{
  "day": "2026-07-29",
  "boundary": "UTC calendar day",
  "published_count": 274,
  "by_severity": {
    "CRITICAL": 47,
    "HIGH": 116,
    "MEDIUM": 103,
    "LOW": 8
  },
  "kev_count": 1,
  "exploit_reference_count": 5,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-20316",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00788,
      "epss_percentile": 0.53374,
      "kev": true,
      "kev_due_at": "2026-08-01",
      "vendor": "Cisco",
      "product": "Cisco Secure Firewall Management Center (FMC)",
      "cwe": "CWE-259",
      "title": "Cisco Secure Firewall Management Center Software Static Credential Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20316"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-5492",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.016,
      "epss_percentile": 0.73812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DriveLock",
      "product": "DriveLock",
      "cwe": "CWE-22",
      "title": "DriveLock Directory Traversal Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5492"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-5491",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01539,
      "epss_percentile": 0.72885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DriveLock",
      "product": "DriveLock",
      "cwe": "CWE-22",
      "title": "DriveLock Directory Traversal Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5491"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-5487",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01535,
      "epss_percentile": 0.72813,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DriveLock",
      "product": "DriveLock",
      "cwe": "CWE-22",
      "title": "DriveLock Directory Traversal Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5487"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-5489",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01266,
      "epss_percentile": 0.67403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DriveLock",
      "product": "DriveLock",
      "cwe": "CWE-22",
      "title": "DriveLock Directory Traversal Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5489"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-12357",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.01089,
      "epss_percentile": 0.62701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Heimdall Data",
      "product": "Database Proxy",
      "cwe": "CWE-93",
      "title": "Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12357"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-67438",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00995,
      "epss_percentile": 0.59918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OliveTin",
      "product": "OliveTin",
      "cwe": "CWE-78",
      "title": "OliveTin OS Command Injection via Custom regex: Argument Type Bypassing Shell Safety Check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67438"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-14266",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00939,
      "epss_percentile": 0.5814,
      "kev": false,
      "kev_due_at": null,
      "vendor": "7-Zip",
      "product": "7-Zip",
      "cwe": "CWE-122",
      "title": "7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14266"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-12935",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00807,
      "epss_percentile": 0.53986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "TL-WR940N v6",
      "cwe": "CWE-121",
      "title": "Unauthenticated Remote Code Execution in TP-Link TL-WR940N RTSP Conntrack Feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12935"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-41939",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00801,
      "epss_percentile": 0.53789,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Care Everywhere LLC",
      "product": "Care Everywhere Gateway",
      "cwe": "CWE-1392",
      "title": "Care Everywhere Gateway 14.3.10 Hard-coded Credentials RCE via WildFly",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41939"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-14900",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0069,
      "epss_percentile": 0.49994,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StylemixThemes",
      "product": "Cost Calculator Builder PRO",
      "cwe": "CWE-94",
      "title": "Cost Calculator Builder PRO <= 4.0.3 - Unauthenticated Remote Code Execution via 'orderDetails' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14900"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-59243",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00684,
      "epss_percentile": 0.4977,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Airflow FAB provider",
      "cwe": "CWE-347",
      "title": "Apache Airflow FAB provider: FAB auth manager: JWT signature verification disabled by default for Azure AD OAuth (`verify_signature` defaults to `False`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59243"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-58163",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00652,
      "epss_percentile": 0.48466,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-502",
      "title": "Apache Traffic Server: Cache deserialization and lifetime errors can corrupt state or crash the server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58163"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-23904",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0065,
      "epss_percentile": 0.48406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Kyuubi",
      "cwe": "CWE-923",
      "title": "Apache Kyuubi: Unrestricted access via Kyuubi engine-ui proxy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23904"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-58161",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00636,
      "epss_percentile": 0.47733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-476",
      "title": "Apache Traffic Server: Memory-safety errors in TLS and SNI handling can crash the server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58161"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-58164",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00636,
      "epss_percentile": 0.47732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-416",
      "title": "Apache Traffic Server: Remap configuration lifetime and TOCTOU errors cause use-after-free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58164"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-58175",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00636,
      "epss_percentile": 0.47732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-401",
      "title": "Apache Traffic Server: HostDB SRV handling leaks memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58175"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-58178",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00636,
      "epss_percentile": 0.47733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-674",
      "title": "Apache Traffic Server: ESI plugin allows uncontrolled recursion and server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58178"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-58180",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00636,
      "epss_percentile": 0.47732,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-121",
      "title": "Apache Traffic Server: txn_box plugin overflows the stack from attacker input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58180"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-12476",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00629,
      "epss_percentile": 0.47454,
      "kev": false,
      "kev_due_at": null,
      "vendor": "smub",
      "product": "Easy Digital Downloads – eCommerce Payments and Subscriptions made easy",
      "cwe": "CWE-434",
      "title": "Easy Digital Downloads <= 3.6.9 - Authenticated (Shop Manager+) Arbitrary File Upload via 'edd-import-file' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12476"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-67192",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00616,
      "epss_percentile": 0.46848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xlight",
      "product": "Xlight FTP Server",
      "cwe": "CWE-121",
      "title": "Xlight FTP Server < 3.9.5 Pre-Auth Stack Buffer Overflow via SSH GCM Cipher",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67192"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-58188",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00598,
      "epss_percentile": 0.46016,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-787",
      "title": "Apache Traffic Server: Memory-safety and limit-bypass errors across experimental plugins",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58188"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-18072",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00586,
      "epss_percentile": 0.45455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nico23",
      "product": "Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick …",
      "cwe": "CWE-506",
      "title": "Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18072"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-67191",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00579,
      "epss_percentile": 0.45086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xlight",
      "product": "Xlight FTP Server",
      "cwe": "CWE-122",
      "title": "Xlight FTP Server < 3.9.5 Pre-Auth Heap Buffer Overflow via SSH Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67191"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-13308",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00567,
      "epss_percentile": 0.4452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autel",
      "product": "MaxiCharger AC Elite Home",
      "cwe": "CWE-191",
      "title": "Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13308"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-58158",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0056,
      "epss_percentile": 0.44137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-121",
      "title": "Apache Traffic Server: PROXY protocol parsing has port truncation and a stack overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58158"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-65883",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00557,
      "epss_percentile": 0.43988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aimy-extensions.com",
      "product": "Aimy Captcha-Less Form Guard plugin for Joomla",
      "cwe": "CWE-502",
      "title": "Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65883"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-58179",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00554,
      "epss_percentile": 0.43873,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-121",
      "title": "Apache Traffic Server: regex_remap plugin overflows the stack from attacker input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58179"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-58160",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00552,
      "epss_percentile": 0.43748,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-125",
      "title": "Apache Traffic Server: Out-of-bounds reads while parsing DNS responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58160"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-14270",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00548,
      "epss_percentile": 0.43516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ThemeComplete",
      "product": "Extra Checkout Options - addon for Extra Product Options plugin",
      "cwe": "CWE-434",
      "title": "Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) <= 2.3.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File Upload in eco_save_settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14270"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-58177",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00547,
      "epss_percentile": 0.43489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-787",
      "title": "Apache Traffic Server: Memory-safety and path-traversal errors in the Cripts framework",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58177"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-58186",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00545,
      "epss_percentile": 0.43411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-20",
      "title": "Apache Traffic Server: webp_transform plugin decodes unsafely and mislabels degraded responses",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58186"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-58182",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00542,
