{
  "day": "2026-07-28",
  "boundary": "UTC calendar day",
  "published_count": 243,
  "by_severity": {
    "CRITICAL": 21,
    "HIGH": 117,
    "MEDIUM": 93,
    "LOW": 12
  },
  "kev_count": 0,
  "exploit_reference_count": 20,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-66713",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01829,
      "epss_percentile": 0.77123,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Axis2/Java",
      "cwe": "CWE-502",
      "title": "Apache Axis2/Java: deserialization of untrusted Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66713"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-59764",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01129,
      "epss_percentile": 0.63796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ELECOM CO.,LTD.",
      "product": "WRC-X3000GS3-B",
      "cwe": "CWE-78",
      "title": "ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59764"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-61376",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01129,
      "epss_percentile": 0.63795,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ELECOM CO.,LTD.",
      "product": "WAB-M1775-PS",
      "cwe": "CWE-78",
      "title": "ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61376"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-14959",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.01038,
      "epss_percentile": 0.61245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Aspera Faspex 5",
      "cwe": "CWE-78",
      "title": "OS Command Injection in IBM Aspera Faspex",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14959"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-59878",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00881,
      "epss_percentile": 0.56334,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ActiveMQ AMQP",
      "cwe": "CWE-20",
      "title": "Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All: AMQP NIO negative frame size validation bypass leading to DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59878"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-66748",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00805,
      "epss_percentile": 0.53948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "owen2345",
      "product": "camaleon-cms",
      "cwe": "CWE-94",
      "title": "Camaleon CMS 2.1.1 - 2.9.1 Authenticated RCE via select_eval Custom Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66748"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-17524",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00785,
      "epss_percentile": 0.53247,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "zip-lib",
      "cwe": "CWE-22",
      "title": "Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation during the extraction process. An attacker can bypass security checks designed to prevent directory traversal. The intended security function, isOutsideTargetFolder, only checks and caches the path status when the initial directory symlink is created during the first extraction.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17524"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-16585",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00734,
      "epss_percentile": 0.51571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wordplus",
      "product": "Better Messages – Chat Rooms, Group Chat, Private Messages & AI Chat Bots",
      "cwe": "CWE-22",
      "title": "Better Messages <= 2.15.19 - Authenticated (Administrator+) Arbitrary File Deletion via Path Traversal via 'file' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16585"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-59932",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00691,
      "epss_percentile": 0.50023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHPOffice",
      "product": "PhpSpreadsheet",
      "cwe": "CWE-400",
      "title": "PhpSpreadsheet: Gnumeric reader unbounded gzip expansion causes memory exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59932"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-59933",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00691,
      "epss_percentile": 0.50023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHPOffice",
      "product": "PhpSpreadsheet",
      "cwe": "CWE-400",
      "title": "PhpSpreadsheet: XLS/OLE sector-chain self-loop causes memory exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59933"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-59941",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00635,
      "epss_percentile": 0.47725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dompdf",
      "product": "dompdf",
      "cwe": "CWE-400",
      "title": "Dompdf: Uncontrolled resource consumption based on declared BMP dimensions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59941"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-59931",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00531,
      "epss_percentile": 0.42598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHPOffice",
      "product": "PhpSpreadsheet",
      "cwe": "CWE-918",
      "title": "PhpSpreadsheet: SSRF bypass via HTTP redirect in WEBSERVICE() domain whitelist",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59931"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-14512",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00523,
      "epss_percentile": 0.42173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-502",
      "title": "IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14512"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-14958",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0052,
      "epss_percentile": 0.42012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Aspera Faspex 5",
      "cwe": "CWE-78",
      "title": "OS command injection in IBM Aspera Faspex",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14958"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-15025",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00514,
      "epss_percentile": 0.41645,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uncannyowl",
      "product": "Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin",
      "cwe": "CWE-862",
      "title": "Uncanny Automator <= 7.3.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Integration Metadata Disclosure via Multiple AJAX Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15025"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-14490",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00509,
      "epss_percentile": 0.41311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deveasel",
      "product": "Demi – One Click Demo Import, Backup & Site Migration",
      "cwe": "CWE-22",
      "title": "Demi <= 0.0.6 - Unauthenticated Arbitrary Directory Deletion via demi_restore_step AJAX action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14490"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-55555",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00509,
      "epss_percentile": 0.41278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dompdf",
      "product": "dompdf",
      "cwe": "CWE-203",
      "title": "Dompdf: File existence oracle via font-face stylesheet declaration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55555"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-59942",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00495,
      "epss_percentile": 0.4045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dompdf",
      "product": "dompdf",
      "cwe": "CWE-400",
      "title": "Dompdf: Denial of Service (DoS) via Resource Exhaustion using Oversized Image Bitmaps",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59942"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-67178",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00493,
      "epss_percentile": 0.40328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "misp",
      "cwe": "CWE-601",
      "title": "Open Redirect in MISP Installer-Generated Apache Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67178"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-61487",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00486,
      "epss_percentile": 0.39941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache ActiveMQ Broker",
      "cwe": "CWE-285",
      "title": "Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authorization bypass via temporary composite destinations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61487"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-42492",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00477,
      "epss_percentile": 0.39375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-459",
      "title": "vIRQ event channel binding may break Xenstore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42492"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-42493",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00474,
      "epss_percentile": 0.39144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-400",
      "title": "x86 shadow paging is deprecated",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42493"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-59921",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00466,
      "epss_percentile": 0.38602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-93",
      "title": "Netty: CRLF Injection via Multipart Filename in Netty HttpPostRequestEncoder",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59921"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-47219",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00461,
      "epss_percentile": 0.38285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "delvedor",
      "product": "find-my-way",
      "cwe": "CWE-20",
      "title": "find-my-way is Vulnerable to DDoS with HTTP2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47219"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-15014",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00459,
      "epss_percentile": 0.38205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cozyvision1",
      "product": "SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery",
      "cwe": "CWE-288",
      "title": "SMS Alert <= 3.9.7 - Unauthenticated Authentication Bypass to Account Takeover via 'billing_phone' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15014"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-11841",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00458,
      "epss_percentile": 0.38091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SICK AG",
      "product": "InspectorP61x",
      "cwe": "CWE-552",
      "title": "CVE-2026-11841",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11841"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-65880",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00456,
      "epss_percentile": 0.37992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "balbooa.com",
      "product": "Balbooa Forms component for Joomla",
      "cwe": "CWE-94",
      "title": "Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65880"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-13161",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00454,
      "epss_percentile": 0.37815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themetechmount",
      "product": "TrueBooker – Appointment Booking and Scheduler System",
      "cwe": "CWE-89",
      "title": "TrueBooker <= 1.2.2 - Unauthenticated SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13161"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-54345",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00454,
      "epss_percentile": 0.37813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gopacket",
      "product": "gopacket",
      "cwe": "CWE-191",
      "title": "GoPacket's Diameter AVP decoder: uint32 underflow on vendor header size leads to unbounded ~4 GiB allocation (unauthenticated remote DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54345"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-67185",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.37761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeneralSandman",
      "product": "TinyWeb",
      "cwe": "CWE-22",
      "title": "TinyWeb 0.0.8 Path Traversal via URL Path Component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67185"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-11756",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00452,
