Security Vulnerabilities in Snowflake libsnowflakeclient",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16870"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-12496",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.29015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Loytec",
      "product": "LIP-ME20xC",
      "cwe": "CWE-79",
      "title": "Loytec LINX firmware: Unauthenticated stored XSS in OPC XML-DA server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12496"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-55730",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00358,
      "epss_percentile": 0.29016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Loytec",
      "product": "LWEB-802",
      "cwe": "CWE-79",
      "title": "Loytec LWEB802: Reflected Cross-Site Scripting in LWEB802",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55730"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-15704",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00353,
      "epss_percentile": 0.28517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse BaSyx Go Components",
      "cwe": "CWE-180",
      "title": "CWE-863: ABAC authorization bypass via trailing slash route normalization in Eclipse BaSyx Go Components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15704"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-12654",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00352,
      "epss_percentile": 0.28353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "paymentplugins",
      "product": "Payment Plugins for Stripe WooCommerce",
      "cwe": "CWE-862",
      "title": "Payment Plugins for Stripe WooCommerce <= 4.0.7 - Missing Authorization to Unauthenticated Arbitrary Order Status Modification via Empty Webhook Secret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12654"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-45813",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache NimBLE",
      "cwe": "CWE-191",
      "title": "Apache NimBLE: Incorrect data validation in BASS add/modify source operation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45813"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-17107",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "multicluster engine for Kubernetes 2.1",
      "cwe": "CWE-441",
      "title": "Cluster-proxy: cluster-proxy: impersonation header injection in service-proxy grants cluster-admin on every managed cluster",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17107"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-66041",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00345,
      "epss_percentile": 0.27666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-787",
      "title": "FFmpeg 7.0 - 8.1.2 Heap Out-of-Bounds Write via vf_quirc Filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66041"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-64210",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/mlx5e: xsk: Fix unlocked writing to ICOSQ",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64210"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-13464",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27408,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Kirki – Freeform Page Builder, Website Builder & Customizer",
      "cwe": "CWE-639",
      "title": "Kirki <= 6.0.14 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'context' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13464"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-45811",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache NimBLE",
      "cwe": "CWE-120",
      "title": "Apache NimBLE: Buffer overflow in socket HCI transport",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45811"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-15401",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00342,
      "epss_percentile": 0.27348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e4jvikwp",
      "product": "VikBooking Hotel Booking Engine & PMS",
      "cwe": "CWE-79",
      "title": "VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Unauthenticated Stored Cross-Site Scripting via Custom Field 'vbfX' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15401"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-12736",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpify",
      "product": "WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce",
      "cwe": "CWE-269",
      "title": "WPify Woo <= 5.4.16 - Authenticated (Shop Manager+) Privilege Escalation via Arbitrary Option Update via save_option REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12736"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-64235",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "x86/ftrace: Relocate %rip-relative percpu refs in dynamic trampolines",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64235"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-55732",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.2505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Loytec",
      "product": "LIP-ME20xC",
      "cwe": "CWE-125",
      "title": "Loytec LINX firmware: Out-of-bounds Read in BACnet packet parsing (bacdt_datetime_to_tod)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55732"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-55729",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.2505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Loytec",
      "product": "LWEB-802",
      "cwe": "CWE-200",
      "title": "Loytec LWEB802: Exposure of Sensitive Information in browser localStorage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55729"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-55731",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00322,
      "epss_percentile": 0.2505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Loytec",
      "product": "LIP-ME20xC",
      "cwe": "CWE-606",
      "title": "Loytec LINX firmware: Unchecked input for loop condition in the SNMP agent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55731"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-66008",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0032,
      "epss_percentile": 0.24829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "parse-community",
      "product": "parse-server",
      "cwe": "CWE-209",
      "title": "Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66008"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-66035",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.2463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libssh2",
      "product": "libssh2",
      "cwe": "CWE-122",
      "title": "libssh2 Heap Buffer Overflow via ETM Cipher Negotiation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66035"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-60134",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.24296,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Weintek",
      "product": "cMT3092X firmware",
      "cwe": "CWE-784",
      "title": "Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking in a Security Decision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60134"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-66006",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00315,
      "epss_percentile": 0.24363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "treeverse",
      "product": "lakeFS",
      "cwe": "CWE-306",
      "title": "lakeFS Unauthenticated Operator Metadata Overwrite via setup_comm_prefs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66006"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-49326",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00312,
      "epss_percentile": 0.2394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HBase",
      "cwe": "CWE-862",
      "title": "Apache HBase: Missing scanner instance owner check in thrift delegation service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49326"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-66039",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23916,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-122",