      "epss_percentile": 0.43246,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-400",
      "title": "Apache Traffic Server: ts_lua plugin has initialization and resource-handling errors",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58182"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-13423",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00536,
      "epss_percentile": 0.42893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Streamit",
      "cwe": "CWE-94",
      "title": "Streamit <= 4.5.0 - Unauthenticated Remote Code Execution via Arbitrary Function Call",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13423"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-58159",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00525,
      "epss_percentile": 0.42284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-863",
      "title": "Apache Traffic Server: Listener and ACL handling allow access-control bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58159"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-58183",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00512,
      "epss_percentile": 0.41514,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-20",
      "title": "Apache Traffic Server: prefetch plugin can crash on attacker-influenced input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58183"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-67429",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00494,
      "epss_percentile": 0.40428,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flytohub",
      "product": "flyto-core",
      "cwe": "CWE-22",
      "title": "Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67429"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-66723",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00494,
      "epss_percentile": 0.40421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CERT.PL",
      "product": "MWDB Core",
      "cwe": "CWE-862",
      "title": "Missing authentication requirement in Remote Instances proxy API in MWDB Core",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66723"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2025-10656",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00492,
      "epss_percentile": 0.40308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "holest",
      "product": "Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light",
      "cwe": "CWE-863",
      "title": "Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light <= 2.4.37 - Missing Authorization to Unauthenticated Privilege Escalation via Admin Account Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-10656"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-58181",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00492,
      "epss_percentile": 0.40311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-121",
      "title": "Apache Traffic Server: uri_signing and url_sig plugins can exhaust the stack or crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58181"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-11974",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00489,
      "epss_percentile": 0.40107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "wp-media-folder-addon",
      "cwe": "CWE-22",
      "title": "Media folder Addon < 4.1.7 - Unauthenticated Arbitrary File Download",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11974"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-58189",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00487,
      "epss_percentile": 0.40003,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-918",
      "title": "Apache Traffic Server: Plugins resetting the redirect counter enable SSRF amplification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58189"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-5057",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00484,
      "epss_percentile": 0.39798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ATEN",
      "product": "Unizon",
      "cwe": "CWE-306",
      "title": "ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5057"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-5490",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00481,
      "epss_percentile": 0.39607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DriveLock",
      "product": "DriveLock",
      "cwe": "CWE-89",
      "title": "DriveLock SQL Injection Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5490"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-58151",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00474,
      "epss_percentile": 0.39157,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-400",
      "title": "Apache Traffic Server: Abusive HTTP/2 framing can exhaust resources and crash the server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58151"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-65324",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00474,
      "epss_percentile": 0.39156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-400",
      "title": "Apache Traffic Server: HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowing memory exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65324"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-58153",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00472,
      "epss_percentile": 0.38992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-444",
      "title": "Apache Traffic Server: HTTP/2 to HTTP/1 conversion forwards origin trailers to clients unsafely",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58153"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-58184",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00457,
      "epss_percentile": 0.38072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-787",
      "title": "Apache Traffic Server: header_rewrite plugin cookie handling can corrupt memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58184"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-58187",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00453,
      "epss_percentile": 0.3776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-787",
      "title": "Apache Traffic Server: Multiplexer plugin chunk decoder enables a denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58187"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-58157",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00452,
      "epss_percentile": 0.37737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-200",
      "title": "Apache Traffic Server: Improper server-session reuse can expose data across client connections",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58157"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-65100",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00449,
      "epss_percentile": 0.37529,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-696",
      "title": "Apache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header encode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65100"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-58185",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00446,
      "epss_percentile": 0.373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-416",
      "title": "Apache Traffic Server: Use-after-free in the intercept plugin",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58185"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-67432",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00436,
      "epss_percentile": 0.36523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "modelcontextprotocol",
      "product": "ruby-sdk",
      "cwe": "CWE-770",
      "title": "MCP Ruby SDK: Unbounded JSON-RPC request body causes uncontrolled memory allocation in StreamableHTTPTransport",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67432"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-50622",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00434,
      "epss_percentile": 0.36317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Atlas",
      "cwe": "CWE-862",
      "title": "Apache Atlas: Missing Authorization on Admin Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50622"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-60113",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00432,
      "epss_percentile": 0.36143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NASA-AMMOS",
      "product": "AIT-DSN",
      "cwe": "CWE-306",
      "title": "AIT-DSN < 2.2.2 Missing Authentication via SLE API Routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60113"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-54680",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00426,
      "epss_percentile": 0.35715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kube-logging",
      "product": "logging-operator",
      "cwe": "CWE-74",
      "title": "Logging operator has Fluentd configuration injection that allows remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54680"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-5056",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00426,
      "epss_percentile": 0.35702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GStreamer",
      "product": "GStreamer",
      "cwe": "CWE-121",
      "title": "GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5056"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-67595",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00422,
      "epss_percentile": 0.35393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "webreinvent",
      "product": "vaahcms",
      "cwe": "CWE-506",
      "title": "VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67595"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-46678",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00419,
      "epss_percentile": 0.35122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pydantic",
      "product": "pydantic-ai",
      "cwe": "CWE-918",
      "title": "Pydantic AI: SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6 (Incomplete fix of CVE-2026-25580)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46678"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-60112",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00408,
      "epss_percentile": 0.34207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NASA-AMMOS",
      "product": "AIT-GUI",
      "cwe": "CWE-306",
      "title": "AIT-GUI < 2.5.1 Missing Authentication via Sessions.create()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60112"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-15975",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00394,
      "epss_percentile": 0.3277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-770",
      "title": "Allocation of Resources Without Limits or Throttling in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15975"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-67201",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00391,
      "epss_percentile": 0.32415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vlang",
      "product": "v",
      "cwe": "CWE-436",
      "title": "V 0.5.2 SSRF Bypass via Parser Differential in net.urllib and net.http",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67201"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-58155",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00386,
      "epss_percentile": 0.31938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-444",
      "title": "Apache Traffic Server: Header-name length truncation enables header aliasing and request smuggling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58155"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-18191",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00383,
      "epss_percentile": 0.3163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Vacron",
      "product": "VIN-DS783E-E6",
      "cwe": "CWE-912",
      "title": "Vacron｜IP Camera - Hidden Functionality",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18191"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-67215",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31302,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DaveGamble",
      "product": "cJSON",
      "cwe": "CWE-674",
      "title": "cJSON JSON Patch copy/add Uncontrolled Recursion Stack Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67215"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-18192",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Vacron",
      "product": "VIN-DS783E-E6",
      "cwe": "CWE-23",
      "title": "Vacron｜IP Camera - Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18192"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-58154",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00372,