      "epss_percentile": 0.37678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dassault Systèmes",
      "product": "Station Launcher App in 3DEXPERIENCE platform",
      "cwe": "CWE-502",
      "title": "Deserialization of Untrusted Data vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11756"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-14973",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00452,
      "epss_percentile": 0.37687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Aspera Desktop App",
      "cwe": "CWE-22",
      "title": "Path Traversal in IBM Desktop App",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14973"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-66299",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00451,
      "epss_percentile": 0.37634,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tomcat",
      "cwe": "CWE-400",
      "title": "Apache Tomcat: DoS via WebSocket chat example",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66299"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-56722",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00448,
      "epss_percentile": 0.37461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dompdf",
      "product": "dompdf",
      "cwe": "CWE-20",
      "title": "Dompdf: Local file read due to improper file path validation in SVG images encoded as data-URI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56722"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-54658",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0044,
      "epss_percentile": 0.3681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hypequery",
      "product": "hypequery",
      "cwe": "CWE-89",
      "title": "@hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54658"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-67184",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00432,
      "epss_percentile": 0.36144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeneralSandman",
      "product": "TinyWeb",
      "cwe": "CWE-476",
      "title": "TinyWeb 0.0.8 Null Pointer Dereference DoS via Malformed HTTP Request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67184"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-54332",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00429,
      "epss_percentile": 0.35957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gopacket",
      "product": "gopacket",
      "cwe": "CWE-770",
      "title": "GoPacket's sFlow ExtendedGatewayFlow decoder: unbounded attacker-controlled allocation (104-byte UDP datagram -> up to 16 GiB make) -> unauthenticated remote DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54332"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-54635",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0042,
      "epss_percentile": 0.35232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nessshon",
      "product": "tonapi",
      "cwe": "CWE-287",
      "title": "pytonapi has a Webhook Custom Path Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54635"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-16462",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00419,
      "epss_percentile": 0.35158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Weidmueller Interface",
      "product": "PROCON-WEB SCADA",
      "cwe": "CWE-89",
      "title": "SQL injection via unauthenticated GetGridData endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16462"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-67182",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00415,
      "epss_percentile": 0.34828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tomaka",
      "product": "rouille",
      "cwe": "CWE-444",
      "title": "Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Header Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67182"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-47427",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "github",
      "product": "github-mcp-server",
      "cwe": "CWE-476",
      "title": "GitHub MCP Server: Nil Pointer Dereference DoS in completion/complete Handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47427"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-66754",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00401,
      "epss_percentile": 0.33529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tomaka",
      "product": "rouille",
      "cwe": "CWE-617",
      "title": "Rouille 0.1.6 - 3.6.2 Reachable Assertion DoS via remove_prefix percent-encoding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66754"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-21047",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.32984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Samsung Mobile",
      "product": "Samsung Mobile Devices",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in ImsService prior to SMR Jul-2026 Release 1 allows remote attackers to potentially execute arbitrary code.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21047"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-61609",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.32726,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pterodactyl",
      "product": "panel",
      "cwe": "CWE-770",
      "title": "Pterodactyl's shared global rate-limit key on login and 2FA checkpoint enables unauthenticated panel-wide authentication lockout (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61609"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-63303",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00391,
      "epss_percentile": 0.32422,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSolution",
      "product": "Quick.CMS",
      "cwe": "CWE-23",
      "title": "Path Traversal in Quick.CMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63303"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-67174",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00385,
      "epss_percentile": 0.31875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pivotick",
      "product": "pivotick",
      "cwe": "CWE-79",
      "title": "DOM-Based Cross-Site Scripting via Unsafe String and SVG Icon Rendering in Pivotick",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67174"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-65624",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00383,
      "epss_percentile": 0.31627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ninenines",
      "product": "cowboy",
      "cwe": "CWE-770",
      "title": "Cowboy HTTP/1.1 max_headers Bypass via Duplicate Header Names Enables Memory Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65624"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-14974",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00378,
      "epss_percentile": 0.31083,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-502",
      "title": "IBM WebSphere Application Server is affected by cross-site scripting and deserialization vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14974"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-14328",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.30814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eazyplugins",
      "product": "Eazy Plugin Manager – Powerful Plugin Management Solution for WordPress",
      "cwe": "CWE-269",
      "title": "Eazy Plugin Manager <= 4.4.1 - Authenticated (Subscriber+) Privilege Escalation via pos_get_option AJAX Action and admin/login REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14328"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-62431",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.30764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-369",
      "title": "Viridian STIMER division by zero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62431"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-55389",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00374,
      "epss_percentile": 0.30684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "koxudaxi",
      "product": "datamodel-code-generator",
      "cwe": "CWE-22",
      "title": "datamodel-code-generator vulnerable to arbitrary local file read via JSON-Schema `$ref` (`file://` and `../` traversal), bypassing `--no-allow-remote-refs`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55389"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-54653",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00369,
      "epss_percentile": 0.30124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "koxudaxi",
      "product": "datamodel-code-generator",
      "cwe": "CWE-94",
      "title": "`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54653"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-54659",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00368,
      "epss_percentile": 0.30043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ddnexus",
      "product": "pagy",
      "cwe": "CWE-22",
      "title": "Pagy I18n locale option is not validated before being used in a file path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54659"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-67183",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00367,
      "epss_percentile": 0.29962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GeneralSandman",
      "product": "TinyWeb",
      "cwe": "CWE-401",
      "title": "TinyWeb 0.0.8 Memory Leak DoS via HTTP Request Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67183"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-54650",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.2934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bablilayoub",
      "product": "openhole",
      "cwe": "CWE-22",
      "title": "openhole-server vulnerable to path traversal via URL-decoded request path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54650"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-55390",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.2934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "koxudaxi",
      "product": "datamodel-code-generator",
      "cwe": "CWE-22",
      "title": "Arbitrary local file read via XSD `schemaLocation` (`xs:include`/`xs:import`) path traversal, with no remote-ref gate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55390"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-63301",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00361,
      "epss_percentile": 0.293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSolution",
      "product": "Quick.CMS",
      "cwe": "CWE-602",
      "title": "Denial of Service in Quick.CMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63301"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-8058",
      "cvss_base": 4.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00358,
      "epss_percentile": 0.29028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "OPENBMC",
      "cwe": "CWE-200",
      "title": "This Power System update is being released to address a sensitive information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8058"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-54593",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00357,
      "epss_percentile": 0.28971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pterodactyl",
      "product": "panel",
      "cwe": "CWE-1259",
      "title": "Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54593"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-6879",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00355,
      "epss_percentile": 0.28769,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Software Foundation",
      "product": "CPython",
      "cwe": "CWE-407",
      "title": "Quadratic Behavior in xml.etree.ElementPath Index Predicates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6879"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-54638",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27746,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gotd",
      "product": "td",
      "cwe": "CWE-770",
      "title": "td has pre-auth denial of service via unbounded memory allocation in proto.UnencryptedMessage.Decode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54638"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-62325",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00344,
      "epss_percentile": 0.27544,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goshs-labs",
      "product": "goshs",
      "cwe": "CWE-306",
