{
  "day": "2026-07-30",
  "boundary": "UTC calendar day",
  "published_count": 662,
  "by_severity": {
    "CRITICAL": 110,
    "HIGH": 199,
    "MEDIUM": 329,
    "LOW": 23
  },
  "kev_count": 1,
  "exploit_reference_count": 6,
  "awaiting_enrichment_count": 1,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-59310",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02405,
      "epss_percentile": 0.82739,
      "kev": true,
      "kev_due_at": "2026-08-21",
      "vendor": "VMware",
      "product": "Cloud Foundation",
      "cwe": "CWE-22",
      "title": "vCenter directory-traversal vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59310"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-67208",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.04233,
      "epss_percentile": 0.90214,
      "kev": false,
      "kev_due_at": null,
      "vendor": "somta",
      "product": "Juggle",
      "cwe": "CWE-306",
      "title": "Juggle 1.6.0 Unauthenticated RCE via Exposed H2 Console",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67208"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-38709",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0267,
      "epss_percentile": 0.84555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the net.set_wan interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38709"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-66066",
      "cvss_base": 9.5,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01767,
      "epss_percentile": 0.76282,
      "kev": false,
      "kev_due_at": null,
      "vendor": "rails",
      "product": "rails",
      "cwe": "CWE-1188",
      "title": "Action Pack: Possible arbitrary file read and remote code execution in Active Storage variant processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66066"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-63362",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.01528,
      "epss_percentile": 0.72683,
      "kev": false,
      "kev_due_at": null,
      "vendor": "o6 Automation",
      "product": "open62541",
      "cwe": "CWE-191",
      "title": "o6 Automation open62541 Integer Underflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63362"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-44098",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.01367,
      "epss_percentile": 0.6965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-78",
      "title": "OS Command Injection in OCPP Agent via charge_box_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44098"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-58218",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.011,
      "epss_percentile": 0.6307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-410",
      "title": "Samba: dns signing dos via tkey name cache exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58218"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-14522",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01016,
      "epss_percentile": 0.60571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "App Connect Enterprise",
      "cwe": "CWE-78",
      "title": "IBM App Connect Enterprise is vulnerable to an arbitrary file read and arbitrary changes to configuration settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14522"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-15969",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00981,
      "epss_percentile": 0.59474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SGLang",
      "product": "SGLang",
      "cwe": "CWE-502",
      "title": "CVE-2026-15969",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15969"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-12943",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0092,
      "epss_percentile": 0.57499,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "HMC V10.3.1050.0",
      "cwe": "CWE-78",
      "title": "This Power Hardware Management Console update is being released to address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12943"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-58222",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00839,
      "epss_percentile": 0.54992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-90",
      "title": "Samba: samba ad ldap compare filter injection and trusted-request confusion disclose protected attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58222"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-44617",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00838,
      "epss_percentile": 0.54964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Zeppelin",
      "cwe": "CWE-90",
      "title": "Apache Zeppelin: LDAP filter injection in LdapRealm — incomplete fix of CVE-2024-31867",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44617"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-52680",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00749,
      "epss_percentile": 0.52095,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Kyuubi",
      "cwe": "CWE-22",
      "title": "Apache Kyuubi: REST batch multipart upload path traversal allows controlled file write",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52680"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-59309",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00744,
      "epss_percentile": 0.51924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VMware",
      "product": "Cloud Foundation",
      "cwe": "CWE-303",
      "title": "vCenter authentication-bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59309"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-15435",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00734,
      "epss_percentile": 0.51577,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "App Connect Enterprise",
      "cwe": "CWE-22",
      "title": "IBM App Connect Enterprise is vulnerable to arbitrary file write vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15435"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-16524",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00652,
      "epss_percentile": 0.48463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-78",
      "title": "Pcp: pcp linux_sockets pmda: arbitrary command execution via command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16524"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-14519",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00623,
      "epss_percentile": 0.47182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "App Connect Enterprise",
      "cwe": "CWE-22",
      "title": "IBM App Connect Enterprise is vulnerable to an arbitrary file read and arbitrary changes to configuration settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14519"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-28323",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00606,
      "epss_percentile": 0.46353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SolarWinds",
      "product": "Web Help Desk",
      "cwe": "CWE-287",
      "title": "SolarWinds Web Help Desk SAML Authentication Bypass Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28323"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-65423",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00605,
      "epss_percentile": 0.46298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "o6 Automation",
      "product": "open62541",
      "cwe": "CWE-190",
      "title": "o6 Automation open62541 Integer Overflow or Wraparound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65423"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-22621",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00584,
      "epss_percentile": 0.45336,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eaton",
      "product": "PADM",
      "cwe": "CWE-78",
      "title": "Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22621"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-16610",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00578,
      "epss_percentile": 0.45051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASE",
      "product": "Admin and Site Enhancements (ASE) Pro",
      "cwe": "CWE-434",