      "epss_percentile": 0.3053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-787",
      "title": "Apache Traffic Server: Memory-safety errors in MIME and header parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58154"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-0667",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.30095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Schneider Electric",
      "product": "SCADAPack 47x",
      "cwe": "CWE-754",
      "title": "CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of confidentiality & integrity when communicating over the Modbus TCP protocol.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0667"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-12144",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00368,
      "epss_percentile": 0.30061,
      "kev": false,
      "kev_due_at": null,
      "vendor": "saadiqbal",
      "product": "Wholesale for WooCommerce",
      "cwe": "CWE-269",
      "title": "Wholesale for WooCommerce <= 2.0.5 - Authenticated (Author+) Privilege Escalation via 'user_role_set' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12144"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-65886",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00364,
      "epss_percentile": 0.29657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "balbooa.com",
      "product": "Gridbox extension for Joomla",
      "cwe": "CWE-22",
      "title": "Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65886"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-14529",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0036,
      "epss_percentile": 0.29223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-306",
      "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14529"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-15344",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00355,
      "epss_percentile": 0.28787,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opajaap",
      "product": "WP Photo Album Plus",
      "cwe": "CWE-89",
      "title": "WP Photo Album Plus <= 9.2.04.002 - Authenticated (Administrator+) SQL Injection via 'table' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15344"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-67437",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00354,
      "epss_percentile": 0.2865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OliveTin",
      "product": "OliveTin",
      "cwe": "CWE-400",
      "title": "OliveTin: Unauthenticated DoS via OAuth2 State Memory Exhaustion (Unbounded Map Growth)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67437"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-67216",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00351,
      "epss_percentile": 0.28242,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DaveGamble",
      "product": "cJSON",
      "cwe": "CWE-407",
      "title": "cJSON cJSON_Compare Exponential Complexity Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67216"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-50782",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00349,
      "epss_percentile": 0.28092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-611",
      "title": "Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp endpoint. An unauthenticated remote attacker can send a crafted XML payload to read arbitrary files from the server via an out-of-band attack.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50782"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-22068",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00347,
      "epss_percentile": 0.27892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-777",
      "title": "Apache Traffic Server: Regex mappings match with malicious domain names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22068"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-13346",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00347,
      "epss_percentile": 0.27925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Python Packaging Authority",
      "product": "pip",
      "cwe": "CWE-36",
      "title": "pip absolute path traversal during download from malicious package indexes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13346"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-54735",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00345,
      "epss_percentile": 0.27698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "prebid",
      "product": "prebid-server",
      "cwe": "CWE-918",
      "title": "prebid-server's request forgery vulnerability allows for possible host environment data extraction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54735"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-13307",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00344,
      "epss_percentile": 0.27537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autel",
      "product": "MaxiCharger AC Elite Home",
      "cwe": "CWE-122",
      "title": "Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13307"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-18022",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.2739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "pgvector",
      "cwe": "CWE-190",
      "title": "pgvector buffer overflow via integer wraparound in IVFFlat index build on 32-bit systems",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18022"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-54693",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00343,
      "epss_percentile": 0.27411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zitadel",
      "product": "zitadel",
      "cwe": "CWE-863",
      "title": "ZITADEL Users Can Self-Verify Email/Phone via API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54693"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-67427",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.2698,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flytohub",
      "product": "flyto-core",
      "cwe": "CWE-522",
      "title": "Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67427"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-57834",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-444",
      "title": "Apache Traffic Server: Malformed chunked message body allows request smuggling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57834"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-67428",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00337,
      "epss_percentile": 0.26705,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flytohub",
      "product": "flyto-core",
      "cwe": "CWE-918",
      "title": "Flyto2 Core: Multiple HTTP-family modules fetch client-controlled URLs without the SSRF guard their siblings apply (SSRF to internal/metadata)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67428"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-33267",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-20",
      "title": "Apache Traffic Server: Untrusted @ headers can spoof ATS internal metadata",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33267"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-59899",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00335,
      "epss_percentile": 0.26483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-770",
      "title": "Netty HttpContentEncoder: Unbounded Per-Connection Queue Growth via HTTP/1.1 Pipelining Leads to Denial of Service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59899"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-6267",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00333,
      "epss_percentile": 0.2629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-201",
      "title": "Insertion of Sensitive Information Into Sent Data in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6267"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-58162",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.2622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-295",
      "title": "Apache Traffic Server: Certifier plugin trusts client SNI when generating certificates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58162"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-44943",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0033,
      "epss_percentile": 0.26017,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-iscsi",
      "product": "open-iscsi",
      "cwe": "CWE-22",
      "title": "remote limited file-write as root via discovery in open-iscsi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44943"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-63227",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00328,
      "epss_percentile": 0.25798,
      "kev": false,
      "kev_due_at": null,
      "vendor": "An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP webshell to a publicly accessible directory and execute arbitrary code on the server.",
      "product": "Koollab LMS",
      "cwe": "CWE-434",
      "title": "Unrestricted SCORM file upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63227"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-24033",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00327,
      "epss_percentile": 0.25675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-444",
      "title": "Apache Traffic Server: Request smuggling via chunked extension quoted-string parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-24033"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-13723",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00327,
      "epss_percentile": 0.25701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Develar",
      "product": "app-builder",
      "cwe": "CWE-22",
      "title": "Develar's electron-builder allows arbitrary file overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13723"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-14341",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00326,
      "epss_percentile": 0.25572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-862",
      "title": "Missing Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14341"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-13697",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00325,
      "epss_percentile": 0.25506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-200",
      "title": "undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13697"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-33930",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00323,
      "epss_percentile": 0.25226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-121",
      "title": "Apache Traffic Server: Buffer overflow via Host field that has a long string value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33930"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-58152",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00323,
      "epss_percentile": 0.25226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-190",
      "title": "Apache Traffic Server: Integer-handling errors in HPACK/XPACK decoding corrupt memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58152"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-54078",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "veraPDF",
      "product": "veraPDF-validation",
      "cwe": "CWE-611",
      "title": "veraPDF Validation XXE via Rich Text",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54078"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-54079",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0032,
      "epss_percentile": 0.24837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "veraPDF",
      "product": "veraPDF-validation",
      "cwe": "CWE-611",
      "title": "veraPDF Validation XXE via XFA",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54079"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-67425",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flytohub",
      "product": "flyto-core",
      "cwe": "CWE-201",
      "title": "Flyto2 Core: LLM/API keys leak to an attacker-controlled base_url",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67425"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-67213",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nanoid_project",
      "product": "nanoid",
      "cwe": "CWE-835",
      "title": "nanoid before 5.1.6 Infinite Loop via Zero Size in customAlphabet and customRandom",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67213"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-67214",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00319,
      "epss_percentile": 0.24774,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nanoid_project",