      "title": "goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62325"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-67173",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00341,
      "epss_percentile": 0.27246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pivotick",
      "product": "pivotick",
      "cwe": "CWE-918",
      "title": "Pivotick Unvalidated Node Image URLs Allow Unintended Client-Side Requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67173"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-5114",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0034,
      "epss_percentile": 0.27124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "softaculous",
      "product": "SpeedyCache – Cache, Optimization, Performance",
      "cwe": "CWE-22",
      "title": "SpeedyCache <= 1.3.8 - Authenticated (Administrator+) Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5114"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-57510",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "superplanehq",
      "product": "superplane",
      "cwe": "CWE-639",
      "title": "SuperPlane < 0.27.0 Broken Object Level Authorization via CanvasService gRPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57510"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-64863",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00337,
      "epss_percentile": 0.26688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goshs-labs",
      "product": "goshs",
      "cwe": "CWE-284",
      "title": "goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64863"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-15280",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server - Liberty",
      "cwe": "CWE-22",
      "title": "IBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15280"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-14893",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00334,
      "epss_percentile": 0.26442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Observability with Instana (Agent)",
      "cwe": "CWE-1321",
      "title": "IBM Instana Observability is affected by multiple Prototype Pollution within Instana Agent container image",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14893"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-16498",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0033,
      "epss_percentile": 0.26005,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Tooling",
      "cwe": "CWE-488",
      "title": "terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16498"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-15673",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00328,
      "epss_percentile": 0.25743,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cozyvision1",
      "product": "SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery",
      "cwe": "CWE-89",
      "title": "SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'checkout_payment_plans' and 'order_status' Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15673"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-62434",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00327,
      "epss_percentile": 0.25646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-787",
      "title": "PoD: Don't try to reclaim special pages",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62434"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-16184",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00322,
      "epss_percentile": 0.25149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-862",
      "title": "IBM WebSphere Application Server is affected by an authentication bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16184"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-15012",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00317,
      "epss_percentile": 0.2457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "deveasel",
      "product": "Demi – One Click Demo Import, Backup & Site Migration",
      "cwe": "CWE-200",
      "title": "Demi <= 0.0.8 - Unauthenticated Information Exposure to Arbitrary Directory Copy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15012"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-66745",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArticaTech",
      "product": "Artica Proxy",
      "cwe": "CWE-94",
      "title": "Artica Proxy 4.50 Session Fixation via fw.login.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66745"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-66749",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sdelements",
      "product": "lets-chat",
      "cwe": "CWE-476",
      "title": "Let's Chat 0.4.0 - 0.4.8 Denial of Service via Null Dereference in Room Lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66749"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-66064",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00308,
      "epss_percentile": 0.23566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goshs-labs",
      "product": "goshs",
      "cwe": "CWE-41",
      "title": "goshs has ACL Bypass & Path Traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66064"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-47483",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00307,
      "epss_percentile": 0.23349,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NVIDIA",
      "product": "DCGM",
      "cwe": "CWE-770",
      "title": "NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests. A successful exploit of this vulnerability might lead to denial of service and information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47483"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-63302",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.23377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSolution",
      "product": "Quick.CMS",
      "cwe": "CWE-98",
      "title": "Local File Inclusion in Quick.CMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63302"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-14976",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00305,
      "epss_percentile": 0.23175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server - Liberty",
      "cwe": "CWE-306",
      "title": "IBM WebSphere Application Server Liberty is affected by a remote code execution and path-segment injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14976"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-10207",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.2312,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pickplugins",
      "product": "PickPlugins Question Answer",
      "cwe": "CWE-89",
      "title": "PickPlugins Question Answer <= 1.2.73 - Unauthenticated SQL Injection via 'id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10207"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-12741",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23119,
      "kev": false,
      "kev_due_at": null,
      "vendor": "epsiloncool",
      "product": "WP Fast Total Search – The Power of Indexed Search",
      "cwe": "CWE-89",
      "title": "WP Fast Total Search <= 1.80.280 - Unauthenticated SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12741"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-12800",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.2312,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codename065",
      "product": "Premium Packages – Sell Digital Products Securely",
      "cwe": "CWE-89",
      "title": "Premium Packages <= 6.2.0 - Unauthenticated SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12800"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-14785",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mihail-chepovskiy",
      "product": "Web Directory Free",
      "cwe": "CWE-89",
      "title": "Web Directory Free <= 1.7.13 - Unauthenticated SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14785"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-50738",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EnterpriseDB",
      "product": "pglogical",
      "cwe": "CWE-416",
      "title": "A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced after the underlying slot has been freed or recycled during normal worker lifecycle events. The condition is reachable during normal replication operation, including by a low-privileged user able to influence worker start, stop, and restart timing through permitted pglogical operations. In the typical case the condition crashes replication workers, causing an availability impact. In the worst case a use-after-free in a PostgreSQL backend can be leveraged as a remote code execution primitive at the privilege of that backend.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50738"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-14869",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.21868,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Tooling",
      "cwe": "CWE-918",
      "title": "terraform-mcp-server vulnerable to server side request forgery leading to token exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14869"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-14446",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00292,
      "epss_percentile": 0.21788,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-306",
      "title": "IBM WebSphere Application Server is affected by a privilege escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14446"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-55415",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "koxudaxi",
      "product": "datamodel-code-generator",
      "cwe": "CWE-94",
      "title": "datamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statements",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55415"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-67181",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21759,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tomaka",
      "product": "rouille",
      "cwe": "CWE-444",
      "title": "Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Transfer-Encoding Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67181"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-59248",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21731,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ninenines",
      "product": "cowlib",
      "cwe": "CWE-770",
      "title": "Unbounded HPACK/QPACK prefixed-integer decoding in Cowlib causes memory-exhaustion DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59248"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-48025",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.2173,
      "kev": false,
      "kev_due_at": null,
      "vendor": "juev",
      "product": "nebula-mesh",
      "cwe": "CWE-244",
      "title": "nebula-mesh: Decrypted CA private key persists in heap after signing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48025"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-14516",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.21562,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ladela",
      "product": "Online Scheduling and Appointment Booking System – Bookly",
      "cwe": "CWE-89",
      "title": "Online Scheduling and Appointment Booking System <= 27.5 - Unauthenticated SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14516"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-1918",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00289,
      "epss_percentile": 0.21522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Sterling B2B Integrator",
      "cwe": "CWE-532",
      "title": "IBM Sterling B2B Integrator and IBM Sterling File Gateway store sensitive information in a log file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1918"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-14169",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00288,
      "epss_percentile": 0.21333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ads-tec Industrial IT",
      "product": "DVG-IRF1401",
      "cwe": "CWE-696",
      "title": "ads-tec Industrial IT: Account lockout via non-atomic user creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14169"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-15444",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "themeum",
      "product": "Tutor LMS – eLearning and online course solution",
      "cwe": "CWE-89",
      "title": "Tutor LMS <= 4.0.1 - Authenticated (Administrator+) SQL Injection via 'coupon_code' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15444"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-15671",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00288,