      "title": "Admin and Site Enhancements (ASE) Pro <= 8.9.0 - Unauthenticated Remote Code Execution via PHP Code Injection via cfgroup[input] Repeater Row Key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16610"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-63035",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00572,
      "epss_percentile": 0.4476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "o6 Automation",
      "product": "open62541",
      "cwe": "CWE-416",
      "title": "o6 Automation open62541 Use After Free",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63035"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-1360",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00569,
      "epss_percentile": 0.44624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "buddypress",
      "product": "BuddyPress",
      "cwe": "CWE-502",
      "title": "BuddyPress <= 14.5.0 - Authenticated (Subscriber+) PHP Object Injection via XProfile Field Data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1360"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-41703",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00556,
      "epss_percentile": 0.43934,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VMware",
      "product": "Cloud Foundation",
      "cwe": "CWE-125",
      "title": "Out-of-bounds read vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41703"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-16308",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00549,
      "epss_percentile": 0.43572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Enterprise Build of Quarkus",
      "cwe": "CWE-770",
      "title": "IBM Enterprise Build of Quarkus is affected by a DoS vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16308"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-48449",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00542,
      "epss_percentile": 0.43211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-863",
      "title": "Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48449"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-18245",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00534,
      "epss_percentile": 0.42797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "Amplify Codegen UI",
      "cwe": "CWE-94",
      "title": "Incomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18245"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-68502",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00527,
      "epss_percentile": 0.42419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grisuno",
      "product": "LazyOwn",
      "cwe": "CWE-306",
      "title": "LazyOwn: Unauthenticated Socket.IO `input` Event Reaches LazyOwn Command Dispatcher — Unauthenticated RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68502"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-12940",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00524,
      "epss_percentile": 0.4227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-78",
      "title": "Langflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12940"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-14602",
      "cvss_base": 9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00524,
      "epss_percentile": 0.42262,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Remote API",
      "cwe": "CWE-94",
      "title": "Remote API <= 0.2 - Unauthenticated PHP Object Injection via remote-api Query Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14602"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-59952",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00524,
      "epss_percentile": 0.42261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "open-circle",
      "product": "valibot",
      "cwe": "CWE-755",
      "title": "Valibot: record() issue paths can make flatten() throw for inherited Object property names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59952"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-17544",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00522,
      "epss_percentile": 0.4211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHP Group",
      "product": "PHP",
      "cwe": "CWE-787",
      "title": "Out-of-bounds write in bccomp() via crafted operand and scale",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17544"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-58216",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00515,
      "epss_percentile": 0.41711,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Samba: kpasswd service: kpasswd packet that contains malformed asn.1 might cause the server to access 6 bytes of unallocated memory leading server to crash",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58216"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-12118",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00499,
      "epss_percentile": 0.40701,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "webMethods Integration (on prem)",
      "cwe": "CWE-502",
      "title": "IBM webMethods Integration could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the deserialization of untrusted data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12118"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-16527",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00497,
      "epss_percentile": 0.4062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-306",
      "title": "Pcp: pcp pmproxy: unauthenticated access to /store endpoint allows bypassing pmcd access rules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16527"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-66803",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00484,
      "epss_percentile": 0.39754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Azure Cosmos DB",
      "cwe": "CWE-284",
      "title": "Azure Cosmos DB Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66803"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-28811",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00477,
      "epss_percentile": 0.3936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache JSPWiki",
      "cwe": "CWE-1295",
      "title": "Apache JSPWiki: Error Handling - Reveals Error Details",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28811"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-17543",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00468,
      "epss_percentile": 0.38752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHP Group",
      "product": "PHP",
      "cwe": "CWE-89",
      "title": "SQL injection in ext-pgsql via E'...' backslash breakout",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17543"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-44108",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00462,
      "epss_percentile": 0.38356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-696",
      "title": "Firewall bypass during shutdown",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44108"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-12996",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00461,
      "epss_percentile": 0.38333,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "OpenVPN",
      "cwe": "CWE-125",
      "title": "A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TLS session promotion or expiry",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12996"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-67594",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00455,
      "epss_percentile": 0.37931,
      "kev": false,
      "kev_due_at": null,
      "vendor": "yolanmees",
      "product": "Spikster",
      "cwe": "CWE-306",
      "title": "Spikster Missing Authentication via API Route Group",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67594"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-16526",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00453,
      "epss_percentile": 0.3779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-403",
      "title": "Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16526"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-44616",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00449,
      "epss_percentile": 0.37509,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Zeppelin",
      "cwe": "CWE-90",