      "product": "nanoid",
      "cwe": "CWE-835",
      "title": "nanoid before 5.1.16 Infinite Loop via Negative Size in non-secure module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67214"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-58150",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.2445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-444",
      "title": "Apache Traffic Server: HTTP/2 requests with Transfer-Encoding are not rejected, allowing request smuggling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58150"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-12436",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-915",
      "title": "Improperly Controlled Modification of Dynamically-Determined Object Attributes in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12436"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-14488",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00307,
      "epss_percentile": 0.23426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Meta Box",
      "product": "Meta Box AIO",
      "cwe": "CWE-862",
      "title": "Meta Box AIO <= 3.8.0 - Missing Authorization to Unauthenticated Arbitrary Post Deletion via 'rwmb_frontend_field_object_id' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14488"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-67194",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "svarshavchik",
      "product": "Courier IMAP",
      "cwe": "CWE-674",
      "title": "Courier IMAP < 6.0.1 Mail Server < 2.0.2 Stack Overflow DoS via Nested SEARCH Queries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67194"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-16655",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmanageninja",
      "product": "Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder",
      "cwe": "CWE-79",
      "title": "Fluent Forms <= 6.2.7 - Unauthenticated Stored Cross-Site Scripting via Name Field Nested `password` Member",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16655"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-54080",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.22815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "veraPDF",
      "product": "veraPDF-parser",
      "cwe": "CWE-1325",
      "title": "veraPDF Parser DoS via PostScript CMap Streams",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54080"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-54081",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.22816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "veraPDF",
      "product": "veraPDF-parser",
      "cwe": "CWE-1325",
      "title": "veraPDF Parser DoS via PostScript Type 1 Font Programs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54081"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-11973",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00301,
      "epss_percentile": 0.22779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wp-lab",
      "product": "WP-Lister Lite for eBay",
      "cwe": "CWE-89",
      "title": "WP-Lister Lite for eBay <= 3.8.8 - Authenticated (Shop Manager+) SQL Injection via 'orderby' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11973"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-8338",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.003,
      "epss_percentile": 0.22626,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Black Duck",
      "product": "Coverity Connect",
      "cwe": "CWE-288",
      "title": "Authentication and Authorization Bypass in Coverity Connect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8338"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-50642",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.003,
      "epss_percentile": 0.22628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "so-fancy",
      "product": "diff-so-fancy",
      "cwe": "CWE-116",
      "title": "Terminal Escape Injection in diff‑so‑fancy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50642"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-16326",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00299,
      "epss_percentile": 0.22561,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Tooling",
      "cwe": "CWE-488",
      "title": "consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16326"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-63229",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00296,
      "epss_percentile": 0.22211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Three Learning",
      "product": "Koollab LMS",
      "cwe": "CWE-89",
      "title": "Pre-authentication blind SQL injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63229"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-63230",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00296,
      "epss_percentile": 0.22211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Three Learning",
      "product": "Koollab LMS",
      "cwe": "CWE-89",
      "title": "Pre-authentication error-based SQL injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63230"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-41920",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-284",
      "title": "Apache Traffic Server: SNI to Host header matching policy is not properly enforced",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41920"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-16751",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00295,
      "epss_percentile": 0.22114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ente",
      "product": "Museum Server",
      "cwe": null,
      "title": "Ente Museum Server Authorization Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16751"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-63232",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00294,
      "epss_percentile": 0.22053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Three Learning",
      "product": "Koollab LMS",
      "cwe": "CWE-89",
      "title": "SQL injection and unsafe deserialisation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63232"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-63233",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00294,
      "epss_percentile": 0.22054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Three Learning",
      "product": "Koollab LMS",
      "cwe": "CWE-89",
      "title": "SQL injection and unsafe deserialisation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63233"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-63234",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00294,
      "epss_percentile": 0.22054,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Three Learning",
      "product": "Koollab LMS",
      "cwe": "CWE-89",
      "title": "SQL injection and unsafe deserialisation vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63234"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-14351",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-1230",
      "title": "Exposure of Sensitive Information Through Metadata in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14351"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-18207",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-285",
      "title": "Keycloak-services: keycloak-services: client policy source-group condition bypass via duplicate group name matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18207"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-67426",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00291,
      "epss_percentile": 0.21708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flytohub",
      "product": "flyto-core",
      "cwe": "CWE-306",
      "title": "Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67426"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-67430",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21733,
      "kev": false,
      "kev_due_at": null,
      "vendor": "modelcontextprotocol",
      "product": "ruby-sdk",
      "cwe": "CWE-401",
      "title": "MCP Ruby SDK: Unbounded session retention in StreamableHTTPTransport allows memory exhaustion via initialize flood",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67430"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-9177",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00288,
      "epss_percentile": 0.21388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Axway",
      "product": "SecureTransport",
      "cwe": "CWE-1336",
      "title": "Server-Side Template Injection in SecureTransport's Apache Velocity mail templates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9177"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-65885",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00286,
      "epss_percentile": 0.2122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "balbooa.com",
      "product": "Gridbox extension for Joomla",
      "cwe": "CWE-434",
      "title": "Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65885"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-54666",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "acacode",
      "product": "swagger-typescript-api",
      "cwe": "CWE-74",
      "title": "swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54666"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-67435",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00286,
      "epss_percentile": 0.21181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linuxfabrik",
      "product": "monitoring-plugins",
      "cwe": "CWE-200",
      "title": "linuxfabrik-lib: fetch() forwards credential headers across a cross-origin redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67435"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-18201",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: generic identity-provider creation can bind brokers to organizations without manage-organizations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18201"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-4672",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21092,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-862",
      "title": "Missing Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4672"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-65884",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00284,
      "epss_percentile": 0.21018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "balbooa.com",
      "product": "Gridbox extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65884"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-65887",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00284,
      "epss_percentile": 0.21019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "balbooa.com",
      "product": "Gridbox extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65887"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-65888",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00284,
      "epss_percentile": 0.21019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "balbooa.com",
      "product": "Gridbox extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65888"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-65889",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00284,
      "epss_percentile": 0.20996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "balbooa.com",
      "product": "Gridbox extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion in Gridbox < 2.20.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65889"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-6089",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "blendmedia",
      "product": "WP CTA – Call Now Button, Sticky Button & Call to Action Builder",
      "cwe": "CWE-918",
      "title": "WP CTA <= 2.1.2 - Authenticated (Administrator+) Server-Side Request Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6089"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2025-69943",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00276,
      "epss_percentile": 0.20096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and specilizationid.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69943"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-65890",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00276,
      "epss_percentile": 0.20096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "balbooa.com",
      "product": "Gridbox extension for Joomla",
      "cwe": "CWE-89",
      "title": "Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65890"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-67431",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "modelcontextprotocol",
      "product": "ruby-sdk",
      "cwe": "CWE-284",