      "epss_percentile": 0.21348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cozyvision1",
      "product": "SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery",
      "cwe": "CWE-89",
      "title": "SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15671"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-48060",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.20982,
      "kev": false,
      "kev_due_at": null,
      "vendor": "litestar-org",
      "product": "litestar",
      "cwe": "CWE-79",
      "title": "Litestar: HTML Injection Through CSRF Token",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48060"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-66922",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00284,
      "epss_percentile": 0.20977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pivotick",
      "product": "pivotick",
      "cwe": "CWE-1321",
      "title": "Pivotick Prototype-Key Collision in Tree Layout and Cycle Detection Allows Graph Manipulation and Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66922"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-49258",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20838,
      "kev": false,
      "kev_due_at": null,
      "vendor": "juev",
      "product": "nebula-mesh",
      "cwe": "CWE-639",
      "title": "Nebula Mesh: Web UI lacks ownership checks, enabling cross-operator access to hosts and networks (read, block, delete)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49258"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-54719",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00283,
      "epss_percentile": 0.20906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goshs-labs",
      "product": "goshs",
      "cwe": "CWE-862",
      "title": "goshs: File-based .goshs ACL authorization bypass via the ?bulk zip-download route (unauthenticated read; residual of CVE-2026-40189)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54719"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-7521",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00283,
      "epss_percentile": 0.20923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mattermost",
      "product": "Mattermost",
      "cwe": "CWE-22",
      "title": "SAML certificate deletion allows path traversal to delete arbitrary files outside the config directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7521"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-49332",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat OpenShift Container Platform 4.14",
      "cwe": "CWE-436",
      "title": "Openshift/oauth-proxy: openshift/oauth-proxy: underscore header smuggling enables identity impersonation on wsgi/php upstreams",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49332"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-18047",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00281,
      "epss_percentile": 0.20701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Certificate System 10",
      "cwe": "CWE-288",
      "title": "Dogtag-pki: pki-core: redhat-pki: pki: acme admin enable/disable endpoint authentication bypass via trailing slash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18047"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-55554",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00278,
      "epss_percentile": 0.20355,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dompdf",
      "product": "dompdf",
      "cwe": "CWE-20",
      "title": "Dompdf: Chroot Validation Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55554"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-14545",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00277,
      "epss_percentile": 0.20209,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "TrueBooker",
      "cwe": "CWE-269",
      "title": "TrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via Password Reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14545"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-14168",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.20178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ads-tec Industrial IT",
      "product": "DVG-IRF1401",
      "cwe": "CWE-862",
      "title": "ads-tec Industrial IT: Vertical privilege escalation via configuration table write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14168"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-14167",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.20179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ads-tec Industrial IT",
      "product": "DVG-IRF1401",
      "cwe": "CWE-863",
      "title": "ads-tec Industrial IT: Privilege escalation during configuration import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14167"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-66918",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.20212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pivotick",
      "product": "pivotick",
      "cwe": "CWE-79",
      "title": "DOM-Based Cross-Site Scripting via Unsanitized SVG Node Icons",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66918"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-66921",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20212,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pivotick",
      "product": "pivotick",
      "cwe": "CWE-79",
      "title": "Pivotick - Stored DOM-Based Cross-Site Scripting via Unescaped Markdown Node References",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66921"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-7769",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20022,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Sterling B2B Integrator",
      "cwe": "CWE-89",
      "title": "SQL injection Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7769"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2024-14041",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00275,
      "epss_percentile": 0.19942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-208",
      "title": "ML-KEM (Kyber) decapsulation leaks private key information through non-constant-time division in message decoding and ciphertext compression (KyberSlash)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-14041"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-15992",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00274,
      "epss_percentile": 0.19865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "teydeastudio",
      "product": "WP Password Policy",
      "cwe": "CWE-269",
      "title": "WP Password Policy <= 3.7.1 - Authenticated (Subscriber+) Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15992"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-16496",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00273,
      "epss_percentile": 0.19704,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Tooling",
      "cwe": "CWE-384",
      "title": "terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session ID is obtained by another user",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16496"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-16773",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00273,
      "epss_percentile": 0.19796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quantumcloud",
      "product": "WPBot – AI ChatBot for Live Support, Lead Generation, AI Services",
      "cwe": "CWE-200",
      "title": "WPBot <= 8.5.9 - Unauthenticated Sensitive Information Exposure in 'wpbot_send_email_transcript' AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16773"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-54603",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ruby-oauth",
      "product": "oauth2",
      "cwe": "CWE-200",
      "title": "OAuth2::Client#request: Protocol-relative redirect Location overrides authority, leaking bearer Authorization to attacker host",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54603"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-15670",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cozyvision1",
      "product": "SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery",
      "cwe": "CWE-89",
      "title": "SMS Alert <= 3.9.7 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15670"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-16811",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "devitemsllc",
      "product": "ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin",
      "cwe": "CWE-89",
      "title": "ShopLentor <= 3.4.5 - Authenticated (Administrator+) SQL Injection via 'orderby' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16811"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-13440",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.18521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wedevs",
      "product": "StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce",
      "cwe": "CWE-79",
      "title": "StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Unauthenticated Stored Cross-Site Scripting via 'message_popup' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13440"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-54609",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Quiet-Terminal-Interactive",
      "product": "QTINeon",
      "cwe": "CWE-400",
      "title": "QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54609"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-14981",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-400",
      "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14981"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-15057",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server - Liberty",
      "cwe": "CWE-787",
      "title": "IBM WebSphere Application Server Liberty is affected by a denial of service vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15057"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-62433",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-665",
      "title": "correct buffer checks for DM_OP hypercalls",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62433"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-16192",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server - Liberty",
      "cwe": "CWE-674",
      "title": "IBM WebSphere Application Server Liberty is affected by a denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16192"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-66750",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sdelements",
      "product": "lets-chat",
      "cwe": "CWE-862",
      "title": "Let's Chat 0.3.0 - 0.4.8 Broken Access Control File Disclosure via GET /files route",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66750"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-66919",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.18153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pivotick",
      "product": "Pivotick",
      "cwe": "CWE-79",
      "title": "Stored DOM-Based Cross-Site Scripting in Node Modal Headers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66919"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-15267",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00261,
      "epss_percentile": 0.1805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "taskbuilder",
      "product": "Taskbuilder – Project Management & Task Management Tool With Kanban Board",
      "cwe": "CWE-89",
      "title": "Taskbuilder <= 5.0.9 - Authenticated (Subscriber+) SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15267"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-63727",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0026,
      "epss_percentile": 0.17894,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Anchore",
      "product": "Anchore Enterprise",
      "cwe": "CWE-648",
      "title": "Anchore Enterprise Privilege Escalation via User Management API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63727"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-15411",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0026,
      "epss_percentile": 0.17968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wedevs",
      "product": "StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce",
      "cwe": "CWE-862",