      "title": "FFmpeg MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66039"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-48032",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kerberosmansour",
      "product": "hulumi",
      "cwe": "CWE-697",
      "title": "Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48032"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-12981",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "CAFEHAUS API",
      "cwe": "CWE-269",
      "title": "CAFEHAUS API <= 1.0.0 - Unauthenticated Arbitrary User Password Reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12981"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-15663",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.2289,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kstover",
      "product": "Ninja Forms – The Contact Form Builder That Grows With You",
      "cwe": "CWE-89",
      "title": "Ninja Forms <= 3.14.9 - Authenticated (Administrator+) SQL Injection via Import File 'settings' Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15663"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-16280",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00295,
      "epss_percentile": 0.22125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-190",
      "title": "GPU DDK - Integer overflow in _PMRLogicalOffsetToPhysicalOffset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16280"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-66004",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ahujasid",
      "product": "blender-mcp",
      "cwe": "CWE-22",
      "title": "BlenderMCP Path Traversal via download_polyhaven_asset API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66004"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-16800",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.22051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "PowerShell Universal",
      "cwe": "CWE-94",
      "title": "Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names concatenated into a script invocation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16800"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-16801",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.22051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "PowerShell Universal",
      "cwe": "CWE-94",
      "title": "Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the variables configuration file.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16801"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-48036",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.21978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kerberosmansour",
      "product": "hulumi",
      "cwe": "CWE-755",
      "title": "Hulumi: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48036"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-66139",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.21983,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Zaqar",
      "cwe": "CWE-306",
      "title": "OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66139"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-9765",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Grafana",
      "product": "Grafana IRM",
      "cwe": "CWE-284",
      "title": "CVE-2026-9765 CVE Record",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9765"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-66032",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libssh2",
      "product": "libssh2",
      "cwe": "CWE-415",
      "title": "libssh2 Double-Free Heap Corruption via sftp_open()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66032"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-66036",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-122",
      "title": "FFmpeg Heap Out-of-Bounds Write in vf_hqdn3d Filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66036"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-48033",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.19992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kerberosmansour",
      "product": "hulumi",
      "cwe": "CWE-693",
      "title": "Hulumi: Policy packs bypassed by a forged Pulumi-URN logical name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48033"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-61892",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19864,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Weintek",
      "product": "cMT3092X firmware",
      "cwe": "CWE-732",
      "title": "Weintek cMT3092X Incorrect Permission Assignment for Critical Resource",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61892"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-15810",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google Cloud",
      "product": "Looker",
      "cwe": "CWE-79",
      "title": "Cross-Site Scripting (XSS) in Looker allows Admin Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15810"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-65707",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "likeadmin-likeshop",
      "product": "likeshop",
      "cwe": "CWE-89",
      "title": "Likeshop 3.0.5 Authenticated SQL Injection via adjustAccount Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65707"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-66009",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "parse-community",
      "product": "parse-server",
      "cwe": "CWE-209",
      "title": "Parse Server 9.0.0 Information Disclosure via GraphQL Error Messages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66009"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-15346",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.18009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e4jvikwp",
      "product": "VikBooking Hotel Booking Engine & PMS",
      "cwe": "CWE-79",
      "title": "VikBooking Hotel Booking Engine & PMS <= 1.8.13 - Reflected Cross-Site Scripting via 'category_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15346"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-48035",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17835,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kerberosmansour",
      "product": "hulumi",
      "cwe": "CWE-1059",
      "title": "Hulumi: AccountFoundation audit-delivery S3 bucket could be silently weakened",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48035"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-48037",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kerberosmansour",
      "product": "hulumi",
      "cwe": "CWE-693",
      "title": "Hulumi: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48037"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-48034",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kerberosmansour",
      "product": "hulumi",
      "cwe": "CWE-284",
      "title": "HULUMI-H5 bypass via decoy sibling resources targeting a different bucket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48034"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-64223",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "wifi: mac80211: consume only present negotiated TTLM maps",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64223"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-66027",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kortix-ai",
      "product": "suna",
      "cwe": "CWE-862",
      "title": "Suna < 0.9.102 Broken Access Control via Message Queue API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66027"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-66140",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Exim",
      "product": "Exim",
      "cwe": "CWE-24",
      "title": "Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related to queue-name are mishandled.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66140"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-66034",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "libssh2",
      "product": "libssh2",
      "cwe": "CWE-125",
      "title": "libssh2 Heap Out-of-Bounds Read via publickey subsystem",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66034"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-15333",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cozythemes",