      "title": "MCP Ruby SDK: Ruby SSE Session Poisoning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67431"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-18255",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00272,
      "epss_percentile": 0.1966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Quay 3",
      "cwe": "CWE-863",
      "title": "Quay: quay: global read-only superuser can view robot account tokens",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18255"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-54661",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "acacode",
      "product": "swagger-typescript-api",
      "cwe": "CWE-74",
      "title": "swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54661"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-54662",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "acacode",
      "product": "swagger-typescript-api",
      "cwe": "CWE-74",
      "title": "swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54662"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-54664",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0027,
      "epss_percentile": 0.19304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "acacode",
      "product": "swagger-typescript-api",
      "cwe": "CWE-74",
      "title": "swagger-typescript-api vulnerable to code injection via unescaped enum string values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54664"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-18197",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19026,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Link Library",
      "cwe": "CWE-79",
      "title": "Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Link Library allows Cross-Site Scripting (XSS). This issue affects Link Library: before 7.9.4.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18197"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-66724",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.1909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CERT.PL",
      "product": "MWDB Core",
      "cwe": "CWE-862",
      "title": "Permission Bypass Via Undocumented HTTP Methods In MWDB Core",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66724"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-67193",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18426,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Xlight",
      "product": "Xlight FTP Server",
      "cwe": "CWE-203",
      "title": "Xlight FTP Server < 3.9.5 Information Disclosure via USER Command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67193"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-59901",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-835",
      "title": "Netty Bzip2Decoder: Infinite Loop in RLE State Machine Leads to Event-Loop Thread Hang",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59901"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2025-65340",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-65340"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2025-67403",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67403"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2025-67404",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_class.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67404"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2025-69942",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17935,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69942"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-6336",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00255,
      "epss_percentile": 0.17258,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6336"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-13690",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00254,
      "epss_percentile": 0.17135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "UsersWP",
      "cwe": "CWE-287",
      "title": "UsersWP < 1.2.67 - Two-Factor Authentication Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13690"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-16553",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00254,
      "epss_percentile": 0.17133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-522",
      "title": "Insufficiently Protected Credentials in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16553"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-55995",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-iscsi",
      "product": "open-iscsi",
      "cwe": "CWE-415",
      "title": "Double-free in the iSNS attribute decoder in open-iscsi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55995"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-63231",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Three Learning",
      "product": "Koollab LMS",
      "cwe": "CWE-89",
      "title": "Post-authentication SQL injection vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63231"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-67439",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16941,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OliveTin",
      "product": "OliveTin",
      "cwe": "CWE-863",
      "title": "OliveTin: StartActionAndWait Endpoints Bypass `logs` Permission and Return Action Output",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67439"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-67217",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "DaveGamble",
      "product": "cJSON",
      "cwe": "CWE-696",
      "title": "cJSON JSON Patch Non-Atomic Application Destroys Data Before Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67217"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-50558",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16666,
      "kev": false,
      "kev_due_at": null,
      "vendor": "brightio",
      "product": "penelope",
      "cwe": "CWE-22",
      "title": "Penelope unsafe tar extraction allows arbitrary local file write via crafted session archive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50558"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-15077",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0025,
      "epss_percentile": 0.16721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-74",
      "title": "Improper Neutralization of Input Used for LLM Prompting in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15077"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-67436",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linuxfabrik",
      "product": "monitoring-plugins",
      "cwe": "CWE-20",
      "title": "Linuxfabrik monitoring-plugins: SSRF and auth-token disclosure via unvalidated @odata.id link in redfish-* plugins",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67436"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-59898",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16588,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-444",
      "title": "Netty: WebSockets V07/V08 handshaker missing Connection/Upgrade validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59898"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-13425",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00248,
      "epss_percentile": 0.1643,
      "kev": false,
      "kev_due_at": null,
      "vendor": "code4life",
      "product": "Database for CF7",
      "cwe": "CWE-79",
      "title": "Database for CF7 <= 1.2.6 - Unauthenticated Stored Cross-Site Scripting via Array Form Field Values",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13425"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-15144",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00246,
      "epss_percentile": 0.16226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "@fastify/rate-limit",
      "product": "@fastify/rate-limit",
      "cwe": "CWE-307",
      "title": "@fastify/rate-limit vulnerable to rate-limit bypass via IPv6 address rotation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15144"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-54660",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00243,
      "epss_percentile": 0.15828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "acacode",
      "product": "swagger-typescript-api",
      "cwe": "CWE-200",
      "title": "swagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54660"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-18266",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15794,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LangGenius",
      "product": "Dify",
      "cwe": "CWE-601",
      "title": "Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18266"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-16597",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "duracelltomi",
      "product": "GTM4WP – A Google Tag Manager (GTM) plugin for WordPress",
      "cwe": "CWE-79",
      "title": "GTM4WP <= 1.22.3 - Unauthenticated Stored Cross-Site Scripting via WooCommerce Billing Fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16597"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-8791",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.1554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ameliabooking",
      "product": "Booking System Trafft",
      "cwe": "CWE-79",
      "title": "Booking System Trafft <= 1.0.17 - Authenticated (Subscriber+) Stored Cross-Site Scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8791"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-33385",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenSolution",
      "product": "Quick.CMS",
      "cwe": "CWE-89",
      "title": "Blind SQL Injection in Quick.CMS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33385"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-14300",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)",
      "cwe": "CWE-287",
      "title": "miniOrange Social Login and Register < 7.8.0 - Unauthenticated Account Takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14300"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-59920",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00239,
      "epss_percentile": 0.15256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-93",
      "title": "Netty: STOMP CONNECT Frame Header Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59920"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-3093",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-79",
      "title": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-3093"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-64557",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14844,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "Bluetooth: L2CAP: Fix use-after-free in l2cap_sock_new_connection_cb()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64557"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-67424",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flytohub",
      "product": "flyto-core",
      "cwe": "CWE-918",
      "title": "Flyto2 Core: Guarded HTTP modules follow redirects into internal space without per-hop SSRF revalidation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67424"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-13605",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "PhotoSwipe",
      "cwe": "CWE-79",
      "title": "Photo Swipe <= 4.1.1.1 - Author+ Stored XSS via title Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13605"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-4604",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.1467,
      "kev": false,
      "kev_due_at": null,
      "vendor": "klubraum",
      "product": "Klubraum Membership Request",
      "cwe": "CWE-862",
      "title": "Klubraum Membership Request <= 1.1.0 - Missing Authorization to Unauthenticated Arbitrary Plugin Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4604"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-12703",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14629,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TeamViewer",
      "product": "Remote",
      "cwe": "CWE-288",
      "title": "Bypass of 2FA for Connections via Unattended Access in TeamViewer for macOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12703"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-16328",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14347,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HashiCorp",
      "product": "Tooling",
      "cwe": "CWE-918",
      "title": "consul-mcp-server vulnerable to server side request forgery leading to token exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16328"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2025-60931",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.1435,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-639",