      "title": "StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Missing Authorization to Unauthenticated Options Update via create_popup AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15411"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-14528",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-532",
      "title": "IBM WebSphere Application Server is affected by an unsafe deserialization and exposure of sensitive information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14528"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-59943",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00258,
      "epss_percentile": 0.17711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dompdf",
      "product": "dompdf",
      "cwe": "CWE-209",
      "title": "Dompdf: Embedded SVG images can leak existence of files and directories within the filesystem",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59943"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-66920",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.1699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Pivotick",
      "product": "Pivotick",
      "cwe": "CWE-400",
      "title": "Pivotick - Stack Exhaustion Denial of Service via Deep or Cyclic Graph Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66920"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-14924",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.17027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Tablesome Table",
      "cwe": "CWE-862",
      "title": "Tablesome < 1.1.31 - Unauthenticated Post Creation and Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14924"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-66913",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.16992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lookyloo",
      "product": "lookyloo",
      "cwe": "CWE-400",
      "title": "Zip Bomb in Lookyloo Capture Upload Allows Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66913"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-62430",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-362",
      "title": "x86: Out-of-bounds read in vRTC emulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62430"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-16771",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AT&T",
      "product": "Arris BGW210‑700",
      "cwe": "CWE-306",
      "title": "CVE-2026-16771",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16771"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-15393",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cozythemes",
      "product": "Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates",
      "cwe": "CWE-79",
      "title": "Cozy Blocks <= 2.2.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'postMeta.font.size' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15393"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-62427",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-284",
      "title": "sysctl and platform-op locks open to abuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62427"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-6251",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Chaty",
      "product": "Chaty Pro",
      "cwe": "CWE-89",
      "title": "Chaty Pro <= 3.5.5 - Authenticated (Subscriber+) SQL Injection via 'widget_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6251"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-15304",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "foomagoo",
      "product": "Plugin Organizer",
      "cwe": "CWE-89",
      "title": "Plugin Organizer <= 10.2.4 - Authenticated (Subscriber+) SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15304"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-65881",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomdle.com",
      "product": "Joomdle component for Joomla",
      "cwe": "CWE-1188",
      "title": "Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65881"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-16313",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-93",
      "title": "Sg3_utils: sg3_utils: arbitrary command execution via udev property injection in sg_inq --export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16313"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-66746",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.1555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tomaka",
      "product": "rouille",
      "cwe": "CWE-113",
      "title": "Rouille 0.4.0 - 3.6.2 HTTP Response Splitting via Header Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66746"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-9680",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Alibaba",
      "product": "Alibaba Cloud RDS OpenAPI MCP Server",
      "cwe": "CWE-1188",
      "title": "MCP Server Exposure via Insecure Default Binding on alibabacloud-rds-openapi-mcp-server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9680"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-4912",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tigroumeow",
      "product": "Media Cleaner: Clean your WordPress!",
      "cwe": "CWE-918",
      "title": "Media Cleaner: Clean your WordPress! <= 7.0.3 - Authenticated (Administrator+) Server-Side Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4912"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-43910",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15283,
      "kev": false,
      "kev_due_at": null,
      "vendor": "appium",
      "product": "java-client",
      "cwe": "CWE-441",
      "title": "Appium java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43910"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-47726",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00238,
      "epss_percentile": 0.15099,
      "kev": false,
      "kev_due_at": null,
      "vendor": "juev",
      "product": "nebula-mesh",
      "cwe": "CWE-285",
      "title": "nebula-mesh: GET /api/v1/audit-log discloses all entries to any operator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47726"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-66752",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tiny-http",
      "product": "tiny-http",
      "cwe": "CWE-444",
      "title": "tiny-http 0.12.0 HTTP Request Smuggling via Transfer-Encoding Handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66752"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-57511",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "superplanehq",
      "product": "superplane",
      "cwe": "CWE-93",
      "title": "SuperPlane < 0.30.0 SMTP Header Injection via Webhook Event Title",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57511"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-62828",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14655,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge for Android",
      "cwe": "CWE-20",
      "title": "Microsoft Edge for Android (Chromium-based) Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62828"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-13110",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.1467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wedevs",
      "product": "StoreGrowth – Upsell, BOGO, Quick View, Direct Checkout & Side Cart for WooCommerce",
      "cwe": "CWE-862",
      "title": "StoreGrowth: Smart Sales Booster for WooCommerce | BOGO, Upsells, Direct Checkout, Quick View, Side Cart <= 2.1.0 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Modification via bogo_category_msg_create AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13110"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-16774",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "quantumcloud",
      "product": "WPBot – AI ChatBot for Live Support, Lead Generation, AI Services",
      "cwe": "CWE-862",
      "title": "WPBot <= 8.5.9 - Missing Authorization to Unauthenticated Email Relay via wpcs_send_email AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16774"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-16347",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00233,
      "epss_percentile": 0.145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MikroTik",
      "product": "RouterOS",
      "cwe": "CWE-307",
      "title": "Improper restriction of excessive authentication attempts in MikroTik RouterOS and Cloud Hosted Router",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16347"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-62429",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.1444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-362",
      "title": "vNUMA domain cleanup may race other operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62429"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-66063",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.14414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "goshs-labs",
      "product": "goshs",
      "cwe": "CWE-22",
      "title": "goshs has a Path Traversal issue",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66063"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-15328",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-444",
      "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty is inconsistent Interpretation of HTTP Requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15328"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-62426",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-412",
      "title": "sysctl and platform-op locks open to abuse",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62426"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-14996",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00225,
      "epss_percentile": 0.13418,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Aspera Faspex 5",
      "cwe": "CWE-613",
      "title": "Multiple vulnerabilities in IBM Aspera Faspex",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14996"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-16581",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.1346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "igloohome",
      "product": "Smart Lock Mobile Application",
      "cwe": "CWE-540",
      "title": "Inclusion of sensitive information in source code in igloohome Smart Lock Mobile Application",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16581"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-13463",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.13351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Cloud Pak System",
      "cwe": "CWE-798",
      "title": "Due to use of IBM Storage Protect, IBM Cloud Pak System is affected by vulnerability []",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13463"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-49447",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "azukaar",
      "product": "Cosmos-Server",
      "cwe": "CWE-287",
      "title": "Cosmos-Server's constellation public-devices endpoint accepts arbitrary bearer tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49447"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-16587",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nasirahmed",
      "product": "Advanced Form Integration — Connect Forms to 200+ Apps",
      "cwe": "CWE-862",
      "title": "Advanced Form Integration <= 2.6.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary MailUp OAuth Token Overwrite via auth_redirect() Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16587"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-18038",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00222,
      "epss_percentile": 0.13041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nextlevelbuilder",
      "product": "GoClaw",
      "cwe": "CWE-200",
      "title": "nextlevelbuilder GoClaw jq Handler tools_invoke.go ExecTool.Execute information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18038"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-15064",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0022,
      "epss_percentile": 0.12782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-444",
      "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15064"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-3157",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Sterling B2B Integrator",
      "cwe": "CWE-615",
      "title": "Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure in mailbox UI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3157"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-66753",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.1254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tiny-http",
