{
  "day": "2026-07-27",
  "boundary": "UTC calendar day",
  "published_count": 440,
  "by_severity": {
    "CRITICAL": 91,
    "HIGH": 167,
    "MEDIUM": 162,
    "LOW": 14
  },
  "kev_count": 2,
  "exploit_reference_count": 7,
  "awaiting_enrichment_count": 6,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2025-68686",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01264,
      "epss_percentile": 0.67361,
      "kev": true,
      "kev_due_at": "2026-08-10",
      "vendor": "Fortinet",
      "product": "FortiOS",
      "cwe": "CWE-200",
      "title": "Fortinet FortiOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-68686"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-16812",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00884,
      "epss_percentile": 0.56405,
      "kev": true,
      "kev_due_at": "2026-07-30",
      "vendor": "Arista Networks",
      "product": "VeloCloud Orchestrator On-Prem",
      "cwe": "CWE-78",
      "title": "VeloCloud Orchestrator OS Command Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16812"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-48030",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.05155,
      "epss_percentile": 0.91755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pheditor",
      "product": "pheditor",
      "cwe": "CWE-78",
      "title": "Pheditor: OS Command Injection in terminal handler via unsanitized 'dir' parameter (CWE-78)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48030"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-17191",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.02826,
      "epss_percentile": 0.85468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "VeloCloud Orchestrator On-Prem",
      "cwe": "CWE-89",
      "title": "VeloCloud Orchestrator Flow Metrics API SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17191"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-17192",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.02338,
      "epss_percentile": 0.82245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Arista Networks",
      "product": "VeloCloud Orchestrator On-Prem",
      "cwe": "CWE-918",
      "title": "VeloCloud Orchestrator Missing Input Validation SSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17192"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-45112",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0194,
      "epss_percentile": 0.785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-770",
      "title": "Apache Thrift: Unbounded Read Leading to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45112"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-61511",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01715,
      "epss_percentile": 0.75573,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vBulletin",
      "product": "vBulletin",
      "cwe": "CWE-95",
      "title": "vBulletin < 6.2.2 Eval Injection RCE via vb5/template/runtime.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61511"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-58662",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01148,
      "epss_percentile": 0.64267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-125",
      "title": "Apache Thrift: C++ THeaderTransport::readString() info-header length bounds bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58662"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-55968",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01097,
      "epss_percentile": 0.6299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-407",
      "title": "Apache Thrift: Node.js quadratic-time DoS in server receive transports",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55968"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-55969",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01097,
      "epss_percentile": 0.6299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-190",
      "title": "Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: integer overflow in TProtocol::checkReadBytesAvailable()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55969"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-58389",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01097,
      "epss_percentile": 0.6299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-770",
      "title": "Apache Thrift: Rust binary protocol non-strict path missing string size limit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58389"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-41608",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01097,
      "epss_percentile": 0.6299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-409",
      "title": "Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41608"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-49158",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01097,
      "epss_percentile": 0.62989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-409",
      "title": "Apache Thrift: Ruby THeaderTransport ZLIB Decompression Bomb",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49158"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-58023",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01083,
      "epss_percentile": 0.6254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-125",
      "title": "Apache Thrift: c_glib heap out-of-bounds read in transport leftover-bytes path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58023"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-43871",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01074,
      "epss_percentile": 0.62309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-835",
      "title": "Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43871"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-48586",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01074,
      "epss_percentile": 0.62309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-409",
      "title": "Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TZlibTransport Decompression Size Limit",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48586"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-55971",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01042,
      "epss_percentile": 0.61371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-122",
      "title": "Apache Thrift: C++ ZLIB heap buffer overflow (write) in THeaderTransport::untransform()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55971"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-64642",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00948,
      "epss_percentile": 0.58413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vercel",
      "product": "next.js",
      "cwe": "CWE-285",
      "title": "Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64642"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-55970",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00825,
      "epss_percentile": 0.54566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-126",
      "title": "Apache Thrift: C++ heap out-of-bounds read in THeaderTransport::readHeaderFormat()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55970"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-64645",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00782,
      "epss_percentile": 0.53156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vercel",
      "product": "next.js",
      "cwe": "CWE-601",
      "title": "Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64645"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-59686",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00738,
      "epss_percentile": 0.51718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "LoadMaster",
      "cwe": "CWE-78",
      "title": "Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59686"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-66050",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00737,
      "epss_percentile": 0.51698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nitroshare",
      "product": "nitroshare-desktop",
      "cwe": "CWE-22",
      "title": "NitroShare Desktop 0.3.4 Path Traversal via LAN File Transfer Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66050"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-59250",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0073,
      "epss_percentile": 0.51457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-120",
      "title": "Megaco flex scanner buffer overflow via oversized property parm name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59250"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-59687",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0072,
      "epss_percentile": 0.51085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "LoadMaster",
      "cwe": "CWE-78",
      "title": "Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Geo Location Management Interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59687"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-59688",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0072,
      "epss_percentile": 0.51085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "LoadMaster",
      "cwe": "CWE-78",
      "title": "Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Backup Restore Functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59688"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-54540",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00712,
      "epss_percentile": 0.50768,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pheditor",
      "product": "pheditor",
      "cwe": "CWE-78",
      "title": "Authenticated terminal command whitelist bypass in Pheditor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54540"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-55685",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00699,
      "epss_percentile": 0.50319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "remix-run",
      "product": "react-router",
      "cwe": "CWE-400",
      "title": "React Router: Unauthenticated Denial of Service via Inefficient Route Matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55685"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-24252",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00686,
      "epss_percentile": 0.49854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "NeMo Framework",
      "cwe": "CWE-78",
      "title": "NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24252"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-64644",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00675,
      "epss_percentile": 0.49422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vercel",
      "product": "next.js",
      "cwe": "CWE-407",
      "title": "Next.js: Denial of Service in the Image Optimization API using SVGs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64644"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-51564",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00655,
      "epss_percentile": 0.4858,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-601",
      "title": "An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external URLs via a crafted request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51564"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-45623",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00608,
      "epss_percentile": 0.46466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "postcss",
      "product": "postcss",
      "cwe": "CWE-22",
      "title": "PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45623"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-55579",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00603,
      "epss_percentile": 0.46206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pheditor",
      "product": "pheditor",
      "cwe": "CWE-798",
      "title": "Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55579"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-64641",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00599,
      "epss_percentile": 0.46052,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vercel",
      "product": "next.js",
      "cwe": "CWE-834",
      "title": "Next.js: Denial of Service in App Router using Server Actions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64641"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-66729",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00596,
      "epss_percentile": 0.45871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boazsegev",
      "product": "facil.io",
      "cwe": "CWE-125",
      "title": "facil.io 0.6.0 - 0.7.6 Integer Underflow DoS via Multipart MIME Body Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66729"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-66730",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00596,
      "epss_percentile": 0.4587,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boazsegev",
      "product": "facil.io",
      "cwe": "CWE-835",
      "title": "facil.io 0.6.0 - 0.7.6 Infinite Loop DoS via Multipart MIME Body Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66730"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-66731",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00596,
      "epss_percentile": 0.45871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "boazsegev",
      "product": "facil.io",
      "cwe": "CWE-125",
      "title": "facil.io 0.7.5 - 0.7.6 HTTP/1.1 Chunked Transfer Encoding Parser Crash DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66731"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-43803",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00584,
      "epss_percentile": 0.45344,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote attacker may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43803"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-43810",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00584,
      "epss_percentile": 0.45343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43810"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-56748",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00566,
      "epss_percentile": 0.44487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cribl",
      "product": "Cribl Stream",
      "cwe": "CWE-61",
      "title": "Authenticated RCE via Symlink Following in Cribl Stream Pack Git Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56748"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2025-50455",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00552,
      "epss_percentile": 0.43785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passed to the order_by method of the CodeIgniter Query Builder, enabling attackers to perform time-based queries and schema enumeration. Under certain MySQL configurations, the flaw may lead to remote code execution by writing a PHP shell using INTO OUTFILE.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-50455"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-64649",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00536,
      "epss_percentile": 0.42936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vercel",
      "product": "next.js",
      "cwe": "CWE-918",
      "title": "Next.js: Server-Side Request Forgery in Server Actions on Custom Servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64649"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-43807",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00535,
      "epss_percentile": 0.42862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-120",
      "title": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious accessory may be able to cause unexpected app termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43807"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-64646",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00531,
      "epss_percentile": 0.426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vercel",
      "product": "next.js",
      "cwe": "CWE-770",
      "title": "Next.js: Unbounded Server Action payload in Edge runtime",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64646"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-64541",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00521,
      "epss_percentile": 0.42036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64541"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-64551",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00521,
      "epss_percentile": 0.42037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "sctp: validate STALE_COOKIE cause length before reading staleness",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64551"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-64695",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00519,
      "epss_percentile": 0.4194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64695"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-64643",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00516,
      "epss_percentile": 0.41792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vercel",
      "product": "next.js",
      "cwe": "CWE-201",
      "title": "Next.js: Unauthenticated Disclosure of Internal Server Function endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64643"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-43682",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00513,
      "epss_percentile": 0.41568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43682"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-64696",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00513,
      "epss_percentile": 0.41568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64696"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-43777",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00511,
      "epss_percentile": 0.41418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-20",
      "title": "This issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote attacker may be able to cause a denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43777"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-64545",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00496,
      "epss_percentile": 0.40543,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net, bpf: check master for NULL in xdp_master_redirect()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64545"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-43769",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00484,
      "epss_percentile": 0.39801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-190",
      "title": "An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43769"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-64771",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00477,