      "product": "Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates",
      "cwe": "CWE-79",
      "title": "Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'cozyCustomFont' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15333"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-15334",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cozythemes",
      "product": "Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates",
      "cwe": "CWE-79",
      "title": "Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'icon.view' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15334"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-57531",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Milkdown",
      "product": "milkdown",
      "cwe": "CWE-79",
      "title": "Milkdown < 7.21.3 DOM XSS via innerHTML Assignment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57531"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-66038",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-908",
      "title": "FFmpeg LCL/ZLIB Video Decoder Information Disclosure via lcldec.c",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66038"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-17048",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat build of Keycloak 26.6",
      "cwe": "CWE-200",
      "title": "Keycloak-services: keycloak-services: vault-resolved rotated client secrets leaked via admin rest api",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17048"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-15739",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.1554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "widgetpack",
      "product": "Rich Showcase for Google Reviews",
      "cwe": "CWE-79",
      "title": "Rich Showcase for Google Reviews <= 6.9.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pagination' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15739"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-15755",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "100plugins",
      "product": "Open User Map – Interactive Leaflet Maps",
      "cwe": "CWE-79",
      "title": "Open User Map <= 1.4.45 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15755"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-14603",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WowOptin: Next-Gen Popup Maker",
      "cwe": "CWE-284",
      "title": "WowOptin < 1.4.38 - Unauthenticated Opt-in Deactivation and Template Row Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14603"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-11354",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xnau",
      "product": "Participants Database",
      "cwe": "CWE-862",
      "title": "Participants Database <= 2.7.8.3 - Missing Authorization to Unauthenticated Arbitrary Record Update / Sensitive Information Exposure via 'id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11354"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-12877",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00238,
      "epss_percentile": 0.15109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Project Management, Bug and Issue Tracking Plugin",
      "cwe": "CWE-287",
      "title": "Software Issue Manager < 5.1.0 - Unauthenticated SQL Injection via Search Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12877"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-12497",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content",
      "cwe": "CWE-269",
      "title": "ProfilePress < 4.16.18 - Unauthenticated Privilege Escalation via Registration Role Selection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12497"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-61886",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Weintek",
      "product": "cMT3092X firmware",
      "cwe": "CWE-256",
      "title": "Weintek cMT3092X Plaintext Storage of a Password",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61886"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-66337",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Libsoup: libsoup: heap buffer over-read via integer underflow in soup_filter_input_stream_read_until()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66337"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-66339",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-201",
      "title": "Libsoup: libsoup: proxy credentials leak to destination server via proxy-authorization header in connect tunnels",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66339"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-64255",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "wifi: iwlwifi: mld: validate sta_mask before ffs() in BA session handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64255"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-16798",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "PowerShell Universal",
      "cwe": "CWE-201",
      "title": "Insertion of sensitive information into sent data in the automation jobs API in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with scoped job or script read permission to obtain another user's stored OAuth refresh token via job read responses that fail to strip the refresh token.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16798"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-65709",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00223,
      "epss_percentile": 0.13221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxsmin",
      "product": "sysPass",
      "cwe": "CWE-639",
      "title": "sysPass 3.2.11 Missing Object-Level Authorization via JSON-RPC API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65709"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-8789",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00223,
      "epss_percentile": 0.13142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "easyappointments",
      "product": "Easy Appointments",
      "cwe": "CWE-863",
      "title": "Easy Appointments <= 3.12.27 - Missing Authorization to Authenticated (Contributor+) Arbitrary Connection Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8789"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-65708",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxsmin",
      "product": "sysPass",
      "cwe": "CWE-639",
      "title": "sysPass 3.2.11 Insecure Direct Object Reference via AccountFileController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65708"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-60135",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.11946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Weintek",
      "product": "cMT3092X firmware",
      "cwe": "CWE-286",
      "title": "Weintek cMT3092X Incorrect User Management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60135"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-66037",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.11964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FFmpeg",
      "product": "FFmpeg",
      "cwe": "CWE-770",
      "title": "FFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66037"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-16910",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11956,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Update Service",
      "cwe": "CWE-918",
      "title": "Quay: ssrf in red hat quay notification webhooks (slack/generic)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16910"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-17039",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00211,
      "epss_percentile": 0.11619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Certificate System 10",
      "cwe": "CWE-863",
      "title": "Pki-core: dogtag-pki: redhat-pki: pki-core: ca renewal request processing omits realm authorization check performed by enrollment path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17039"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-6454",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.10946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "firelightwp",