      "product": "tiny-http",
      "cwe": "CWE-113",
      "title": "tiny-http 0.12.0 HTTP Response Splitting via Header Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66753"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-17528",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "nice-select2",
      "cwe": "CWE-79",
      "title": "Versions of the package nice-select2 before 2.4.1 are vulnerable to Cross-site Scripting (XSS) via the <select> element. An attacker can supply a malicious payload that is rendered directly into the DOM without proper sanitization, causing arbitrary script execution in a victim’s browser when they view or interact with the affected page.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17528"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-16797",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12534,
      "kev": false,
      "kev_due_at": null,
      "vendor": "devitemsllc",
      "product": "ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin",
      "cwe": "CWE-639",
      "title": "ShopLentor <= 3.4.5 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Information Exposure via 'optionSection' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16797"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-54690",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00216,
      "epss_percentile": 0.12354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "koxudaxi",
      "product": "datamodel-code-generator",
      "cwe": "CWE-918",
      "title": "datamodel-code-generator vulnerable to SSRF via JSON-Schema `$ref` to HTTP URL (silent by default)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54690"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-15730",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rubengc",
      "product": "GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress",
      "cwe": "CWE-79",
      "title": "GamiPress <= 7.9.9.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'heading_size' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15730"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-7187",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.12244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Universal Software Inc.",
      "product": "UKBS",
      "cwe": "CWE-306",
      "title": "Improper Authentication in Universal Sotware's UKBS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7187"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-66751",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sdelements",
      "product": "lets-chat",
      "cwe": "CWE-862",
      "title": "Let's Chat 0.3.0 - 0.4.8 Improper Authorization via DELETE /rooms/:room",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66751"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-62432",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-362",
      "title": "evtchn: Race between FIFO expand and reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62432"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-55403",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00211,
      "epss_percentile": 0.11718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "koxudaxi",
      "product": "datamodel-code-generator",
      "cwe": "CWE-200",
      "title": "datamodel-code-generator: Authorization / request headers leaked to cross-origin redirect target when fetching remote schemas",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55403"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-11598",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lrnz",
      "product": "Shortcodify",
      "cwe": "CWE-79",
      "title": "Shortcodify <= 1.4.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'name' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11598"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-54691",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00209,
      "epss_percentile": 0.1141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "koxudaxi",
      "product": "datamodel-code-generator",
      "cwe": "CWE-918",
      "title": "datamodel-code-generator vulnerable to SSRF via --url: no host/IP validation, follows redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54691"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-12124",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpeverest",
      "product": "PDFDraft – Drag & Drop PDF Builder, PDF Viewer, Embed & Download PDF, Certificate & Invoice Designer",
      "cwe": "CWE-862",
      "title": "PDFDraft <= 1.1.0 - Missing Authorization to Unauthenticated Sensitive PDF Disclosure via 'slug' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12124"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-15325",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00208,
      "epss_percentile": 0.11252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-444",
      "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15325"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-18029",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11171,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix GmbH",
      "product": "pretix-girosolution",
      "cwe": "CWE-841",
      "title": "Insufficient validation of payment status in pretix-girosolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18029"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-18028",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00207,
      "epss_percentile": 0.11121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pretix GmbH",
      "product": "pretix",
      "cwe": "CWE-639",
      "title": "Missing authorization check in event quick setup view",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18028"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-42495",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.1086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-191",
      "title": "buffer overruns in libfsimage iso9660 handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42495"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-62423",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.1086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-130",
      "title": "buffer overruns in libfsimage iso9660 handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62423"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-62424",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.1086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-130",
      "title": "buffer overruns in libfsimage iso9660 handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62424"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-62425",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.1086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-20",
      "title": "buffer overruns in libfsimage iso9660 handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62425"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-6881",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00203,
      "epss_percentile": 0.10652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ellucian",
      "product": "Advance Web",
      "cwe": "CWE-89",
      "title": "Authenticated SQL Injection Enables Unauthorized Access to Sensitive Information in Ellucian Advance Web and Legacy Advance",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6881"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-62435",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09632,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-362",
      "title": "grant-table: version change racing with other operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62435"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-62436",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-362",
      "title": "grant-table: version change racing with other operations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62436"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-50736",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00194,
      "epss_percentile": 0.09494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EnterpriseDB",
      "product": "pglogical",
      "cwe": "CWE-89",
      "title": "The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads on the subscriber at the privilege level of the apply worker, which is equivalent to a PostgreSQL superuser in default installations. A party acting as the publisher can send crafted queue messages that cause arbitrary SQL to be executed on the subscriber as superuser, escalating from a role permitted to use pglogical to full superuser and breaking the isolation between tenants in shared deployments. To exploit the issue an attacker must be able to direct a subscription at an endpoint they control. In default installations this requires privileges normally reserved for a superuser, so the issue is most relevant to managed deployments where the ability to create subscriptions has been delegated to non-superuser roles.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50736"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-50737",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00194,
      "epss_percentile": 0.09493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EnterpriseDB",
      "product": "pglogical",
      "cwe": "CWE-250",
      "title": "When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressions on the subscriber. Because the apply worker runs at a privilege level equivalent to a PostgreSQL superuser in default installations, any function invoked by such a default expression also runs at that privilege. A party acting as the publisher can use this path to cause functions to be executed on the subscriber as superuser, escalating from a role permitted to use pglogical to full superuser. This is a second, independent path to the same superuser escalation tracked under CVE-2026-50736 (the pglogical queue issue). To exploit the issue an attacker must be able to direct a subscription at an endpoint they control. In default installations this requires privileges normally reserved for a superuser, so the issue is most relevant to managed deployments where the ability to create subscriptions has been delegated to non-superuser roles.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50737"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-50735",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09493,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EnterpriseDB",
      "product": "pglogical",
      "cwe": "CWE-125",
      "title": "pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol messages before copying them, resulting in an out-of-bounds read. A party acting as the publisher for a subscription, for example a non-PostgreSQL endpoint that speaks the pglogical replication protocol, can return crafted messages that cause the subscriber's apply worker to read beyond the bounds of an allocated buffer, disclosing adjacent process memory or crashing the worker. To exploit the issue an attacker must be able to direct a subscription at an endpoint they control. In default installations this requires privileges normally reserved for a superuser, so the issue is most relevant to managed deployments where the ability to create subscriptions has been delegated to non-superuser roles.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50735"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-55391",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00193,
      "epss_percentile": 0.09346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "koxudaxi",
      "product": "datamodel-code-generator",
      "cwe": "CWE-350",
      "title": "datamodel-code-generator vulnerable to SSRF protection bypass via DNS rebinding",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55391"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-48058",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "juev",
      "product": "nebula-mesh",
      "cwe": "CWE-614",
      "title": "nebula-mesh: Session and OIDC state cookies lack the Secure attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48058"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-48374",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.08986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Bridge",
      "cwe": "CWE-22",
      "title": "Bridge | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48374"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-48372",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08578,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Format Plugins",