      "epss_percentile": 0.3938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-119",
      "title": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64771"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-64535",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet-tcp: Fix potential UAF when ddgst mismatch",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64535"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-43778",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00471,
      "epss_percentile": 0.38904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-416",
      "title": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43778"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-43799",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00471,
      "epss_percentile": 0.38904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-416",
      "title": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43799"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-43822",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00471,
      "epss_percentile": 0.38904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-416",
      "title": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43822"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-64700",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00471,
      "epss_percentile": 0.38905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-416",
      "title": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64700"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-64731",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00467,
      "epss_percentile": 0.38677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-22",
      "title": "A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64731"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-64726",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00463,
      "epss_percentile": 0.38417,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker in physical proximity may be able to corrupt process memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64726"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-13714",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00462,
      "epss_percentile": 0.38355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Realtyna Organic IDX plugin + WPL Real Estate",
      "cwe": "CWE-434",
      "title": "Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13714"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-64733",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00462,
      "epss_percentile": 0.38385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-200",
      "title": "This issue was addressed with improved data protection. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to fingerprint the user.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64733"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-43812",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0045,
      "epss_percentile": 0.37554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-416",
      "title": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43812"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-64767",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00445,
      "epss_percentile": 0.37204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-120",
      "title": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64767"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-64704",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00443,
      "epss_percentile": 0.37026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-843",
      "title": "A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64704"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-64769",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00442,
      "epss_percentile": 0.36987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64769"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-64770",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00442,
      "epss_percentile": 0.36988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64770"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-64774",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00442,
      "epss_percentile": 0.36987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-190",
      "title": "An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64774"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-42792",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00441,
      "epss_percentile": 0.36893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-755",
      "title": "epmd permanent DoS via EMFILE on accept(2) in erts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42792"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-43750",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00437,
      "epss_percentile": 0.36607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-120",
      "title": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to execute arbitrary code out of its sandbox or with certain elevated privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43750"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-48145",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00435,
      "epss_percentile": 0.36458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-297",
      "title": "Apache Thrift: C++ TSSLSocket matchName() RFC 6125 Wildcard Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48145"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-64772",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00432,
      "epss_percentile": 0.36209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may be able to cause unexpected application termination or heap corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64772"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-43802",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00431,
      "epss_percentile": 0.36082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43802"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-43809",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00431,
      "epss_percentile": 0.36083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-125",
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43809"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-28928",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00419,
      "epss_percentile": 0.35103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-416",
      "title": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28928"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-43814",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00419,
      "epss_percentile": 0.35104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-416",
      "title": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43814"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-64729",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00419,
      "epss_percentile": 0.35104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-416",
      "title": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64729"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-17500",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00419,
      "epss_percentile": 0.35091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "llama.cpp",
      "cwe": "CWE-404",
      "title": "ggml-org llama.cpp json-schema-to-grammar.cpp _visit_pattern null pointer dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17500"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-17501",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00419,
      "epss_percentile": 0.35091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "llama.cpp",
      "cwe": "CWE-404",
      "title": "ggml-org llama.cpp JSON-Schema-to-GBNF Conversion json-schema-to-grammar.cpp transform recursion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17501"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-48144",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00418,
      "epss_percentile": 0.35015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-297",
      "title": "Apache Thrift: c_glib TLS Client Missing Hostname Verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48144"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-43694",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00417,
      "epss_percentile": 0.34922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or write kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43694"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-43764",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00417,
      "epss_percentile": 0.34921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-190",
      "title": "An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43764"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-43773",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00417,
      "epss_percentile": 0.34922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-125",
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Mounting a maliciously crafted disk image may cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43773"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-43793",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00417,
      "epss_percentile": 0.34921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-20",
      "title": "An issue existed in the handling of environment variables. This issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43793"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-64694",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00417,
      "epss_percentile": 0.34922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-190",
      "title": "An integer overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64694"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-64697",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00417,
      "epss_percentile": 0.34922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64697"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-64698",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00417,
      "epss_percentile": 0.34923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination or read kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64698"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-53666",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00415,
      "epss_percentile": 0.34762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "remix-run",
      "product": "react-router",
      "cwe": "CWE-470",
      "title": "React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53666"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-64703",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00405,
      "epss_percentile": 0.33901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-416",
      "title": "A use after free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause a denial-of-service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64703"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-66391",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00403,
      "epss_percentile": 0.33757,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Wicket",
      "cwe": "CWE-330",
      "title": "Apache Wicket: leaked and missing CSP headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66391"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-51565",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00403,
      "epss_percentile": 0.33667,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Cross-site scripting (XSS) vulnerability in Modules/Docs/DocsController.php in Milk admin <=0.9.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter in a crafted request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51565"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-64735",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00401,
      "epss_percentile": 0.3349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-451",
      "title": "An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A remote attacker may be able to bypass network filters.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64735"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-64738",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00398,
      "epss_percentile": 0.33202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-284",
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64738"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-64746",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00398,
      "epss_percentile": 0.33202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-862",
      "title": "An authorization issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. An app may be able to add contacts without user authorization.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64746"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-59528",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00398,
      "epss_percentile": 0.33151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shiptime",
      "product": "ShipTime: Discounted Shipping Rates",
      "cwe": "CWE-497",
      "title": "WordPress ShipTime: Discounted Shipping Rates plugin <= 1.1.1 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59528"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-14289",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.32987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "FacturaONE para WooCommerce con VeriFactu",
      "cwe": "CWE-94",
      "title": "WP FacturaONE < 5.37 - Unauthenticated Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14289"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-66015",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32459,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-269",
      "title": "JFrog Platform contains an authorization flaw that may allow authenticated privilege escalation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66015"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-43818",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00388,
      "epss_percentile": 0.32123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-190",
      "title": "An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Processing a maliciously crafted image may lead to arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43818"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-43779",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00385,
      "epss_percentile": 0.31868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-284",
      "title": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to intercept network connections intended for another process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43779"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-64702",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00385,
      "epss_percentile": 0.31868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-284",
      "title": "An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to break out of its sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64702"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-54890",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00385,
      "epss_percentile": 0.31836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-191",
      "title": "BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54890"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-64534",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00384,
      "epss_percentile": 0.31686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64534"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-59239",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00383,
      "epss_percentile": 0.31645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roskus",
      "product": "Prospero Flow CRM",
      "cwe": "CWE-79",
      "title": "Stored XSS in Prospero Flow CRM email body allows administrator account takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59239"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-65894",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00378,
      "epss_percentile": 0.31087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CP-Plus",
      "product": "EZ-P21 IP Camera",
      "cwe": "CWE-307",
      "title": "Improper Authentication Vulnerability in CP PLUS EZ-P21 IP Camera",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65894"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-17527",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.30836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Virtualization 4",
      "cwe": "CWE-639",
      "title": "Virt-cdi-operator: containerized-data-importer: cdi.kubevirt.io:view aggregated clusterrole grants create on datavolumes/source, allowing unauthorized pvc clone",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17527"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-65921",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00374,
      "epss_percentile": 0.30731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-22",
      "title": "Potential path traversal leading to unauthorized file writes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65921"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-64739",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.30577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker may be able to cause unexpected app termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64739"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-58227",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00368,
      "epss_percentile": 0.3006,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-674",
      "title": "TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58227"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-64775",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00367,
      "epss_percentile": 0.29941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-665",
      "title": "A memory initialization issue was addressed with improved memory handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64775"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-56747",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00364,
      "epss_percentile": 0.29646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cribl",
      "product": "Cribl Stream",
      "cwe": "CWE-94",
      "title": "Code Injection in JSON Pointer Processing Component in Cribl Stream",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56747"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-59730",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00364,
      "epss_percentile": 0.29616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "withastro",
      "product": "astro",
      "cwe": "CWE-601",