      "title": "An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allows unauthorized attackers to arbitrarily view the compensation information of other employees via a crafted GET request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-60931"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-65943",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rolandd.com",
      "product": "RO CSVI extension for Joomla",
      "cwe": "CWE-284",
      "title": "Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65943"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-59900",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-444",
      "title": "Netty codec-http2: Lack of Host Header Deduplication in HTTP/2→HTTP/1.x Translation Leads to Request Routing Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59900"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-17166",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "magepeopleteam",
      "product": "Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar",
      "cwe": "CWE-862",
      "title": "Event Booking Manager for WooCommerce <= 5.3.7 - Missing Authorization to Authenticated (Contributor+) Site-Wide Payment Settings Modification via mep_save_payment_settings_modal AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17166"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-14643",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00231,
      "epss_percentile": 0.14144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-436",
      "title": "undici vulnerable to cross-user information disclosure via whitespace around equals in Cache-Control directives",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14643"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-54082",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "veraPDF",
      "product": "veraPDF-validation",
      "cwe": "CWE-611",
      "title": "veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54082"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-13309",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00228,
      "epss_percentile": 0.13764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autel",
      "product": "MaxiCharger AC Elite Home",
      "cwe": "CWE-121",
      "title": "Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13309"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2025-14562",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00225,
      "epss_percentile": 0.13387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-863",
      "title": "Incorrect Authorization in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-14562"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-58156",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-863",
      "title": "Apache Traffic Server: URL and port parsing errors allow access-control bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58156"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-15831",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-1270",
      "title": "Generation of Incorrect Security Tokens in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15831"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-5060",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12862,
      "kev": false,
      "kev_due_at": null,
      "vendor": "stylemix",
      "product": "MasterStudy LMS WordPress Plugin – for Online Courses and Education",
      "cwe": "CWE-639",
      "title": "MasterStudy LMS WordPress Plugin – for Online Courses and Education <= 3.7.14 - Insecure Direct Object Reference to Authenticated (Instructor+) Arbitrary Attachment Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5060"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-12895",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00216,
      "epss_percentile": 0.12312,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Frappe",
      "product": "ERPNext",
      "cwe": "CWE-89",
      "title": "SQL Injection in Frappe's ERPNext",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12895"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-63238",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12364,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Three Learning",
      "product": "Koollab LMS",
      "cwe": "CWE-287",
      "title": "Authentication bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63238"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-12938",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "contrid",
      "product": "Newsletters",
      "cwe": "CWE-79",
      "title": "Newsletters <= 4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'target' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12938"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-12939",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11846,
      "kev": false,
      "kev_due_at": null,
      "vendor": "contrid",
      "product": "Newsletters",
      "cwe": "CWE-79",
      "title": "Newsletters <= 4.15 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'link' Shortcode Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12939"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-54705",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11312,
      "kev": false,
      "kev_due_at": null,
      "vendor": "arnog",
      "product": "mathlive",
      "cwe": "CWE-116",
      "title": "mathlive's Lack of Escaping of HTML allows for XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54705"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-11351",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.11019,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ShinyStat Analytics",
      "cwe": "CWE-200",
      "title": "ShinyStat Analytics < 1.0.17 - Unauthenticated Non-Published Product Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11351"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-66489",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00205,
      "epss_percentile": 0.10856,
      "kev": false,
      "kev_due_at": null,
      "vendor": "balbooa.com",
      "product": "Gridbox extension for Joomla",
      "cwe": "CWE-200",
      "title": "Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66489"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-66488",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00204,
      "epss_percentile": 0.10767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "balbooa.com",
      "product": "Gridbox extension for Joomla",
      "cwe": "CWE-285",
      "title": "Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66488"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-8339",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.1065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Black Duck",
      "product": "Coverity Connect",
      "cwe": "CWE-89",
      "title": "SQL Injection in Coverity Connect SOAP API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8339"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2025-67406",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10582,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execute arbitrary code (remote). The component is: control/activate_case.php,?id=1. The attack vector is: A SQL Injection vulnerability exists in the activate_case.php in parameter id endpoint of Advocate office management system. Unsanitized user input in the specified parameter is interpolated directly into an SQL query, allowing attackers to infer or extract data and, in some cases, execute stacked/time-based payloads. ¶¶ Affected Component & Parameter Affected Endpoint URL: http://localhost/advocate/kortex_lite/control/activate_case.php?id=1 HTTP Method: GET Vulnerable File: activate_case.php Parameter: id Vector Location: GET Injection Techniques (as identified by sqlmap) Type: error-based Title: MySQL >= 5.1 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (EXTRACTVALUE) Payload: id=1 AND EXTRACTVALUE(6268,CONCAT(0x5c,0x71766b6a71,(SELECT (ELT(6268=6268,1))),0x716a7a6b71)) Type: time-based blind Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP) Payload: id=1 AND (SELECT 4464 FROM (SELECT(SLEEP(5)))aHqo) Proof of Concept (Burp Repeater)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67406"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-18236",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00201,
      "epss_percentile": 0.10295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Google-ADK",
      "cwe": "CWE-863",
      "title": "Google-ADK Continuation Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18236"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-12927",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.10317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Schneider Electric",
      "product": "IGSS Definition (Def.exe)",
      "cwe": "CWE-787",
      "title": "CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is imported to IGSS Definition.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12927"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-13113",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.002,
      "epss_percentile": 0.10265,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GitLab",
      "product": "GitLab",
      "cwe": "CWE-367",
      "title": "Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13113"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-5626",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bplugins",
      "product": "Survey Form Block – collect answers and insights from your audience",
      "cwe": "CWE-862",
      "title": "Survey Form Block <= 1.0.1 - Missing Authorization to Authenticated (Subscriber+) Survey Submission Data Export",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5626"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-63118",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09976,
      "kev": false,
      "kev_due_at": null,
      "vendor": "modelcontextprotocol",
      "product": "ruby-sdk",
      "cwe": "CWE-346",
      "title": "MCP Ruby SDK: Streamable HTTP transport lacks DNS-rebinding (Host/Origin) protection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63118"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-54249",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pydantic",
      "product": "pydantic-ai",
      "cwe": "CWE-918",
      "title": "VercelAIAdapter trusts client-controlled `providerMetadata` to construct `UploadedFile` — S3/GCS confused deputy via provider metadata injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54249"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-65975",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09833,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pydantic",
      "product": "pydantic-ai",
      "cwe": "CWE-863",
      "title": "Pydantic AI AG-UI Adapter: A dangling client-submitted tool call can execute when a trailing message is dropped during `sanitize_messages`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65975"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-64685",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-125",
      "title": "ImageMagick: Heap Buffer Over-Read in BGR decoder due to mising end-of-file check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64685"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-63235",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00196,
      "epss_percentile": 0.09646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Three Learning",
      "product": "Koollab LMS",
      "cwe": "CWE-284",
      "title": "Improper access control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63235"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-65891",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "joomlacontenteditor.net",
      "product": "Joomla Content Editor (JCE) extension for Joomla",
      "cwe": "CWE-20",
      "title": "Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE) < 2.9.99.10",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65891"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-7436",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpclever",
      "product": "WPC Badge Management for WooCommerce",
      "cwe": "CWE-79",
      "title": "WPC Badge Management for WooCommerce <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'text' Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7436"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-15735",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09366,
      "kev": false,
      "kev_due_at": null,
      "vendor": "itpathsolutions",
      "product": "Contact Form to Any API",
      "cwe": "CWE-79",
      "title": "Contact Form to Any API <= 3.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15735"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-17161",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpxpo",