      "cwe": "CWE-787",
      "title": "Format Plugins | Heap-based Buffer Overflow (CWE-122)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48372"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-11391",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tanium",
      "product": "Patch",
      "cwe": "CWE-89",
      "title": "Tanium addressed a SQL injection vulnerability in Patch.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11391"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-45293",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.08354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WordPress",
      "product": "WordPress-Coding-Standards",
      "cwe": "CWE-95",
      "title": "WordPress Coding Standards (WordPressCS) contains an arbitrary code execution vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45293"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-14171",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08248,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ads-tec Industrial IT",
      "product": "DVG-IRF1401",
      "cwe": "CWE-601",
      "title": "ads-tec Industrial IT: Post-login open redirect in the web interface",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14171"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-3158",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Sterling B2B Integrator",
      "cwe": "CWE-615",
      "title": "Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway due to information disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3158"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-7362",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.0763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Sterling B2B Integrator",
      "cwe": "CWE-284",
      "title": "Improper Access Control Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7362"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-14515",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-79",
      "title": "IBM WebSphere Application Server is affected by cross-site scripting and deserialization vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14515"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-13442",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.07168,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-520",
      "title": "Langflow is affected by NET Misconfiguration: Use of Impersonation due to multiple unauthenticated and insufficiently authorized API endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13442"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-7868",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "OPENBMC",
      "cwe": "CWE-863",
      "title": "This Power System update is being released to address incorrect authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7868"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-48388",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Photoshop Installer",
      "cwe": "CWE-427",
      "title": "Photoshop Installer | CWE-427: Uncontrolled Search Path Element",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48388"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-54656",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00171,
      "epss_percentile": 0.06834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "koxudaxi",
      "product": "datamodel-code-generator",
      "cwe": "CWE-94",
      "title": "`datamodel-code-generator` vulnerable to code execution on import via unescaped `validators` entries in --extra-template-data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54656"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-48395",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00169,
      "epss_percentile": 0.06706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Bridge",
      "cwe": "CWE-426",
      "title": "Bridge | Untrusted Search Path (CWE-426)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48395"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-14821",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00168,
      "epss_percentile": 0.06602,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Quiz and Survey Master (QSM)",
      "cwe": "CWE-862",
      "title": "Quiz And Survey Master < 11.1.5 - Contributor+ Arbitrary Template Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14821"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-48396",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.0574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Bridge",
      "cwe": "CWE-863",
      "title": "Bridge | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48396"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-16107",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00159,
      "epss_percentile": 0.05563,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "TS4500 CLI tool",
      "cwe": "CWE-295",
      "title": "TS4500 CLI tool addresses security vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16107"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-18085",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BlackBerry",
      "product": "UEM",
      "cwe": "CWE-74",
      "title": "Improper Input Validation Leads to Arbitrary File Download and Potential Denial of Service in BlackBerry UEM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18085"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-15016",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "strangerstudios",
      "product": "Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions",
      "cwe": "CWE-79",
      "title": "Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions <= 3.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15016"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-48391",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00155,
      "epss_percentile": 0.05188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Bridge",
      "cwe": "CWE-426",
      "title": "Bridge | Untrusted Search Path (CWE-426)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48391"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-47725",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "juev",
      "product": "nebula-mesh",
      "cwe": "CWE-352",
      "title": "nebula-mesh: Web UI lacks CSRF tokens on /ui/* mutating endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47725"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-44387",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.04687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ELECOM CO.,LTD.",
      "product": "WAB-M1775-PS",
      "cwe": "CWE-79",
      "title": "ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44387"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-58246",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0015,
      "epss_percentile": 0.0475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SAP_SE",
      "product": "SAP NetWeaver Application Server for ABAP",
      "cwe": "CWE-497",
      "title": "Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58246"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-18084",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BlackBerry",
      "product": "UEM",
      "cwe": "CWE-79",
      "title": "Cross-Site Scripting (XSS) in Management Console of BlackBerry UEM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18084"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-54545",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pionxzh",
      "product": "wakaru",
      "cwe": "CWE-22",
      "title": "@wakaru/cli arbitrary file write during bundle unpack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54545"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-8167",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04612,
      "kev": false,
      "kev_due_at": null,
      "vendor": "THEWP Digital Solutions",
      "product": "News Theme V8",
      "cwe": "CWE-79",
      "title": "Reflected XSS in theWP's News Theme V8",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8167"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-65882",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomdle.com",
      "product": "Joomdle component for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65882"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-48392",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04544,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Bridge",
      "cwe": "CWE-787",
      "title": "Bridge | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48392"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-48393",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04543,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Bridge",
      "cwe": "CWE-787",
      "title": "Bridge | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48393"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-48394",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00148,
      "epss_percentile": 0.04543,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Bridge",
      "cwe": "CWE-787",
      "title": "Bridge | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48394"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-14870",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00146,
      "epss_percentile": 0.04386,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Database for Contact Form 7, WPforms, Elementor forms",
      "cwe": "CWE-79",
      "title": "Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS via form_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14870"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-54655",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "koxudaxi",
      "product": "datamodel-code-generator",
      "cwe": "CWE-94",
      "title": "`datamodel-code-generator` vulnerable to code execution on import via `x-python-type` JSON-Schema extension in datamodel-code-generator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54655"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-48390",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00144,
      "epss_percentile": 0.04187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Bridge",
      "cwe": "CWE-863",
      "title": "Bridge | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48390"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-14926",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00144,
      "epss_percentile": 0.04158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "FluentCart A New Era of eCommerce",
      "cwe": "CWE-284",
      "title": "FluentCart < 1.4.0 - Subscriber+ Subscription Payment-Method Tampering via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14926"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-54621",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.04012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "koxudaxi",
      "product": "datamodel-code-generator",
      "cwe": "CWE-94",
      "title": "`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in GraphQL Union description",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54621"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-54654",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00142,
      "epss_percentile": 0.04011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "koxudaxi",
      "product": "datamodel-code-generator",
      "cwe": "CWE-94",
      "title": "`datamodel-code-generator` vulnerable to code injection via unescaped carriage return in `--extra-template-data` `comment` field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54654"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-7775",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.04036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Sterling B2B Integrator",
      "cwe": "CWE-79",
      "title": "Cross-site Scripting Security Vulnerability in IBM Sterling B2B Integrator and IBM Sterling File Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7775"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-14819",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00142,
      "epss_percentile": 0.04035,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Event Tickets and Registration",
      "cwe": "CWE-79",
      "title": "Event Tickets < 5.28.4 - Editor+ Stored XSS via Ticket Move",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14819"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-56821",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00137,
      "epss_percentile": 0.0361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-299",