      "title": "@astrojs/node: Backslash-prefixed paths not recognized as internal by trailing-slash redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59730"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-55578",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pheditor",
      "product": "pheditor",
      "cwe": "CWE-78",
      "title": "Pheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55578"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-59546",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.29328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "John Darrel",
      "product": "Hide My WP Ghost",
      "cwe": "CWE-639",
      "title": "WordPress Hide My WP Ghost plugin <= 7.0.06 - 2FA Bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59546"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-43748",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.29,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43748"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-64727",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00358,
      "epss_percentile": 0.28999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-843",
      "title": "A type confusion issue was addressed with improved memory handling. This issue is fixed in macOS Tahoe 26.6, tvOS 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64727"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-17529",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00358,
      "epss_percentile": 0.29083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AstrBotDevs",
      "product": "AstrBot",
      "cwe": "CWE-285",
      "title": "AstrBotDevs AstrBot astr_main_agent.py authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17529"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-17530",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00358,
      "epss_percentile": 0.29083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AstrBotDevs",
      "product": "AstrBot",
      "cwe": "CWE-285",
      "title": "AstrBotDevs AstrBot Subagent astr_agent_tool_exec.py _build_handoff_toolset authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17530"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-66390",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00357,
      "epss_percentile": 0.28931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Wicket",
      "cwe": "CWE-79",
      "title": "Apache Wicket: crafted Link URL strings can break out of the JavaScript sequence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66390"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-65434",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00355,
      "epss_percentile": 0.28782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yoomoney",
      "product": "ЮKassa для WooCommerce",
      "cwe": "CWE-201",
      "title": "WordPress ЮKassa для WooCommerce plugin <= 2.16.1 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65434"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-59560",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00352,
      "epss_percentile": 0.28422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roxnor",
      "product": "FundEngine",
      "cwe": "CWE-862",
      "title": "WordPress FundEngine plugin <= 1.7.8 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59560"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-53667",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0035,
      "epss_percentile": 0.28198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "remix-run",
      "product": "react-router",
      "cwe": "CWE-79",
      "title": "React Router: Cross-site Scripting is Possible due to Missing RSCErrorHandler Protocol Validation (Incomplete fix for CVE-2026-53667)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53667"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-17552",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00349,
      "epss_percentile": 0.28091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RRWO",
      "product": "Plack::App::Prerender",
      "cwe": "CWE-918",
      "title": "Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an arbitrary host via unvalidated REQUEST_URI concatenation in call",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17552"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-65765",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00347,
      "epss_percentile": 0.27873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phoca.cz",
      "product": "Phoca Commander extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - phoca.cz - Path traversal vulnerability in Phoca Commander 1.0.0-6.1.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65765"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-64691",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00343,
      "epss_percentile": 0.274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-120",
      "title": "A buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64691"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-65442",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00341,
      "epss_percentile": 0.27275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Subtle Web Inc",
      "product": "FormCraft",
      "cwe": "CWE-918",
      "title": "WordPress FormCraft plugin <= 3.9.15 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65442"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-64730",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0034,
      "epss_percentile": 0.27144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-451",
      "title": "The issue was addressed with improved UI. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Visiting a website that frames malicious content may lead to UI spoofing.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64730"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-64647",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00339,
      "epss_percentile": 0.26905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vercel",
      "product": "next.js",
      "cwe": "CWE-116",
      "title": "Next.js: Response Body Cache Confusion with Invalid UTF-8 Request Bodies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64647"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-43730",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00338,
      "epss_percentile": 0.26867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-200",
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to fingerprint the user.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43730"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-43757",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00338,
      "epss_percentile": 0.26868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-125",
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43757"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-64762",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00338,
      "epss_percentile": 0.26867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-125",
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64762"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-53668",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00337,
      "epss_percentile": 0.26683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "remix-run",
      "product": "react-router",
      "cwe": "CWE-79",
      "title": "React Router: Open redirect can lead to XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53668"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-64648",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00336,
      "epss_percentile": 0.26641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vercel",
      "product": "next.js",
      "cwe": "CWE-524",
      "title": "Next.js: Response Body Cache Confusion for Requests Containing Bodies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64648"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-64720",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00333,
      "epss_percentile": 0.26273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-362",
      "title": "A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64720"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-64751",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00329,
      "epss_percentile": 0.25862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-416",
      "title": "A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64751"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-64713",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-203",
      "title": "This issue was addressed with improved checks. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Websites may know if the user has visited a given link.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64713"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2021-32084",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00327,
      "epss_percentile": 0.25663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or subnets, the API endpoints are not restricted. If credentials/API keys are known to an attacker, the appliance can still be accessed via the API, leading to a potential compromise of the entire environment that is configured for KACE.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-32084"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-39873",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00327,
      "epss_percentile": 0.25681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Connecting to a malicious SMB server may lead to unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39873"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-43710",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00327,
      "epss_percentile": 0.25681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43710"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-66395",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00327,
      "epss_percentile": 0.25622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan Desktop before v3.7.2 Reflected XSS to RCE via siyuan Protocol",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66395"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-59729",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00327,
      "epss_percentile": 0.2571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "withastro",
      "product": "astro",
      "cwe": "CWE-79",
      "title": "Astro: XSS via unescaped spread attribute names in renderHTMLElement (incomplete fix for CVE-2026-54298)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59729"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-66397",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-22",
      "title": "phpMyFAQ before 4.1.6 Path Traversal via category image deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66397"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-65878",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.25434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Page Builder extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65878"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-65436",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.2546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeum",
      "product": "Kirki",
      "cwe": "CWE-22",
      "title": "WordPress Kirki plugin <= 6.0.13 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65436"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-66476",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00325,
      "epss_percentile": 0.2546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Syed Balkhi",
      "product": "Easy Digital Downloads",
      "cwe": "CWE-22",
      "title": "WordPress Easy Digital Downloads plugin <= 3.6.9 - Arbitrary File Deletion vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66476"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-64768",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-125",
      "title": "An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. A remote attacker may cause an unexpected app termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64768"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-59531",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00324,
      "epss_percentile": 0.25322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anh Tran",
      "product": "Falcon – WordPress Optimizations & Tweaks",
      "cwe": "CWE-1284",
      "title": "WordPress Falcon – WordPress Optimizations & Tweaks plugin <= 2.10.0 - Unknown vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59531"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-59539",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Cozmoslabs",
      "product": "Paid Member Subscriptions",
      "cwe": "CWE-639",
      "title": "WordPress Paid Member Subscriptions plugin <= 3.0.7 - Insecure Direct Object References (IDOR) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59539"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-28982",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00322,
      "epss_percentile": 0.25048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-362",
      "title": "A race condition was addressed with improved locking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A remote user may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28982"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-66028",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00321,
      "epss_percentile": 0.25014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Creativeitem",
      "product": "Ekushey Project Manager CRM",
      "cwe": "CWE-303",
      "title": "Ekushey Project Manager CRM 5.0 Missing Uniqueness Constraint via Client Email",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66028"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-66014",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00319,
      "epss_percentile": 0.24758,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-287",
      "title": "Potential authentication bypass leading to privilege escalation in Artifactory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66014"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-65764",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.24627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phoca.cz",
      "product": "Phoca Commander extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.1.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65764"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-43821",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00317,
      "epss_percentile": 0.24605,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-284",
      "title": "An access issue was addressed with improved access restrictions. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to read files outside of its sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43821"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-51078",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00315,
      "epss_percentile": 0.2435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the str parameter of the file_manage_control.php component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51078"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-53669",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00314,
      "epss_percentile": 0.24259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "remix-run",
      "product": "react-router",
      "cwe": "CWE-601",
      "title": "React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53669"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-65617",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00312,
      "epss_percentile": 0.23971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-502",
      "title": "Potential remote code execution on an Artifactory package service container.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65617"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-51077",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the sqlquery parameter of the sys_sql_query.php component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51077"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-64743",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0031,
      "epss_percentile": 0.23801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-285",
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64743"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-59727",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0031,
      "epss_percentile": 0.23716,
      "kev": false,
      "kev_due_at": null,
      "vendor": "withastro",
      "product": "astro",
      "cwe": "CWE-79",
      "title": "Astro: Cross-site scripting via unescaped transition:* directive values on hydrated islands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59727"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-17612",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23458,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Honeywell",
      "product": "S35 Series 3M/5M/8M/PinHole Cameras",
      "cwe": "CWE-200",
      "title": "Audit Log Exposure through Unauthorized Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17612"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-66053",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.23183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Thrift",
      "cwe": "CWE-297",
      "title": "Apache Thrift: Python TSSLSocket Hostname Matcher Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66053"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-43804",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00304,
      "epss_percentile": 0.23122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-400",
      "title": "This issue was addressed through improved state management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6. Visiting a website may lead to an app denial-of-service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43804"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-59548",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Byteflows",
      "product": "Byteflows Travel &amp; Hotel Booking",
      "cwe": "CWE-497",
      "title": "WordPress Byteflows Travel & Hotel Booking plugin <= 1.0.0 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59548"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-66396",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00296,
      "epss_percentile": 0.22202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan before v3.7.2 Stored XSS to RCE via title-img IAL",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66396"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-40000",
      "cvss_base": 1.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00296,
      "epss_percentile": 0.22252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZTE",