      "product": "Firelight Lightbox",
      "cwe": "CWE-79",
      "title": "Firelight Lightbox <= 2.3.20 - Authenticated (Contributor+) Stored DOM Cross-Site Scripting via PDF beforeLoad 'href' Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6454"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-10033",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10528,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EventON",
      "product": "EventON Action User",
      "cwe": "CWE-862",
      "title": "EventON Action User <= 2.5.14 - Missing Authorization to Unauthenticated Privilege Escalation via evoau_save_capability AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10033"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-15821",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brainstormforce",
      "product": "SureDash – Community, Courses & Member Dashboard",
      "cwe": "CWE-79",
      "title": "SureDash <= 1.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15821"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-17059",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-639",
      "title": "Keycloak-services: keycloak-services: information disclosure via role-users endpoint bypasses per-user view filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17059"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-15665",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.0993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmanageninja",
      "product": "Fluent Support – Helpdesk & Customer Support Ticket System",
      "cwe": "CWE-79",
      "title": "Fluent Support <= 2.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'redirect-to' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15665"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-7484",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ABIS Technology Ltd. Co.",
      "product": "AVESİS",
      "cwe": "CWE-472",
      "title": "Improper Access Control in Abis Technology's AVESİS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7484"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-15100",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpxpo",
      "product": "Post Grid Gutenberg Blocks – PostX",
      "cwe": "CWE-79",
      "title": "Post Grid Gutenberg Blocks <= 5.0.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'searchnoresult' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15100"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-15464",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09367,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thimpress",
      "product": "WP Hotel Booking",
      "cwe": "CWE-79",
      "title": "WP Hotel Booking <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15464"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-15648",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "berocket",
      "product": "Brands for WooCommerce",
      "cwe": "CWE-79",
      "title": "Brands for WooCommerce <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'width' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15648"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-15653",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeisle",
      "product": "Visualizer – Tables & Charts Manager with Built-in AI Generator",
      "cwe": "CWE-79",
      "title": "Visualizer <= 4.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'backend-title' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15653"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-12702",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Octopus Deploy",
      "product": "Octopus Server",
      "cwe": "CWE-284",
      "title": "In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12702"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2025-9205",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "oyatek",
      "product": "MapSVG – Vector maps, Image maps, Google Maps",
      "cwe": "CWE-79",
      "title": "MapSVG Lite <= 8.14.0 - Authenticated (Contributor+) Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-9205"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-66005",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "janhq",
      "product": "jan",
      "cwe": "CWE-183",
      "title": "Jan Local API Server CORS Origin Reflection via 0.0.0.0 Binding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66005"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2025-71408",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.08278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ntlk",
      "product": "ntlk",
      "cwe": "CWE-95",
      "title": "NLTK < 3.9.3 Eval Injection via collocations.py Command-Line Arguments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-71408"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-11922",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zenml-io",
      "product": "zenml-io/zenml",
      "cwe": "CWE-290",
      "title": "Rate-limit Bypass in zenml-io/zenml",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11922"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-65710",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00178,
      "epss_percentile": 0.07608,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nuxsmin",
      "product": "sysPass",
      "cwe": "CWE-639",
      "title": "sysPass 3.2.11 Missing Authorization via PublicLinkController Account Decryption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65710"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-57530",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.0763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Milkdown",
      "product": "milkdown",
      "cwe": "CWE-79",
      "title": "Milkdown < 7.21.3 Stored XSS via javascript: URL in link href",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57530"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-66338",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-444",
      "title": "Libsoup: libsoup: http request smuggling via permissive chunk-size parsing in soup_body_input_stream_read_chunked()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66338"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-15243",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06735,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apereo",
      "product": "Java Apereo CAS Client",
      "cwe": "CWE-297",
      "title": "Improper Validation of Certificate in CAS Client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15243"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-66010",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cure53",
      "product": "DOMPurify",
      "cwe": "CWE-79",
      "title": "DOMPurify before 3.4.12 Hook Bypass via CUSTOM_ELEMENT_HANDLING",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66010"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-12688",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ProfileGrid",
      "cwe": "CWE-284",
      "title": "ProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membership via PayPal IPN Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12688"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-7007",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-369",
      "title": "Division by zero in Zephyr ext2 superblock parsing allows DoS via crafted filesystem image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7007"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-16799",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "PowerShell Universal",
      "cwe": "CWE-862",
      "title": "Improper access control in the automation tests and workflows features in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with only the Reader role to execute automation tests and modify workflow properties via missing server-side authorization checks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16799"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-12690",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00152,
      "epss_percentile": 0.0494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ProfileGrid",
      "cwe": "CWE-862",