      "title": "Apache Zeppelin: LDAP injection in ActiveDirectoryGroupRealm filter construction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44616"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-66756",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00445,
      "epss_percentile": 0.37176,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tika",
      "cwe": "CWE-424",
      "title": "Apache Tika: unpack endpoint in tika-server allows configuration with unsecureFeatures=false",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66756"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-66755",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00443,
      "epss_percentile": 0.37018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Tika",
      "cwe": "CWE-22",
      "title": "Apache Tika: Arbitrary Local File Read in ISArchiveParser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66755"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-17658",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00442,
      "epss_percentile": 0.36992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17658"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-17661",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00442,
      "epss_percentile": 0.36991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17661"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-17665",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00442,
      "epss_percentile": 0.36993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17665"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-17685",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00442,
      "epss_percentile": 0.36992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17685"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-17694",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00442,
      "epss_percentile": 0.36993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in DOM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17694"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-17705",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00442,
      "epss_percentile": 0.36992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in libxml in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17705"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-67206",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00437,
      "epss_percentile": 0.36603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfcms",
      "product": "wolfcms",
      "cwe": "CWE-434",
      "title": "Wolf CMS 0.8.3.1 Authenticated RCE via FileManagerController File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67206"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-18140",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00436,
      "epss_percentile": 0.36523,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "aws-smithy-json",
      "cwe": "CWE-674",
      "title": "Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated remote denial of service in smithy-rs generated servers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18140"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-63559",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00434,
      "epss_percentile": 0.36319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "o6 Automation",
      "product": "open62541",
      "cwe": "CWE-190",
      "title": "o6 Automation open62541 Integer Overflow or Wraparound",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63559"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-17664",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00431,
      "epss_percentile": 0.36073,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17664"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-17681",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0042,
      "epss_percentile": 0.35254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Web Authentication in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17681"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-7849",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00419,
      "epss_percentile": 0.35158,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-77",
      "title": "Command Injection in SCM (idledisconnect parameter)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7849"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-17881",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00418,
      "epss_percentile": 0.35009,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Integer overflow in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17881"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-12932",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00417,
      "epss_percentile": 0.34924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "OpenVPN",
      "cwe": "CWE-401",
      "title": "A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service (memory exhaustion) via a flood of crafted packets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12932"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-12942",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00416,
      "epss_percentile": 0.34839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-22",
      "title": "Langflow is affected by path traversal due to multiple unauthenticated and insufficiently authorized API endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12942"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-53431",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00413,
      "epss_percentile": 0.34616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "malach-it",
      "product": "boruta",
      "cwe": "CWE-294",
      "title": "Boruta accepts expired JWT client assertions due to missing exp claim validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53431"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-17725",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00413,
      "epss_percentile": 0.34624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17725"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-23985",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00413,
      "epss_percentile": 0.34589,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Superset",
      "cwe": "CWE-1333",
      "title": "Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23985"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-28814",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0041,
      "epss_percentile": 0.34371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache JSPWiki",
      "cwe": "CWE-306",
      "title": "Apache JSPWiki: Pre-Authentication Arbitrary Wiki Markup Rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28814"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-15971",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00403,
      "epss_percentile": 0.33767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SGLang",
      "product": "SGLang",
      "cwe": "CWE-95",
      "title": "CVE-2026-15971",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15971"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-28812",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00403,
      "epss_percentile": 0.33673,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache JSPWiki",
      "cwe": "CWE-290",
      "title": "Apache JSPWiki: UserManager does not sanity-check user database at startup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28812"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-17687",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00403,
      "epss_percentile": 0.33672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17687"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-17697",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00403,
      "epss_percentile": 0.33672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17697"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-44090",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00401,
      "epss_percentile": 0.3351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-306",
      "title": "Missing authentication for MQTT Broker",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44090"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-44101",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00401,