      "product": "Blade A75 5G",
      "cwe": "CWE-22",
      "title": "Path Traversal Vulnerability in ZTE Blade A75 5G",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40000"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-16554",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DaveGamble",
      "product": "cJSON",
      "cwe": "CWE-190",
      "title": "Integer Overflow Leading to Heap Buffer Overflow in cJSON",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16554"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2021-32085",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.21918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-798",
      "title": "An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL accounts have a password of box747, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the MySQL databases. Sensitive information is stored in the database, such as privileged credentials for other systems.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-32085"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2021-32087",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.21918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-798",
      "title": "An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a password of getbxf, which is publicly known and documented. This allows remote attackers to trivially gain privileged access to the FTP service interface, which contains MySQL backups. Sensitive information is stored in the database, such as privileged credentials for other systems.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-32087"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-59251",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-770",
      "title": "Denial of service via exponential certificate policy tree growth in path validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59251"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-55737",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-195",
      "title": "Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55737"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-64719",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-125",
      "title": "An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64719"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-28911",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0029,
      "epss_percentile": 0.21569,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to corrupt memory of a system process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28911"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-42017",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00289,
      "epss_percentile": 0.21451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-200",
      "title": "Privilege escalation via JFrog Worker event token exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42017"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-59240",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roskus",
      "product": "Prospero Flow CRM",
      "cwe": "CWE-639",
      "title": "IDOR in Prospero Flow CRM allows deletion of other users' notifications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59240"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2021-32088",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00287,
      "epss_percentile": 0.21247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-384",
      "title": "An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This protection can be bypassed by removing the kboxid cookie.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-32088"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-59529",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "motov.net",
      "product": "Ebook Store",
      "cwe": "CWE-862",
      "title": "WordPress Ebook Store plugin <= 6.19 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59529"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-65879",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00284,
      "epss_percentile": 0.2102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Page Builder extension for Joomla",
      "cwe": "CWE-798",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65879"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-28931",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-120",
      "title": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. Connecting to a malicious NFS server may lead to kernel memory corruption.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28931"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-59537",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20431,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sender",
      "product": "Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce",
      "cwe": "CWE-89",
      "title": "WordPress Sender – Newsletter, SMS and Email Marketing Automation for WooCommerce plugin <= 2.10.22 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59537"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-65433",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.20474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themewant",
      "product": "RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg",
      "cwe": "CWE-862",
      "title": "WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65433"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-59551",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.2027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rtCamp",
      "product": "rtMedia for WordPress, BuddyPress and bbPress",
      "cwe": "CWE-89",
      "title": "WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.10 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59551"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-12394",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00277,
      "epss_percentile": 0.2021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MemberGlut",
      "cwe": "CWE-269",
      "title": "MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12394"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-66824",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00277,
      "epss_percentile": 0.20211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lookyloo",
      "product": "lookyloo",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting via Unsafe Capture Tree JSON Embedding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66824"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-64540",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.20253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64540"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-64547",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.20253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: usb: net1080: validate packet_len before pad-byte access in rx_fixup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64547"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-66825",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pivotick",
      "product": "pivotick",
      "cwe": "CWE-79",
      "title": "Cross-Site Scripting via Unsafe URL Schemes in Pivotick Property Links",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66825"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-12255",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.19952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MainWP Child",
      "cwe": "CWE-287",
      "title": "MainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordless Site Registration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12255"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-43805",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0027,
      "epss_percentile": 0.19252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-362",
      "title": "A race condition was addressed with improved state handling. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. An app may be able to cause unexpected system termination or write kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43805"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-59728",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.19187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "withastro",
      "product": "astro",
      "cwe": "CWE-91",
      "title": "@astrojs/rss: XML Injection via Unescaped RSS Feed Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59728"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-15928",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "XMLRPC-C",
      "product": "XMLRPC-C",
      "cwe": "CWE-79",
      "title": "XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15928"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2025-59181",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ericsson",
      "product": "Packet Core Controller (PCC)",
      "cwe": "CWE-35",
      "title": "Path traversal Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59181"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-66394",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00266,
      "epss_percentile": 0.18881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-79",
      "title": "SiYuan before v3.7.3 Stored and Reflected XSS via SVG Sanitizer Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66394"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2025-63913",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and configure a matching counter' function of SBI PMU extension.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-63913"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-64728",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.18126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-693",
      "title": "A permissions issue was addressed with improved validation. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Maliciously crafted web content may violate iframe sandboxing policy.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64728"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-13597",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00261,
      "epss_percentile": 0.17984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "微信二维码登陆",
      "cwe": "CWE-287",
      "title": "QRcode Login for WeChat <= 1.3 - Unauthenticated Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13597"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2025-15662",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.17984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Printcart Web to Print Product Designer for WooCommerce",
      "cwe": "CWE-918",
      "title": "Printcart Web to Print Product Designer for WooCommerce < 2.5.3 - Unauthenticated Arbitrary File Read and Server-Side Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15662"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-59532",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.1779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "magepeopleteam",
      "product": "Booking and Rental Manager",
      "cwe": "CWE-1284",
      "title": "WordPress Booking and Rental Manager plugin <= 2.7.2 - Price Manipulation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59532"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-64554",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.17706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64554"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-54272",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "beaugunderson",
      "product": "ip-address",
      "cwe": "CWE-20",
      "title": "ip-address: Misclassification of IPv4-mapped/NAT64 IPv6 addresses can bypass SSRF and trust-boundary checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54272"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-64536",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.1696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64536"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-66758",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00251,
      "epss_percentile": 0.16783,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "GIMP",
      "cwe": "CWE-190",
      "title": "Gimp: integer overflow in file-fits plugin causes a heap-based buffer overflow on crafted fits images",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66758"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-12001",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00251,
      "epss_percentile": 0.16828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "TL-WR850N v3",
      "cwe": "CWE-798",
      "title": "Hardcoded Credential Vulnerability in Multiple TP-Link Router Models",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12001"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-16481",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16492,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "MCP Toolbox for Databases (googleapis/mcp-toolbox)",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF) and Credential Exfiltration in googleapis/mcp-toolbox cloud-healthcare-fhir-fetch-page Tool",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16481"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-43792",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-285",
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in Safari 26.6, macOS Tahoe 26.6. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43792"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-9830",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.16404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "bookingpress-appointment-booking-pro",
      "cwe": "CWE-287",
      "title": "BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering via Permission Callback Bug",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9830"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-59530",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16105,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Payment Plugins",
      "product": "Stripe For WooCommerce",
      "cwe": "CWE-862",
      "title": "WordPress Stripe For WooCommerce plugin <= 4.0.7 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59530"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-59534",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Aurovrata Venet",
      "product": "Post My CF7 Form",
      "cwe": "CWE-862",
      "title": "WordPress Post My CF7 Form plugin <= 6.2.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59534"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-59536",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CoCart Headless",
      "product": "CoCart – Headless ecommerce",
      "cwe": "CWE-862",
      "title": "WordPress CoCart – Headless ecommerce plugin <= 4.8.4 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59536"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-59557",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Franky",
      "product": "Events Made Easy",
      "cwe": "CWE-862",
      "title": "WordPress Events Made Easy plugin <= 3.1.3 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59557"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-65435",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.15639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thrive Themes Coupon",
      "product": "Thrive Leads Version",
      "cwe": "CWE-862",
      "title": "WordPress Thrive Leads Version plugin <= 10.9.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65435"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-66398",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00241,
      "epss_percentile": 0.15537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-494",
      "title": "phpMyFAQ before 4.1.6 Remote Code Execution via Configuration API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66398"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-13332",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0024,
      "epss_percentile": 0.15336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Masteriyo LMS",
      "cwe": "CWE-287",
      "title": "Masteriyo LMS < 2.3.1 - Unauthenticated Arbitrary User Session Termination (Denial of Service)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13332"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-43760",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15429,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-284",
      "title": "An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access user-sensitive data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43760"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-10819",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-409",
      "title": "Mattermost Server Denial of Service via Animated GIF Emoji Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10819"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-66412",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Leantime",
      "product": "Leantime",
      "cwe": "CWE-639",
      "title": "Leantime all versions prior to and 3.6.2 Broken Access Control via tickets.getMilestone JSON-RPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66412"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-65766",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00237,
      "epss_percentile": 0.14946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Page Builder extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.7.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65766"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-59527",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00236,
      "epss_percentile": 0.14907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RomanCode",
      "product": "MapSVG",
      "cwe": "CWE-89",
      "title": "WordPress MapSVG plugin <= 8.14.0 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59527"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-59533",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00236,
      "epss_percentile": 0.14905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Christoph Vielgrader",
      "product": "Relevanssi Light",
      "cwe": "CWE-89",
      "title": "WordPress Relevanssi Light plugin <= 1.2.2 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59533"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-59538",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00236,
      "epss_percentile": 0.14905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ruben Garcia",
      "product": "GamiPress",
      "cwe": "CWE-89",
      "title": "WordPress GamiPress plugin <= 7.9.7 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59538"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-59549",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00236,
      "epss_percentile": 0.14906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rtCamp",