      "title": "ProfileGrid < 5.9.9.7 - Subscriber+ Premium License Tampering via Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12690"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-8308",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Polen Media Software and Information Services",
      "product": "Website Template",
      "cwe": "CWE-79",
      "title": "Reflected XSS Polen Media's Website Template",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8308"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-55985",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.0467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tycon Systems",
      "product": "TPDIN-Monitor-WEB2",
      "cwe": "CWE-312",
      "title": "Tycon Systems TPDIN-Monitor-WEB2 Cleartext Storage of Sensitive Information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55985"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-56392",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00149,
      "epss_percentile": 0.04595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "coreutils",
      "cwe": "CWE-122",
      "title": "Heap-based Buffer Overflow in GNU coreutils",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56392"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-10610",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00143,
      "epss_percentile": 0.04058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ESET spol. s.r.o.",
      "product": "ESET Endpoint Security for macOS",
      "cwe": "CWE-269",
      "title": "Local privilege escalation in ESET security applications for macOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10610"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-12689",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.0364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ProfileGrid",
      "cwe": "CWE-862",
      "title": "ProfileGrid < 5.9.9.7 - Subscriber+ Cross-User Private Message Thread Deletion and Tampering via Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12689"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-12503",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00136,
      "epss_percentile": 0.0348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Loytec",
      "product": "LIP-ME20xC",
      "cwe": "CWE-59",
      "title": "Loytec LINX firmware: Improper Link Resolution in /usr/bin/larm_starter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12503"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-64219",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-674",
      "title": "drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64219"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-56391",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "coreutils",
      "cwe": "CWE-125",
      "title": "Out‑of‑bounds Read in GNU coreutils",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56391"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-12504",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Loytec",
      "product": "LIP-ME20xC",
      "cwe": "CWE-287",
      "title": "Loytec LINX firmware: Improper Authentication in PAM configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12504"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-64217",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-787",
      "title": "netfs: Fix overrun check in netfs_extract_user_iter()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64217"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-64218",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.03044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "batman-adv: bla: fix report_work leak on backbone_gw purge",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64218"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-64225",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02997,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-129",
      "title": "octeontx2-af: CGX: add bounds check to cgx_speed_mbps index",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64225"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-64226",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "sched_ext: Avoid UAF in scx_root_enable_workfn() init failure path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64226"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-64224",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-415",
      "title": "octeontx2-pf: fix double free in rvu_rep_rsrc_init()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64224"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-64221",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "spi: ti-qspi: fix use-after-free after DMA setup failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64221"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-7483",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ESET spol. s.r.o.",
      "product": "ESET Endpoint Security for macOS",
      "cwe": "CWE-269",
      "title": "Local privilege escalation in ESET security applications for macOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7483"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-54342",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "med-united",
      "product": "epa4all",
      "cwe": "CWE-295",
      "title": "TLS Certificate Verification Disabled on CXF Transport Clients in epa4all",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54342"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-48021",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00124,
      "epss_percentile": 0.0257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "med-united",
      "product": "epa4all",
      "cwe": "CWE-295",
      "title": "epa4all Security Incident: Implement keystore based on Telematik TSL, implement hostname check and certificate check for lib-vau",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48021"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-54422",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenStack",
      "product": "Ironic Python Agent",
      "cwe": "CWE-522",
      "title": "In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the credentials used to download it.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54422"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-64214",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64214"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-64220",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-908",
      "title": "device property: set fwnode->secondary to NULL in fwnode_init()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64220"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-64231",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02481,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/msm/dsi: don't dump registers past the mapped region",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64231"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-64222",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-415",
      "title": "octeontx2-pf: avoid double free of pool->stack on AQ init failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64222"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-64227",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02395,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "ACPI: driver: Check ACPI_COMPANION() against NULL during probe",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64227"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-64242",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-415",
      "title": "usb: gadget: net2280: Fix double free in probe error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64242"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-64213",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "hwmon: (lm90) Add lock protection to lm90_alert",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64213"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-64228",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "net: ethtool: phy: avoid NULL deref when PHY driver is unbound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64228"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-64229",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.0228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "x86/mm: Disable broadcast TLB flush when PCID is disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64229"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-64230",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "regulator: tps65219: fix irq_data.rdev not being assigned",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64230"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-64245",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00119,