      "epss_percentile": 0.33511,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-306",
      "title": "OCPP reconfiguration vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44101"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-17680",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00399,
      "epss_percentile": 0.33354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in Color in Google Chrome on ChromeOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17680"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-17922",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00399,
      "epss_percentile": 0.33332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-94",
      "title": "Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17922"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-57859",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00399,
      "epss_percentile": 0.33222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "e107inc",
      "product": "e107",
      "cwe": "CWE-502",
      "title": "e107 Second-Order Code Execution via eval()-Based Deserialization in e_array::unserialize()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57859"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-13117",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00398,
      "epss_percentile": 0.33122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "OpenVPN",
      "cwe": "CWE-416",
      "title": "An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during TLS session promotion, potentially leading to a denial of service or memory leakage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13117"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-17651",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00397,
      "epss_percentile": 0.33036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17651"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-17652",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00397,
      "epss_percentile": 0.33036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17652"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-17655",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.32987,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17655"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-17656",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00396,
      "epss_percentile": 0.32988,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Ozone in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17656"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-68503",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00395,
      "epss_percentile": 0.32881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "grisuno",
      "product": "LazyOwn",
      "cwe": "CWE-1392",
      "title": "LazyOwn: Default C2 Operator Credentials Enable Administrative Access to C2 Dashboard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68503"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-12947",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00395,
      "epss_percentile": 0.32848,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "App Connect Enterprise",
      "cwe": "CWE-532",
      "title": "IBM App Connect Enterprise is vulnerable to Confidentiality disclosure on Discovery Connector nodes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12947"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-54363",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00394,
      "epss_percentile": 0.32715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gladinet",
      "product": "CentreStack",
      "cwe": "CWE-321",
      "title": "CentreStack < 17.5 Hardcoded Key Token Forgery RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54363"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-54368",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00392,
      "epss_percentile": 0.32541,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gladinet",
      "product": "CentreStack",
      "cwe": "CWE-89",
      "title": "CentreStack < 17.4 SQL Injection via x-glad-filter Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54368"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-10700",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00391,
      "epss_percentile": 0.32377,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-639",
      "title": "Broken Access Control Vulnerabilities in Langflow 1.0.0 - 1.8.4 File Handling API Allowed Unauthorized Access to User Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10700"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-60074",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00387,
      "epss_percentile": 0.32071,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SBECK",
      "product": "Date::Manip",
      "cwe": "CWE-1289",
      "title": "Date::Manip versions through 6.99 for Perl return corrupted dates via non-ASCII decimal digits that pass the numeric range tests in check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60074"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-60075",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00387,
      "epss_percentile": 0.3207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SBECK",
      "product": "Date::Manip",
      "cwe": "CWE-1333",
      "title": "Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60075"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-44613",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00387,
      "epss_percentile": 0.32046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Zeppelin",
      "cwe": "CWE-352",
      "title": "Apache Zeppelin: Cross-site request forgery in REST and WebSocket request handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44613"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-68500",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.31487,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sylius",
      "product": "MolliePlugin",
      "cwe": "CWE-639",
      "title": "Sylius Mollie Plugin: Payment status forgery via the payment webhook",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68500"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-41709",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00382,
      "epss_percentile": 0.31468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VMware",
      "product": "Cloud Foundation",
      "cwe": "CWE-778",
      "title": "ESX insufficient logging vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41709"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-17667",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00381,
      "epss_percentile": 0.31424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17667"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-17668",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00381,
      "epss_percentile": 0.31424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17668"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-17707",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00381,
      "epss_percentile": 0.31424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17707"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-17714",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00381,
      "epss_percentile": 0.31424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17714"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-44092",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0038,
      "epss_percentile": 0.31276,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-93",
      "title": "Missing input validation / stripping of CRLF characters in SystemConfigManager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44092"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-17719",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00379,
      "epss_percentile": 0.31186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17719"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-11771",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00375,
      "epss_percentile": 0.3074,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "OpenVPN",
      "cwe": "CWE-121",
      "title": "OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11771"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-54885",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00372,