      "product": "rtMedia for WordPress, BuddyPress and bbPress",
      "cwe": "CWE-89",
      "title": "WordPress rtMedia for WordPress, BuddyPress and bbPress plugin <= 4.7.10 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59549"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-59550",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00236,
      "epss_percentile": 0.14905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Strategy11 Team",
      "product": "AWP Classifieds",
      "cwe": "CWE-89",
      "title": "WordPress AWP Classifieds plugin <= 4.4.7 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59550"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-14827",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Calendar",
      "cwe": "CWE-79",
      "title": "Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14827"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-17568",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-863",
      "title": "Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions Server 2026.1.23.0 and earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17568"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-14235",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.1435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Download Manager",
      "cwe": "CWE-284",
      "title": "WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Download Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14235"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-66018",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-200",
      "title": "JFrog Artifactory build environment properties exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66018"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-66399",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thorsten",
      "product": "phpMyFAQ",
      "cwe": "CWE-269",
      "title": "phpMyFAQ before 4.1.6 Privilege Escalation via Group Membership",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66399"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-42016",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14033,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-863",
      "title": "Incorrect authorization validation of user token in JFrog Artifactory allows Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42016"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-14856",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Media Manager",
      "product": "TastyIgniter",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting (XSS) in TastyIgniter Media Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14856"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-65876",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00228,
      "epss_percentile": 0.1379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Page Builder extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - joomshaper.com - Unauthenticated SQL injection in SP Page Builder < 6.8.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65876"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-64757",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00227,
      "epss_percentile": 0.13706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-119",
      "title": "A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 26.6, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64757"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-65877",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.1362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomshaper.com",
      "product": "SP Page Builder extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - joomshaper.com - Authenticated SQL injection in SP Page Builder < 6.7.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65877"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-13152",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Custom Fields Account Registration For Woocommerce",
      "cwe": "CWE-269",
      "title": "Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13152"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-66427",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13587,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jgwhite33",
      "product": "WP Google Review Slider",
      "cwe": "CWE-89",
      "title": "WordPress WP Google Review Slider plugin <= 18.4 - SQL Injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66427"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-14820",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Quiz and Survey Master (QSM)",
      "cwe": "CWE-200",
      "title": "Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via Quiz Login",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14820"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-66442",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00223,
      "epss_percentile": 0.13202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "YayCommerce",
      "product": "YayPricing",
      "cwe": "CWE-862",
      "title": "WordPress YayPricing plugin <= 3.5.6 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66442"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-59535",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00219,
      "epss_percentile": 0.12681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Thrive Themes Coupon",
      "product": "Thrive Product Manager",
      "cwe": "CWE-862",
      "title": "WordPress Thrive Product Manager plugin <= 10.9.2 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59535"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-10600",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-770",
      "title": "Denial of service via unbounded document content extraction in Mattermost Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10600"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-65924",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF) via Terraform Remote repository",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65924"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-66759",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00214,
      "epss_percentile": 0.12109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "GIMP",
      "cwe": "CWE-125",
      "title": "Gimp: out-of-bounds read in file-icns plugin causes information disclosure or crash on crafted icns images",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66759"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-55953",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00211,
      "epss_percentile": 0.11723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-757",
      "title": "TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55953"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-59559",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.11708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themewant",
      "product": "RT Mega Menu – Mega Menu Builder for Elementor &amp; Gutenberg",
      "cwe": "CWE-79",
      "title": "WordPress RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin <= 1.5.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59559"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-48052",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.1173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "papra-hq",
      "product": "papra",
      "cwe": "CWE-639",
      "title": "Papra: Cross-organization tag deletion and modification via authenticated cross-tenant request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48052"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-65618",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11318,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-918",
      "title": "Improper URL validation when handling specific URLs Pub, Terraform and Docker packages might lead to SSRF vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65618"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-65925",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery (SSRF) via JFrog Artifactory Cargo remote repository",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65925"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-64783",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00208,
      "epss_percentile": 0.11259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-416",
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64783"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-12493",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00208,
      "epss_percentile": 0.11291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Clover Payment Gateway by Zaytech for WooCommerce",
      "cwe": "CWE-287",
      "title": "Clover Payment Gateway by Zaytech for WooCommerce < 1.3.6 - Unauthenticated Payment Bypass via check_order",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12493"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-48051",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00207,
      "epss_percentile": 0.11142,
      "kev": false,
      "kev_due_at": null,
      "vendor": "papra-hq",
      "product": "papra",
      "cwe": "CWE-918",
      "title": "Papra: SSRF via HTTP redirect bypass in webhook delivery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48051"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-14568",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00203,
      "epss_percentile": 0.10565,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "User Frontend: AI Powered Frontend Post Submission, User Directory, User Profile, Membership & User Registration",
      "cwe": "CWE-287",
      "title": "WP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14568"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-66473",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00202,
      "epss_percentile": 0.10449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xendit",
      "product": "Xendit Payment",
      "cwe": "CWE-862",
      "title": "WordPress Xendit Payment plugin <= 7.1.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66473"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-17531",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00199,
      "epss_percentile": 0.10134,
      "kev": false,
      "kev_due_at": null,
      "vendor": "unitedbyai",
      "product": "droidclaw",
      "cwe": "CWE-285",
      "title": "unitedbyai droidclaw Unsigned Scheduled Callback goals.ts authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17531"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-66757",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "GIMP",
      "cwe": "CWE-190",
      "title": "Gimp: signed integer overflow in file-sgi (sgi-lib) causes the plugin to crash on rle sgi images",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66757"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-65564",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.0988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "chrisvrichardson",
      "product": "MapPress Maps for WordPress",
      "cwe": "CWE-497",
      "title": "WordPress MapPress Maps for WordPress plugin <= 2.97.6 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65564"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-66438",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tim Strifler",
      "product": "Exclusive Addons Elementor",
      "cwe": "CWE-497",
      "title": "WordPress Exclusive Addons Elementor plugin <= 2.8.0 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66438"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-64742",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-319",
      "title": "This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64742"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-65445",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "iSaumya",
      "product": "Ad Invalid Click Protector (AICP)",
      "cwe": "CWE-862",
      "title": "WordPress Ad Invalid Click Protector (AICP) plugin <= 1.3.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65445"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-12989",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00195,
      "epss_percentile": 0.09595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ghost Robotics",
      "product": "Vision 60",
      "cwe": "CWE-306",
      "title": "Multiple vulnerabilities in Ghost Robotics' Vision 60",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12989"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-43728",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00195,
      "epss_percentile": 0.09568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-362",
      "title": "This issue was addressed through improved state management. This issue is fixed in macOS Tahoe 26.6. An attacker may be able to modify the state of the Keychain.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43728"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-59552",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.09454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shahadat Hossain",
      "product": "3D Flipbook PDF Viewer &amp; Embedder",
      "cwe": "CWE-918",
      "title": "WordPress 3D Flipbook PDF Viewer & Embedder plugin <= 1.4.2 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59552"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2021-32086",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0019,
      "epss_percentile": 0.09071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-321",
      "title": "An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in the MySQL databases. (This key is not unique for each installation.) An attacker that gains access to the MySQL server or a backup files can decrypt the secrets. Often, the decrypted secrets can be used to escalate privileges within KACE, or gain privileged access to unrelated systems or services.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2021-32086"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-65923",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-918",
      "title": "Potential server-side request forgery in Artifactory Ansible repository handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65923"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-65616",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00187,
      "epss_percentile": 0.08706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-347",
      "title": "Potential privilege escalation to JFrog administrator privileges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65616"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-13390",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "The Events Calendar",
      "cwe": "CWE-862",
      "title": "The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Status Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13390"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2025-59172",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ericsson",
      "product": "Packet Core Controller (PCC)",
      "cwe": "CWE-78",
      "title": "Improper Neutralization of Special Elements used in an OS Command Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59172"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-59553",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RexTheme",
      "product": "Product Feed Manager",
      "cwe": "CWE-79",
      "title": "WordPress Product Feed Manager plugin <= 7.6.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59553"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-59556",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "acowebs",
      "product": "Dynamic Pricing With Discount Rules for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Dynamic Pricing With Discount Rules for WooCommerce plugin <= 4.5.11 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59556"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-59558",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0018,
      "epss_percentile": 0.07867,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpdevelop",
      "product": "Booking Calendar",
      "cwe": "CWE-79",
      "title": "WordPress Booking Calendar plugin <= 11.4.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59558"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-64549",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.0018,
      "epss_percentile": 0.0791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: bpa10x: avoid OOB read of revision string in bpa10x_setup()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64549"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-65922",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jfrog",
      "product": "artifactory",
      "cwe": "CWE-862",
      "title": "Potential unauthorized modification of Artifactory internal metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65922"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-65567",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "Event Tickets",
      "cwe": "CWE-862",
      "title": "WordPress Event Tickets plugin <= 5.29.0.1 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65567"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-66477",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07431,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Shufflehound",
      "product": "Gillion",
      "cwe": "CWE-862",
      "title": "WordPress Gillion theme <= 4.13 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66477"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-64538",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00176,
      "epss_percentile": 0.07489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv6: Fix null-ptr-deref in fib6_nh_mtu_change().",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64538"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-64544",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00176,
      "epss_percentile": 0.07489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64544"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-64553",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00176,
      "epss_percentile": 0.0749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: psample: fix info leak in PSAMPLE_ATTR_DATA",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64553"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-59690",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "LoadMaster",
      "cwe": "CWE-862",
      "title": "Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, MOVEit WAF, and Multi Tenant Missing Authorization Allows Privilege Escalation via REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59690"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-64537",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00172,