      "product": "WowStore – Store Builder & Product Blocks for WooCommerce",
      "cwe": "CWE-79",
      "title": "WowStore <= 4.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'filterMobileText' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17161"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-17162",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09363,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpxpo",
      "product": "WowStore – Store Builder & Product Blocks for WooCommerce",
      "cwe": "CWE-79",
      "title": "WowStore <= 4.4.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'currentPostId' Block Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17162"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-18174",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "@fastify/forwarded",
      "product": "@fastify/forwarded",
      "cwe": "CWE-20",
      "title": "@fastify/forwarded vulnerable to improper input validation via unstripped tab characters in X-Forwarded-For",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18174"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-16463",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00192,
      "epss_percentile": 0.09238,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "AutoCAD",
      "cwe": "CWE-122",
      "title": "DXF File Parsing Heap-Based Overflow in Autodesk AutoCAD",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16463"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-18220",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00186,
      "epss_percentile": 0.08526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-787",
      "title": "Binutils: binutils: out-of-bounds write in bfd dlx elf backend relocation processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18220"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-13306",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08164,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autel",
      "product": "MaxiCharger AC Elite Home",
      "cwe": "CWE-306",
      "title": "Autel MaxiCharger AC Elite Home USB Authentication Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13306"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-13692",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08065,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "PayU CommercePro Plugin",
      "cwe": "CWE-862",
      "title": "PayU CommercePro < 3.9.0 - Unauthenticated Order Tampering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13692"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-16465",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00181,
      "epss_percentile": 0.08037,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "AutoCAD",
      "cwe": "CWE-125",
      "title": "DWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCAD",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16465"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-54663",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07984,
      "kev": false,
      "kev_due_at": null,
      "vendor": "acacode",
      "product": "swagger-typescript-api",
      "cwe": "CWE-20",
      "title": "swagger-typescript-api vulnerable to Server-Side Request Forgery via spec `$ref`",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54663"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-17550",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07684,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autodesk",
      "product": "AutoCAD",
      "cwe": "CWE-125",
      "title": "DWG or DXF File Parsing Out-of-Bounds Read in Autodesk AutoCAD",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17550"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2025-69949",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.07391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters emailid and email.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69949"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-16728",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-444",
      "title": "undici vulnerable to downstream response desynchronization via retry interceptor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16728"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-63240",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Three Learning",
      "product": "Koollab LMS",
      "cwe": "CWE-200",
      "title": "Information disclosure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63240"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-35226",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CODESYS",
      "product": "CODESYS PROFINET",
      "cwe": "CWE-787",
      "title": "Out-of-bounds Write in CODESYS PROFINET Controller",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35226"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2025-67405",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00169,
      "epss_percentile": 0.06676,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67405"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2025-67407",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00169,
      "epss_percentile": 0.06678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters fname and student_class.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67407"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2025-67408",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00169,
      "epss_percentile": 0.06678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter status.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67408"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2025-69944",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00169,
      "epss_percentile": 0.06677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the viewid parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69944"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2025-69945",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00169,
      "epss_percentile": 0.06677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69945"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-16729",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06415,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-74",
      "title": "undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16729"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-63236",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00166,
      "epss_percentile": 0.06387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Three Learning",
      "product": "Koollab LMS",
      "cwe": "CWE-284",
      "title": "Improper access control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63236"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-65325",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Traffic Server",
      "cwe": "CWE-295",
      "title": "Apache Traffic Server: HTTP/2 multiplexed origin sessions are reused without certificate re-verification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65325"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-50641",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0016,
      "epss_percentile": 0.05721,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Streamsoft",
      "product": "Business Intelligence",
      "cwe": "CWE-256",
      "title": "Plaintext password storage in Streamsoft Business Intelligence",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50641"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2025-65337",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address field.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-65337"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-66490",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05145,
      "kev": false,
      "kev_due_at": null,
      "vendor": "balbooa.com",
      "product": "Gridbox extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66490"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-56389",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "Bison",
      "cwe": "CWE-78",
      "title": "Arbitrary Command Execution in GNU Bison",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56389"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-15157",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "undici",
      "product": "undici",
      "cwe": "CWE-93",
      "title": "undici vulnerable to CRLF Injection via blob-like body 'type' property",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15157"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-66400",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-613",
      "title": "Grav Login Plugin before 3.8.13 Insufficient Session Expiration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66400"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-63242",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04909,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Three Learning",
      "product": "Koollab LMS",
      "cwe": "CWE-639",
      "title": "Business logic vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63242"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-13268",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "G DATA",
      "product": "Total Security",
      "cwe": "CWE-59",
      "title": "G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13268"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-65946",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rolandd.com",
      "product": "RO CSVI extension for Joomla",
      "cwe": "CWE-79",
      "title": "Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65946"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-14224",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Easy Appointments",
      "cwe": "CWE-639",
      "title": "Easy Appointments < 3.12.28 - Subscriber+ Cross-User Appointment Data Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14224"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-54574",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00145,
      "epss_percentile": 0.04295,
      "kev": false,
      "kev_due_at": null,
      "vendor": "termux",
      "product": "proot-distro",
      "cwe": "CWE-61",
      "title": "`proot-distro install` has a Symlink Escape (Arbitrary Host File Write) via Malicious Tar Archive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54574"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-15228",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.03853,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Kong/kubernetes-ingress-controller",
      "cwe": "CWE-400",
      "title": "Kong Kubernetes Ingress Controller cluster-wide ingress configuration DoS via CA-certificate ID collision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15228"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-16543",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.03852,
      "kev": false,
      "kev_due_at": null,
      "vendor": null,
      "product": "Kong/kong-operator",
      "cwe": "CWE-400",
      "title": "Kong Operator cluster-wide ingress configuration DoS via embedded KIC CA-certificate ID collision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16543"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-63241",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0014,
      "epss_percentile": 0.03865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Three Learning",
      "product": "Koollab LMS",
      "cwe": "CWE-639",
      "title": "Insecure direct object reference vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63241"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-56390",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00133,
      "epss_percentile": 0.03271,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNU",
      "product": "Bison",
      "cwe": "CWE-73",
      "title": "Arbitrary Output Location Change in GNU Bison",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56390"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-65944",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.0311,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rolandd.com",
      "product": "RO CSVI extension for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65944"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-59247",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0013,
      "epss_percentile": 0.03051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gleam-lang",
      "product": "gleam",
      "cwe": "CWE-345",
      "title": "Insufficient verification of Hex package metadata in Gleam",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59247"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-63119",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "modelcontextprotocol",
      "product": "ruby-sdk",
      "cwe": "CWE-400",