      "epss_percentile": 0.02099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "fbdev: modedb: fix a possible UAF in fb_find_mode()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64245"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-16519",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00118,
      "epss_percentile": 0.01986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeoVision Inc.",
      "product": "GV-IP Device Utility",
      "cwe": "CWE-427",
      "title": "GeoVision GV-IP Device Utility DLL Search Order Hijacking Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16519"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-64246",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64246"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-64249",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "fpga: region: fix use-after-free in child_regions_with_firmware()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64249"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-64251",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "pwrseq: core: fix use-after-free in pwrseq_debugfs_seq_next()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64251"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-64209",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "phy: qcom: qmp-usbc: Fix out-of-bounds array access in dp swing config",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64209"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-64237",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "Input: elan_i2c - validate firmware size before use",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64237"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-64243",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.0197,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-129",
      "title": "ASoC: codecs: simple-mux: Fix enum control bounds check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64243"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-64212",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "wifi: iwlwifi: mld: don't dereference a pointer before NULL checking it",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64212"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-64239",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-416",
      "title": "mm/damon/sysfs-schemes: delete tried region in regions_rmdirs()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64239"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-64247",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00114,
      "epss_percentile": 0.01694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-125",
      "title": "KVM: x86: hyper-v: Bound the bank index when querying sparse banks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64247"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-64233",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usb: gadget: uvc: hold opts->lock across XU walks in uvc_function_bind",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64233"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-64234",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01771,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "tty: serial: pch_uart: add check for dma_alloc_coherent()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64234"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-64240",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "media: rc: igorplugusb: fix control request setup packet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64240"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-64241",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01693,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-401",
      "title": "gpio: rockchip: teardown bugs and resource leaks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64241"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-64244",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drivers/base/memory: set mem->altmap after successful device registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64244"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-64252",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "MIPS: DEC: Prevent initial console buffer from landing in XKPHYS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64252"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-64253",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "kernel/fork: clear PF_BLOCK_TS in copy_process()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64253"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-64254",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-617",
      "title": "NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64254"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-64236",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-369",
      "title": "i2c: davinci: fix division by zero on missing clock-frequency",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64236"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-55728",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00113,
      "epss_percentile": 0.01678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Loytec",
      "product": "LIP-ME20xC",
      "cwe": "CWE-121",
      "title": "Loytec LINX firmware: Stack-based Buffer Overflow in cmd_ipaddr_conflict",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55728"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-64248",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "MIPS: smp: report dying CPU to RCU in stop_this_cpu()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64248"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-64250",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "LoongArch: Report dying CPU to RCU in stop_this_cpu()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64250"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-49743",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-416",
      "title": "GPU DDK - Write UAF of sync checkpoint in GPU kick function after export fence file descriptor is prematurely closed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49743"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-49744",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.0145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-823",
      "title": "GPU DDK - Unchecked ui32TracePointer in rgxfw_log_ex()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49744"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-49745",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.0145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Imagination Technologies",
      "product": "Graphics DDK",
      "cwe": "CWE-823",
      "title": "GPU DDK - Unvalidated sHWPerfCtlDMABuf GPU-VA, DMA-write into FW privdata via MMU ctx 0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49745"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-64215",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-476",
      "title": "drm/msm/a6xx: Check kzalloc return in a8xx_hfi_send_perf_table",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64215"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-14172",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.01281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rapid7",
      "product": "InsightVM",
      "cwe": "CWE-250",
      "title": "Rapid7 InsightVM, Nexpose, and Insight Agent Local Privilege Escalation via Unvalidated Executable Invocation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14172"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-16730",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-755",