      "epss_percentile": 0.07003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bridge: cfm: reject invalid CCM interval at configuration time",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64537"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-14236",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.0686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Contact Form 7",
      "cwe": "CWE-601",
      "title": "Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14236"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-43753",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-125",
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker with physical access to a locked device may be able to view sensitive user information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43753"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-59689",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00169,
      "epss_percentile": 0.06714,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Progress Software",
      "product": "LoadMaster",
      "cwe": "CWE-863",
      "title": "Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF Improper Authorization Allows Privilege Escalation to Root",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59689"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-64542",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00168,
      "epss_percentile": 0.06509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "ipv6: ndisc: fix NULL deref in accept_untracked_na()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64542"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-39875",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00167,
      "epss_percentile": 0.06463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-276",
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39875"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-64740",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00165,
      "epss_percentile": 0.06266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-22",
      "title": "A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6. A malicious app may be able to break out of its sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64740"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-66029",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.0627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Creativeitem",
      "product": "Ekushey Project Manager CRM",
      "cwe": "CWE-79",
      "title": "Ekushey Project Manager CRM 5.0 Stored XSS via Client Name Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66029"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-66030",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Creativeitem",
      "product": "Ekushey Project Manager CRM",
      "cwe": "CWE-79",
      "title": "Ekushey Project Manager CRM 5.0 Stored XSS via Ticket Title Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66030"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-66031",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Creativeitem",
      "product": "Ekushey Project Manager CRM",
      "cwe": "CWE-79",
      "title": "Ekushey Project Manager CRM 5.0 Stored XSS via Reply Ticket Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66031"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-65568",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Visual Composer",
      "product": "Visual Composer Website Builder",
      "cwe": "CWE-862",
      "title": "WordPress Visual Composer Website Builder plugin <= 45.15.0 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65568"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-13726",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00164,
      "epss_percentile": 0.06056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MPG",
      "cwe": "CWE-79",
      "title": "Multiple Page Generator Plugin – MPG < 4.1.8 - Reflected XSS via mpg_shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13726"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-10683",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-835",
      "title": "DesignWare I2C target driver can be wedged into a permanent stuck state by an on-bus master (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10683"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-12982",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Document Gallery",
      "cwe": "CWE-79",
      "title": "Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12982"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-14190",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Sina Extension for Elementor",
      "cwe": "CWE-79",
      "title": "Sina Extension for Elementor < 3.10.2 - Reflected XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14190"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-12495",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mercusys",
      "product": "MB115-4G",
      "cwe": "CWE-121",
      "title": "Stack-Based Buffer Overflow in the Mercusys MB115-4G",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12495"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-17569",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05877,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-522",
      "title": "Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint. This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions Server 2026.1.23.0 and earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17569"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-17570",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.05787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Server",
      "cwe": "CWE-639",
      "title": "Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests. This issue affects : * Devolutions Server 2026.2.4.0 through 2026.2.12.0 * Devolutions Server 2026.1.23.0 and earlier",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17570"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-43766",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0016,
      "epss_percentile": 0.05721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-287",
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An attacker with physical access to a locked device may be able to view sensitive user information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43766"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-61953",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00159,
      "epss_percentile": 0.05616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "QuantumCloud",
      "product": "Simple Link Directory Pro",
      "cwe": "CWE-918",
      "title": "WordPress Simple Link Directory Pro plugin <= 15.0.6 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61953"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-65893",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00158,
      "epss_percentile": 0.05533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CP-Plus",
      "product": "EZ-P21 IP Camera",
      "cwe": "CWE-489",
      "title": "Arbitrary Code Execution Vulnerability in CP PLUS EZ-P21 IP Camera",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65893"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-14189",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00158,
      "epss_percentile": 0.05519,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WPBot",
      "cwe": "CWE-89",
      "title": "WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14189"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-12383",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.05279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.5 for RHEL 8",
      "cwe": "CWE-345",
      "title": "Eda-server: externaleventstreamviewset trusts subject header without validation and leaks expected dn",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12383"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-64732",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-284",
      "title": "This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6. An attacker with physical access may be able to access sensitive user data during iPhone Mirroring.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64732"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-56537",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00156,
      "epss_percentile": 0.05279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Connections",
      "cwe": "CWE-209",
      "title": "HCL Connections is vulnerable to information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56537"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-56538",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00156,
      "epss_percentile": 0.05278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCLSoftware",
      "product": "Connections",
      "cwe": "CWE-213",
      "title": "HCL Connections is vulnerable to information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56538"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-28981",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00154,
      "epss_percentile": 0.05044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-120",
      "title": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Processing a maliciously crafted image may lead to arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28981"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-43776",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.04892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-120",
      "title": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43776"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-47078",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Erlang",
      "product": "OTP",
      "cwe": "CWE-23",
      "title": "Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47078"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-43772",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-22",
      "title": "A path traversal issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to break out of its sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43772"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-43698",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04751,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-88",
      "title": "An injection issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to gain root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43698"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-43749",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0015,
      "epss_percentile": 0.04725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-22",
      "title": "A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43749"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-43723",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-22",
      "title": "A path handling issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to gain root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43723"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-10082",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Advanced Ads",
      "cwe": "CWE-79",
      "title": "Advanced Ads – Ad Manager & AdSense < 2.0.23 - Contributor+ Stored XSS via the_ad Shortcode 'ad_args' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10082"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-13400",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Simply Schedule Appointments",
      "cwe": "CWE-79",
      "title": "Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Booking Customer Information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13400"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-61957",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.0439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miniOrange",
      "product": "miniorange otp verification",
      "cwe": "CWE-79",
      "title": "WordPress miniorange otp verification plugin <= 5.5.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61957"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-65437",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CleanTalk Inc",
      "product": "Spam protection, AntiSpam, FireWall by CleanTalk",
      "cwe": "CWE-79",
      "title": "WordPress Spam protection, AntiSpam, FireWall by CleanTalk plugin <= 6.82 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65437"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-65438",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kofi Mokome",
      "product": "Message Filter for Contact Form 7",
      "cwe": "CWE-79",
      "title": "WordPress Message Filter for Contact Form 7 plugin <= 1.6.3.9 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65438"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-65439",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themefic",
      "product": "Ultimate Addons for Contact Form 7",
      "cwe": "CWE-79",
      "title": "WordPress Ultimate Addons for Contact Form 7 plugin <=3.5.45 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65439"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-65440",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04389,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roxnor",
      "product": "GetGenie",
      "cwe": "CWE-79",
      "title": "WordPress GetGenie plugin <= 4.4.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65440"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-65441",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Nexcess",
      "product": "GiveWP",
      "cwe": "CWE-79",
      "title": "WordPress GiveWP plugin <= 4.16.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65441"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-65443",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Media",
      "product": "BackWPup",
      "cwe": "CWE-79",
      "title": "WordPress BackWPup plugin <= 5.7.4 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65443"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-65446",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Chill",
      "product": "Kali Forms",
      "cwe": "CWE-79",
      "title": "WordPress Kali Forms plugin <= 2.4.18 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65446"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-65447",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wasiliy Strecker / ContestGallery developer",
      "product": "Contest Gallery",
      "cwe": "CWE-79",
      "title": "WordPress Contest Gallery plugin <= 30.0.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65447"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2025-59177",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ericsson",
      "product": "Ericsson Packet Core Controller (PCC)",
      "cwe": "CWE-209",
      "title": "Generation of Error Message Containing Sensitive Information Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59177"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2025-59178",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ericsson",
      "product": "Packet Core Controller (PCC)",
      "cwe": "CWE-497",
      "title": "Exposure of Sensitive System Information to an Unauthorized Control Sphere Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59178"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-43771",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-121",
      "title": "A stack overflow was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause a denial-of-service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43771"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-64722",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-120",
      "title": "A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a 3D model may result in disclosure of process memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64722"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-64548",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00144,
      "epss_percentile": 0.04159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64548"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-64552",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00144,
      "epss_percentile": 0.04159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "virtio-net: fix len check in receive_big()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64552"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-43765",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-59",
      "title": "This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to modify protected parts of the file system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43765"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-12991",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.04023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ghost Robotics",
      "product": "Vision 60",
      "cwe": "CWE-300",
      "title": "Multiple vulnerabilities in Ghost Robotics' Vision 60",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12991"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-64747",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.04013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-120",
      "title": "A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to execute arbitrary code with kernel privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64747"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2026-14203",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.04035,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Smart Manager",
      "cwe": "CWE-79",
      "title": "Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post Title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14203"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-65557",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tychesoftwares",
      "product": "Abandoned Cart Lite for WooCommerce",
      "cwe": "CWE-79",
      "title": "WordPress Abandoned Cart Lite for WooCommerce plugin <= 6.8.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65557"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-65563",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeisle",
      "product": "Orbit Fox by ThemeIsle",
      "cwe": "CWE-79",
      "title": "WordPress Orbit Fox by ThemeIsle plugin <= 3.0.7 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65563"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-66475",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0014,
      "epss_percentile": 0.03814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "acowebs",
      "product": "Checkout Field Editor for WooCommerce &#8211; Checkout Manager",
      "cwe": "CWE-79",
      "title": "WordPress Checkout Field Editor for WooCommerce &#8211; Checkout Manager plugin <= 3.0.5 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66475"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-28912",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-693",