      "title": "MCP Ruby SDK: Unbounded line buffer in stdio transports leads to memory exhaustion (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63119"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-9720",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00128,
      "epss_percentile": 0.02897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "facturadorvirtual",
      "product": "Facturación Electrónica Costa Rica",
      "cwe": "CWE-352",
      "title": "Facturación Electrónica Costa Rica <= 2.0.2 - Cross-Site Request Forgery to Plugin Settings Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9720"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-63228",
      "cvss_base": 2.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00128,
      "epss_percentile": 0.02918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Three Learning",
      "product": "Koollab LMS",
      "cwe": "CWE-434",
      "title": "Unrestricted image upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63228"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-65947",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "balbooa.com",
      "product": "Gridbox extension for Joomla",
      "cwe": "CWE-352",
      "title": "Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65947"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-62343",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00124,
      "epss_percentile": 0.02535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-190",
      "title": "ImageMagick: Heap Buffer Over-Write in morphology operation when an invalid kernel is provided",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62343"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-63239",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00122,
      "epss_percentile": 0.02335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Three Learning",
      "product": "Koollab LMS",
      "cwe": "CWE-798",
      "title": "Hard-coded AWS IAM credentials vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63239"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-54727",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00121,
      "epss_percentile": 0.02262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "termux",
      "product": "proot-distro",
      "cwe": "CWE-668",
      "title": "proot-distro has a Container Isolation Bypass via Crafted Restore Archive",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54727"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-13305",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02299,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Autel",
      "product": "MaxiCharger AC Elite Home",
      "cwe": "CWE-347",
      "title": "Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13305"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-64556",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "perf/core: Detach event groups during remove_on_exec",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64556"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-64558",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/pkey: Check length in pkey_pckmo handler implementation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64558"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-64559",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02148,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "s390/pkey: Check length in PKEY_VERIFYPROTK ioctl",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64559"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-64560",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02194,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "posix-cpu-timers: Prevent UAF caused by non-leader exec() race",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64560"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-14354",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00117,
      "epss_percentile": 0.01918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Schneider Electric",
      "product": "EcoStruxure™ Cybersecurity Admin Expert",
      "cwe": "CWE-522",
      "title": "CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, potentially leading to compromise of managed devices, when a local privileged attacker leverages weaknesses in the handling and protection of stored credentials within the application.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14354"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-63237",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Three Learning",
      "product": "Koollab LMS",
      "cwe": "CWE-347",
      "title": "TOTP two-factor authentication bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63237"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-40272",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "BlackBerry Ltd",
      "product": "QNX Software Development Platform",
      "cwe": "CWE-1284",
      "title": "Vulnerability in the QNX libtraceparser Impacts QNX Software Development Platform",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40272"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-59919",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01622,
      "kev": false,
      "kev_due_at": null,
      "vendor": "netty",
      "product": "netty",
      "cwe": "CWE-93",
      "title": "Netty: HAProxy V1 Protocol CRLF Injection via AF_UNIX Address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59919"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-62995",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00106,
      "epss_percentile": 0.01262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "authlib",
      "product": "joserfc",
      "cwe": "CWE-345",
      "title": "joserfc accepts JWT with padding, leading to JWT malleability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62995"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-52791",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00102,
      "epss_percentile": 0.01087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "containers",
      "product": "fuse-overlayfs",
      "cwe": "CWE-266",
      "title": "fuse-overlayfs release-1.x preserves SUID/SGID bits after truncate/open(O_TRUNC)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52791"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-18257",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00961,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Systerel",
      "product": "S2OPC",
      "cwe": "CWE-295",
      "title": "Improper Certificate Validation in S2OPC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18257"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-10684",
      "cvss_base": 3,
      "cvss_severity": "LOW",
      "epss_score": 0.001,
      "epss_percentile": 0.00966,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read in coredump shell when printing stored-dump target code",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10684"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-14234",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00099,
      "epss_percentile": 0.00946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WOLF",
      "cwe": "CWE-79",
      "title": "WOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14234"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-2482",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00098,
      "epss_percentile": 0.00893,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server - Liberty",
      "cwe": "CWE-352",
      "title": "IBM WebSphere Application Server Liberty is affected by a cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2482"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-44944",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00093,
      "epss_percentile": 0.00627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-iscsi",
      "product": "open-iscsi",
      "cwe": "CWE-863",
      "title": "iscsiuio control-socket authentication bypass in open-iscsi",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44944"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-6102",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00086,
      "epss_percentile": 0.00403,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MSI",
      "product": "MSI Center",
      "cwe": "CWE-346",
      "title": "MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6102"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-8497",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00082,
      "epss_percentile": 0.00264,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Devolutions",
      "product": "Password Manager",
      "cwe": "CWE-295",
      "title": "Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8497"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-67433",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0008,
      "epss_percentile": 0.00196,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linuxfabrik",
      "product": "monitoring-plugins",
      "cwe": "CWE-59",
      "title": "Linuxfabrik monitoring-plugins: Symlink following in logfile legacy database migration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67433"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-29022",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-29022. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-29023",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-29023. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2021-29024",
      "detail": "EXPLOIT PUBLISHED — CVE-2021-29024. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-36271",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-36271. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-38352",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-38352 (Linux). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-34632",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-34632 (Adobe Photoshop Installer). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45700",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45700 (FreeRDP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-50289",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-50289 (sebhildebrandt systeminformation). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54497",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54497 (ViewComponent view_component). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54498",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54498 (ViewComponent view_component). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56821",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56821 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59733",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59733 (rclone). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-59919",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-59919 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-60113",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-60113 (NASA-AMMOS AIT-DSN). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66746",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66746 (tomaka rouille). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66748",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66748 (owen2345 camaleon-cms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66754",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66754 (tomaka rouille). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-56155",
      "detail": "DUE DATE PASSED — CVE-2026-56155 (Microsoft Windows 10 Version 1607). CISA remediation deadline was July 28, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-21537",
      "detail": "RESCORED — CVE-2024-21537 (lilconfig). CVSS 9.3 → 8.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-11541",
      "detail": "RESCORED — CVE-2026-11541 (IBM CICS Transaction Gateway for Multiplatforms). CVSS 7.4 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-49181",
      "detail": "RESCORED — CVE-2026-49181 (Microsoft Windows 10 Version 1607). CVSS 7.5 → 9.8 (NVD)."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2025-38352",
      "detail": "PATCH SHIPPED — CVE-2025-38352 (Linux). Fixed in Linux 5.4.295."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-29022",
      "detail": "ENRICHED — CVE-2021-29022. Received CVSS 5.3 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-29023",
      "detail": "ENRICHED — CVE-2021-29023. Received CVSS 5.3 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-29024",
      "detail": "ENRICHED — CVE-2021-29024. Received CVSS 7.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-53376",
      "detail": "ENRICHED — CVE-2026-53376 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-53377",
      "detail": "ENRICHED — CVE-2026-53377 (Linux). Received CVSS 5.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