      "title": "Dbus-broker: dbus-broker: session bus denial of service via emfile during peer setup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16730"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-64211",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01321,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "srcu: Don't queue workqueue handlers to never-online CPUs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64211"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-12502",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00106,
      "epss_percentile": 0.0125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Loytec",
      "product": "LIP-ME20xC",
      "cwe": "CWE-269",
      "title": "Loytec LINX firmware: Improper Privilege Management in /usr/bin/ltsudo",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12502"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-16743",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00099,
      "epss_percentile": 0.00908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-269",
      "title": "Accountsservice: accountsservice: arbitrary file read via seticonfile for systemd-homed users",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16743"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-66141",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00095,
      "epss_percentile": 0.00772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Exim",
      "product": "Exim",
      "cwe": "CWE-829",
      "title": "Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66141"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-64238",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0008,
      "epss_percentile": 0.00208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": "CWE-667",
      "title": "gpio: shared: fix deadlock on shared proxy's parent removal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64238"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-16802",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00076,
      "epss_percentile": 0.0011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "PowerShell Universal",
      "cwe": "CWE-312",
      "title": "Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16802"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16372",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16372 (Mozilla Firefox). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16763",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16763 (localstack serverless-localstack). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16765",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16765 (CodeAstro Online Classroom). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16767",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16767 (Ne-Lexa php-zip). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-25244",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-25244 (webdriverio). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-35397",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-35397 (jupyter-server jupyter_server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-38764",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-38764. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47075",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47075 (benoitc hackney). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56290",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56290 (JoomlaCK.fr Page Builder CK extension for Joomla). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56291",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56291 (balbooa.com Balbooa Forms extension for Joomla). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63765",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63765 (chatwoot). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65010",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65010 (huggingface datasets). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65012",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65012 (invoke-ai InvokeAI). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65013",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65013 (onlook repo). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65694",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65694 (microweber). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65698",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65698 (voideditor void). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65916",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65916 (usmannasir cyberpanel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65917",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65917 (usmannasir cyberpanel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65918",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65918 (pytorch vision). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65920",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65920 (huggingface diffusers). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66010",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66010 (cure53 DOMPurify). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66041",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66041 (FFmpeg). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-7007",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-7007 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-37129",
      "detail": "RESCORED — CVE-2024-37129 (Dell Inventory Collector). CVSS 6.7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47304",
      "detail": "RESCORED — CVE-2026-47304 (Microsoft .NET 10.0). CVSS 8.1 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-54120",
      "detail": "RESCORED — CVE-2026-54120 (Microsoft Surface Management Services). CVSS 9.9 → 8.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-56160",
      "detail": "RESCORED — CVE-2026-56160 (Microsoft Azure Red Hat OpenShift (ARO)). CVSS 9.1 → 9.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-56167",
      "detail": "RESCORED — CVE-2026-56167 (Microsoft Azure AI Search). CVSS 8.5 → 8.8 (NVD)."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2022-49662",
      "detail": "ENRICHED — CVE-2022-49662 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2023-52494",
      "detail": "ENRICHED — CVE-2023-52494 (Linux). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2024-27390",
      "detail": "ENRICHED — CVE-2024-27390 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-39729",
      "detail": "ENRICHED — CVE-2025-39729 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-39936",
      "detail": "ENRICHED — CVE-2025-39936 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-20262",
      "detail": "ENRICHED — CVE-2026-20262 (Cisco Catalyst SD-WAN Manager). Received CVSS 6.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-31610",
      "detail": "ENRICHED — CVE-2026-31610 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-33825",
      "detail": "ENRICHED — CVE-2026-33825 (Microsoft Defender). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-35616",
      "detail": "ENRICHED — CVE-2026-35616 (Fortinet FortiClient EMS). Received CVSS 9.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-41091",
      "detail": "ENRICHED — CVE-2026-41091 (Microsoft Defender). Received CVSS 7.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-43119",
      "detail": "ENRICHED — CVE-2026-43119 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-43216",
      "detail": "ENRICHED — CVE-2026-43216 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-45247",
      "detail": "ENRICHED — CVE-2026-45247 (Mirasvit Full Page Cache Warmer). Received CVSS 9.3 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-5281",
      "detail": "ENRICHED — CVE-2026-5281 (Google Dawn). Received CVSS 8.8 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-53027",
      "detail": "ENRICHED — CVE-2026-53027 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-53163",
      "detail": "ENRICHED — CVE-2026-53163 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-53332",
      "detail": "ENRICHED — CVE-2026-53332 (Linux). Received CVSS 5.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