      "title": "A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A user may be able to elevate privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28912"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-64699",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-457",
      "title": "A memory initialization issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64699"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-65558",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPCenter",
      "product": "AffiliateX",
      "cwe": "CWE-918",
      "title": "WordPress AffiliateX plugin <= 2.3.5 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65558"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-64533",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.03561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/ntfs3: validate lcns_follow in log_replay conversion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64533"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-17514",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00137,
      "epss_percentile": 0.03586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ZJONSSON",
      "product": "node-unzipper",
      "cwe": "CWE-22",
      "title": "ZJONSSON node-unzipper extract.js Extract path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17514"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-64745",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00136,
      "epss_percentile": 0.03489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-287",
      "title": "This issue was addressed with additional restrictions on the lock screen. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A person with physical access to a locked device may be able to access contacts and photos.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64745"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-39877",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-119",
      "title": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to disclose kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39877"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-64734",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-200",
      "title": "The issue was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted contact may leak sensitive data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64734"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-57917",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Asseco",
      "product": "proCertum SmartSign",
      "cwe": "CWE-611",
      "title": "Improper Restriction of XML External Entity Reference in proCertum SmartSign",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57917"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-28973",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.03305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-190",
      "title": "An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. A malicious app may be able to break out of its sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28973"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-43729",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.03304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. Processing a maliciously crafted image may corrupt process memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43729"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-43733",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.03303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6. Processing a maliciously crafted image may corrupt process memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43733"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-43780",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.03304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-190",
      "title": "An integer overflow was addressed with improved input validation. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted texture may lead to unexpected app termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43780"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-64716",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00133,
      "epss_percentile": 0.03304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted image may corrupt process memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64716"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-43738",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-125",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. Processing a maliciously crafted asset catalog may result in disclosure of process memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43738"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-12990",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ghost Robotics",
      "product": "Vision 60",
      "cwe": "CWE-284",
      "title": "Multiple vulnerabilities in Ghost Robotics' Vision 60",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12990"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-43800",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.03161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-200",
      "title": "An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43800"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-64532",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.03075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64532"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-64692",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.03048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-125",
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause a denial-of-service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64692"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-64725",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.03068,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause a denial-of-service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64725"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-65448",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AcyMailing Newsletter Team",
      "product": "Anti Spam and list cleaner &#8211; AcyChecker",
      "cwe": "CWE-79",
      "title": "WordPress Anti Spam and list cleaner – AcyChecker plugin <= 1.8.1 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65448"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-65561",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.031,
      "kev": false,
      "kev_due_at": null,
      "vendor": "miniOrange",
      "product": "WordPress Social Login and Register",
      "cwe": "CWE-79",
      "title": "WordPress WordPress Social Login and Register plugin <= 7.8.0 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65561"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-65562",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WPDeveloper",
      "product": "BetterDocs",
      "cwe": "CWE-79",
      "title": "WordPress BetterDocs plugin <= 4.6.2 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65562"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-66433",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ShapedPlugin LLC",
      "product": "Location Weather",
      "cwe": "CWE-79",
      "title": "WordPress Location Weather plugin <= 3.0.6 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66433"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-66434",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sayontan Sinha",
      "product": "Photonic Gallery & Lightbox for Flickr, SmugMug & Others",
      "cwe": "CWE-79",
      "title": "WordPress Photonic Gallery & Lightbox for Flickr, SmugMug & Others plugin <= 3.33 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66434"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-66445",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03104,
      "kev": false,
      "kev_due_at": null,
      "vendor": "100plugins",
      "product": "Open User Map",
      "cwe": "CWE-79",
      "title": "WordPress Open User Map plugin <= 1.4.46 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66445"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-66448",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WP Chill",
      "product": "Gallery PhotoBlocks",
      "cwe": "CWE-79",
      "title": "WordPress Gallery PhotoBlocks plugin <= 1.3.3 - Cross Site Scripting (XSS) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66448"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-43774",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-787",
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43774"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-43797",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-200",
      "title": "This issue was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6. An app may be able to access information about a user's contacts.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43797"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-64710",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-200",
      "title": "A privacy issue was addressed by removing sensitive data. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to leak sensitive user information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64710"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-64531",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02981,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: openvswitch: reject oversized nested action attrs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64531"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-64763",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64763"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-64764",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64764"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-64765",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-190",
      "title": "An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64765"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-64766",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-190",
      "title": "An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination or arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64766"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-43813",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00129,
      "epss_percentile": 0.02937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-20",
      "title": "A validation issue was addressed with improved input sanitization. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. A maliciously crafted app may be able to bypass code signing enforcement.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43813"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-43714",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-20",
      "title": "The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS 26.6, watchOS 26.6. A malicious app may be able to access protected user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43714"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-43754",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-200",
      "title": "This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to leak sensitive kernel state.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43754"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-43758",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-200",
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, watchOS 26.6. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43758"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-43796",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-200",
      "title": "This issue was addressed with improved data protection. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to read a persistent device identifier.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43796"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-43801",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-200",
      "title": "This issue was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43801"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-64709",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.03039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-200",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to disclose kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64709"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-64721",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-664",
      "title": "This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64721"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-64741",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.03039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-200",
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.6 and iPadOS 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to read a persistent device identifier.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64741"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-64744",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.0304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-200",
      "title": "An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64744"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-64555",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00128,
      "epss_percentile": 0.02933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64555"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-28932",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-400",
      "title": "A logic issue existed resulting in memory corruption. This was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause a denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28932"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-43759",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-200",
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.6, watchOS 26.6. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43759"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-43768",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-400",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43768"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-64708",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-693",
      "title": "A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may bypass Gatekeeper checks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64708"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-28896",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An attacker may be able to cause unexpected system termination or read kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28896"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-64550",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "net: qualcomm: rmnet: validate MAP frame length before ingress parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64550"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-43681",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-120",
      "title": "A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A local user may be able to read kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43681"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-64546",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02665,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "drm/edid: fix OOB read in drm_parse_tiled_block()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64546"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-43739",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43739"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-43744",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing an audio stream in a maliciously crafted media file may terminate the process.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43744"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-43816",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43816"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-43817",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-125",
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43817"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-64693",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-843",
      "title": "A type confusion issue was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted image may lead to a denial-of-service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64693"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-64724",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00126,
      "epss_percentile": 0.02738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-400",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An attacker on the local network may be able to cause a denial-of-service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64724"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-64543",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "tipc: fix use-after-free of the discoverer in tipc_disc_rcv()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64543"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-28945",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00125,
      "epss_percentile": 0.02593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-284",
      "title": "A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to bypass network restrictions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28945"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-43673",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted audio file may corrupt process memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43673"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-43711",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-119",
      "title": "A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted video file may lead to unexpected app termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43711"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-64749",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, visionOS 26.6. An app may be able to cause unexpected system termination or corrupt kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64749"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2026-64758",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00124,
      "epss_percentile": 0.02593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved bounds checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to unexpected app termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64758"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-43763",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.0252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-284",
      "title": "A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to read files outside of its sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43763"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-64755",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-200",