      "title": "Netty: Out-of-date OCSP Responses Accepted by OcspServerCertificateValidator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56821"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-41874",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSolution",
      "product": "Quick.Cart",
      "cwe": "CWE-256",
      "title": "Hard-coded admin credentials in Quick.Cart",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41874"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-54605",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00132,
      "epss_percentile": 0.03213,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ruby-oauth",
      "product": "oauth",
      "cwe": "CWE-200",
      "title": "OAuth: Cross-origin token-request redirects can expose signed request metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54605"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-15136",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02999,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wplegalpages",
      "product": "WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode",
      "cwe": "CWE-352",
      "title": "Cookie Banner for GDPR / CCPA – WPLP Cookie Consent <= 4.3.7 - Cross-Site Request Forgery via Bulk Action to Delete/Resolve Entries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15136"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-4648",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.0204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CasfID Servicios Tecnológicos",
      "product": "NFC Wristbands",
      "cwe": "CWE-326",
      "title": "Insufficient Encryption Level in CasfID Servicios Tecnológicos NFC Wristbands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4648"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-17072",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00116,
      "epss_percentile": 0.01905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Gstreamer1-plugins-good: gst-plugins-good: 4-byte heap over-read in gst_matroska_parse_flac_stream_headers when parsing flac codec data in matroska containers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17072"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-42494",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01801,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-125",
      "title": "buffer overruns in libfsimage iso9660 handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-42494"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-18107",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01631,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-269",
      "title": "Criu: criu: container escape via rseq critical section hijack during checkpoint/restore",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18107"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-56822",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-367",
      "title": "Netty: TOCTOU in OcspServerCertificateValidator",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56822"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-47768",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.01372,
      "kev": false,
      "kev_due_at": null,
      "vendor": "juev",
      "product": "nebula-mesh",
      "cwe": "CWE-598",
      "title": "nebula-mesh: Newly-minted operator API key exposed in redirect URL (Referer, history, proxy logs)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47768"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-54619",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00107,
      "epss_percentile": 0.01282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sparklemotion",
      "product": "sqlite3-ruby",
      "cwe": "CWE-416",
      "title": "sqlite3-ruby has Use-After-Free When Redefining SQLite Functions with Different Arity",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54619"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-54620",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00107,
      "epss_percentile": 0.01282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sparklemotion",
      "product": "sqlite3-ruby",
      "cwe": "CWE-416",
      "title": "sqlite3-ruby has Use-After-Free in SQLite Aggregate Function Callbacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54620"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-8164",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00106,
      "epss_percentile": 0.01273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArkSigner Software and Hardware Industry and Trade Inc.",
      "product": "ArkSigner Desktop Client",
      "cwe": "CWE-427",
      "title": "Search Order Hijacking in ArkSigner's ArkSigner Desktop Client",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8164"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-62428",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.001,
      "epss_percentile": 0.00962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xen",
      "product": "Xen",
      "cwe": "CWE-367",
      "title": "grant-table: type confusion in grant-copy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62428"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-55977",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00093,
      "epss_percentile": 0.00638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "EShare",
      "product": "ESharePro",
      "cwe": "CWE-307",
      "title": "Bypass of application rate-limiting mechanism",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55977"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-4932",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00081,
      "epss_percentile": 0.00246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Hypervisor",
      "cwe": "CWE-331",
      "title": "This Power System update is being released to address Insufficient Entropy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4932"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-17531",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-17531 (unitedbyai droidclaw). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-31431",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-31431 (Linux Kernel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-39875",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-39875 (Apple macOS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-4258",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-4258 (sjcl). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43760",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43760 (Apple macOS). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-43910",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-43910 (appium java-client). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45711",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45711 (axllent mailpit). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47427",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47427 (github-mcp-server). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-49477",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-49477 (facelessuser soupsieve). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-53359",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-53359 (Linux). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54332",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54332 (gopacket). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54345",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54345 (gopacket). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54656",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54656 (koxudaxi datamodel-code-generator). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54690",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54690 (koxudaxi datamodel-code-generator). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55389",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55389 (koxudaxi datamodel-code-generator). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55415",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55415 (koxudaxi datamodel-code-generator). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55554",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55554 (dompdf). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-55555",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-55555 (dompdf). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56722",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56722 (dompdf). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59941",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59941 (dompdf). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59942",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59942 (dompdf). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59943",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59943 (dompdf). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-61511",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-61511 (vBulletin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-64620",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-64620 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-64621",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-64621 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65708",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65708 (nuxsmin sysPass). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65709",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65709 (nuxsmin sysPass). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65710",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65710 (nuxsmin sysPass). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65711",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65711 (nuxsmin sysPass). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65899",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65899 (cure53 DOMPurify). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65902",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65902 (cure53 DOMPurify). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65904",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65904 (cure53 DOMPurify). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65911",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65911 (cure53 DOMPurify). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-65917",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-65917 (usmannasir cyberpanel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66028",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66028 (Creativeitem Ekushey Project Manager CRM). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66029",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66029 (Creativeitem Ekushey Project Manager CRM). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66030",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66030 (Creativeitem Ekushey Project Manager CRM). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66031",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66031 (Creativeitem Ekushey Project Manager CRM). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-21538",
      "detail": "RESCORED — CVE-2024-21538 (cross-spawn). CVSS 8.7 → 7.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-68686",
      "detail": "RESCORED — CVE-2025-68686 (Fortinet FortiOS). CVSS 5.3 → 5.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-15631",
      "detail": "RESCORED — CVE-2026-15631 (@fastify/http-proxy). CVSS 8.7 → 10 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-4258",
      "detail": "RESCORED — CVE-2026-4258 (sjcl). CVSS 8.7 → 7.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-45501",
      "detail": "RESCORED — CVE-2026-45501 (Microsoft Exchange Server 2016 Cumulative Update 23). CVSS 6.5 → 6.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-45503",
      "detail": "RESCORED — CVE-2026-45503 (Microsoft Exchange Server 2016 Cumulative Update 23). CVSS 8.1 → 6.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-45583",
      "detail": "RESCORED — CVE-2026-45583 (Microsoft Exchange Server 2016 Cumulative Update 23). CVSS 7.5 → 8.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-47631",
      "detail": "RESCORED — CVE-2026-47631 (Microsoft Exchange Server 2016 Cumulative Update 23). CVSS 8.1 → 5.4 (NVD)."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-31431",
      "detail": "ENRICHED — CVE-2026-31431 (Linux Kernel). Received CVSS 7.8 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