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64755"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-43819",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-284",
      "title": "An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Tahoe 26.6. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43819"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-64539",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: eir: Fix stack OOB write when prepending the Flags AD",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64539"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-43747",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00122,
      "epss_percentile": 0.02339,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-125",
      "title": "An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. Parsing a maliciously crafted file may lead to an unexpected app termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43747"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-64711",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02389,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-285",
      "title": "This issue was addressed with additional entitlement checks. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to leak sensitive user information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64711"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-64723",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02389,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-284",
      "title": "A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64723"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-64776",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-125",
      "title": "The issue was addressed with improved bounds checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to disclose kernel memory.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64776"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-17534",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.0231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MoonshotAI",
      "product": "Kimi Code",
      "cwe": "CWE-918",
      "title": "Kimi Code FetchURL SSRF protection bypass via DNS-resolving hostnames and redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17534"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-20672",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-200",
      "title": "An information disclosure issue was addressed with improved privacy controls. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20672"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-43775",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-285",
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43775"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-43782",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-200",
      "title": "This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43782"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-17523",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 8",
      "cwe": "CWE-825",
      "title": "Kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17523"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-64707",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-732",
      "title": "A permissions issue was addressed with improved validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, visionOS 26.6. An app may be able to delete files for which it does not have permission.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64707"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-66437",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00119,
      "epss_percentile": 0.02112,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Themeisle",
      "product": "Feedzy",
      "cwe": "CWE-918",
      "title": "WordPress Feedzy plugin <= 5.2.4 - Server Side Request Forgery (SSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66437"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-64754",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.02012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-787",
      "title": "An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing a maliciously crafted file may lead to a denial-of-service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64754"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-43767",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.02015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-119",
      "title": "The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to cause unexpected system termination.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43767"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-43672",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00116,
      "epss_percentile": 0.01885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-863",
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious application may be able to bypass Privacy preferences.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43672"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-64737",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01841,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-284",
      "title": "An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64737"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-43756",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-200",
      "title": "A logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access user-sensitive data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43756"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-10682",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00114,
      "epss_percentile": 0.01774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in Zephyr `log_filter_set` syscall verifier reachable from userspace",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10682"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-17512",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00113,
      "epss_percentile": 0.01645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "whisper.cpp",
      "cwe": "CWE-119",
      "title": "ggml-org whisper.cpp log_mel_spectrogram out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17512"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-17513",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00112,
      "epss_percentile": 0.01596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "whisper.cpp",
      "cwe": "CWE-617",
      "title": "ggml-org whisper.cpp ggml.c ggml_ftype_to_ggml_type assertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17513"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2025-59180",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ericsson",
      "product": "Packet Core Controller (PCC)",
      "cwe": "CWE-798",
      "title": "Use of Hard-coded Credentials Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-59180"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-39874",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-276",
      "title": "A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. A malicious app may be able to gain root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39874"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-43806",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-400",
      "title": "A denial of service issue was addressed by removing the vulnerable code. This issue is fixed in macOS Tahoe 26.6. A local attacker may be able to cause a denial of service.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43806"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-64718",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "Safari",
      "cwe": "CWE-416",
      "title": "A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. Processing maliciously crafted web content may lead to an unexpected Safari crash.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64718"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-15003",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-125",
      "title": "Binutils: gnu binutils: heap-buffer-overflow in linker leads to information disclosure and denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15003"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-28849",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01274,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-290",
      "title": "The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Gatekeeper checks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28849"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-28900",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-290",
      "title": "A file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A maliciously crafted ZIP archive may bypass Gatekeeper checks.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28900"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-17573",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.01186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The HDF Group",
      "product": "HDF5",
      "cwe": "CWE-415",
      "title": "Double Free in H5D__chunk_copy() in HDF5 via a Crafted Chunk-Index Size Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17573"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-17574",
      "cvss_base": 5.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The HDF Group",
      "product": "HDF5",
      "cwe": "CWE-476",
      "title": "NULL Pointer Dereference in HDF5 via Invalid Variable-Length Datatype Type Tag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17574"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-17572",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "The HDF Group",
      "product": "HDF5",
      "cwe": "CWE-125",
      "title": "HDF5 SOHM List Index Heap Buffer Overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17572"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-43665",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00098,
      "epss_percentile": 0.00885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-862",
      "title": "This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. A local attacker may be able to determine the legacy VNC password configured for Screen Sharing.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43665"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-66428",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00098,
      "epss_percentile": 0.00881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jgwhite33",
      "product": "WP Google Review Slider",
      "cwe": "CWE-352",
      "title": "WordPress WP Google Review Slider plugin <= 18.4 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66428"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-66474",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00098,
      "epss_percentile": 0.00882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HT Plugins",
      "product": "Insert Headers and Footers Code – HT Script",
      "cwe": "CWE-352",
      "title": "WordPress Insert Headers and Footers Code – HT Script plugin <= 1.1.8 - Cross Site Request Forgery (CSRF) vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66474"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-43693",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00097,
      "epss_percentile": 0.00836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-362",
      "title": "A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43693"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-43781",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00095,
      "epss_percentile": 0.00755,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-362",
      "title": "A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43781"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-43770",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.00695,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-362",
      "title": "A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6, tvOS 26.6. An app may be able to access sensitive user data.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43770"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-28926",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00088,
      "epss_percentile": 0.00451,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-362",
      "title": "A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8. An app may be able to elevate privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28926"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-43755",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00087,
      "epss_percentile": 0.00435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "macOS",
      "cwe": "CWE-362",
      "title": "A race condition was addressed with improved state management. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43755"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-43811",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00087,
      "epss_percentile": 0.00422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apple",
      "product": "iOS and iPadOS",
      "cwe": "CWE-362",
      "title": "A race condition was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and iPadOS 26.6. An app may be able to modify protected parts of the file system.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43811"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-57916",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00085,
      "epss_percentile": 0.00378,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Asseco",
      "product": "proCertum SmartSign",
      "cwe": "CWE-73",
      "title": "Arbitrary Path Execution via CPS URI in proCertum SmartSign",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57916"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-14837",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00082,
      "epss_percentile": 0.00262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Lenze",
      "product": "c430",
      "cwe": "CWE-347",
      "title": "SSH Enablement Signature Verification Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14837"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10682",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10682 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10683",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10683 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17432",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17432 (NousResearch hermes-agent). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17433",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17433 (nanocoai NanoClaw). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17434",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17434 (nanocoai NanoClaw). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17457",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17457 (mf-yang openclaw-cn). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17458",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17458 (mf-yang openclaw-cn). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17459",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17459 (perwendel spark). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17573",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17573 (The HDF Group HDF5). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-40033",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-40033 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44421",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44421 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-44422",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-44422 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45623",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45623 (postcss). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47178",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47178 (strukturag libheif). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47247",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47247 (strukturag libheif). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47251",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47251 (strukturag libheif). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47254",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47254 (strukturag libheif). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47709",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47709 (strukturag libheif). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63097",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63097 (matrix-org dendrite). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63107",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63107 (LimeSurvey). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63108",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63108 (RooCodeInc Roo-Code). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63720",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63720 (koxudaxi datamodel-code-generator). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63731",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63731 (hyperdxio hyperdx). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63770",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63770 (glanceapp glance). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-63771",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-63771 (vrana adminer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-64824",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-64824 (home-assistant Home Assistant Core). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65708",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65708 (nuxsmin sysPass). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65709",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65709 (nuxsmin sysPass). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65710",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65710 (nuxsmin sysPass). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66757",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66757 (GNOME GIMP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66758",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66758 (GNOME GIMP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66759",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66759 (GNOME GIMP). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-40033",
      "detail": "RESCORED — CVE-2026-40033 (FreeRDP). CVSS 8.6 → 8.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-44422",
      "detail": "RESCORED — CVE-2026-44422 (FreeRDP). CVSS 7.5 → 8.8 (NVD)."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