      "epss_percentile": 0.30513,
      "kev": false,
      "kev_due_at": null,
      "vendor": "malach-it",
      "product": "boruta",
      "cwe": "CWE-918",
      "title": "Server-side request forgery in Boruta OAuth request_uri and OpenID jwks_uri fetching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54885"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-67351",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30255,
      "kev": false,
      "kev_due_at": null,
      "vendor": "s9y",
      "product": "Serendipity",
      "cwe": "CWE-304",
      "title": "Serendipity < 2.6.1 Authentication Bypass via Username Collision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67351"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-48448",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.3023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-89",
      "title": "Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48448"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-17669",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.30178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17669"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-17670",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.30181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17670"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-17671",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.30182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17671"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-17672",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.30182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17672"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-17673",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.30179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in QUIC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17673"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-17676",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.30181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17676"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-17682",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.30179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17682"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-17684",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.30179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17684"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-17688",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.30182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Input in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17688"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-17691",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.3018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17691"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-17692",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.30181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17692"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-17695",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.30181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17695"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-17704",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.3018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17704"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-17708",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.30183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Audio in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17708"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-17710",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.3018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17710"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-17713",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.30178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Accessibility in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17713"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-17717",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00369,
      "epss_percentile": 0.30182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17717"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-17677",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00369,
      "epss_percentile": 0.30179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17677"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-17678",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00369,
      "epss_percentile": 0.30183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17678"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-35847",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00367,
      "epss_percentile": 0.2995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-35847"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-6540",
      "cvss_base": 7.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00367,
      "epss_percentile": 0.2992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tigera",
      "product": "Calico",
      "cwe": "CWE-22",
      "title": "L7 policy bypass via unnormalized HTTP path matching",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6540"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-16529",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00366,
      "epss_percentile": 0.29829,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-190",
      "title": "Pcp: pcp: denial of service due to signed integer overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16529"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-17751",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29715,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in AdFilter in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17751"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-23981",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00364,
      "epss_percentile": 0.29624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Superset",
      "cwe": "CWE-285",
      "title": "Apache Superset: Improper Authorization in Chart Update allowing Dashboard Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-23981"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-66421",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00363,
      "epss_percentile": 0.29506,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tugcantopaloglu",
      "product": "openclaw-dashboard",
      "cwe": "CWE-79",
      "title": "OpenClaw Dashboard Stored XSS via lastMessage Session Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66421"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-22620",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29464,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eaton",
      "product": "PADM",
      "cwe": "CWE-89",
      "title": "Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22620"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-17896",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00362,
      "epss_percentile": 0.29463,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17896"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-18362",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00357,
      "epss_percentile": 0.28986,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dfir-iris",
      "product": "iris-web",
      "cwe": "CWE-770",
      "title": "DFIR-IRIS Missing Brute Force Protection in User Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18362"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-16531",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00357,
      "epss_percentile": 0.28951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-22",
      "title": "Pcp: pcp: arbitrary file creation via path traversal in pmproxy logger servlet",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16531"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-17701",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00353,
      "epss_percentile": 0.2851,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17701"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-17712",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00353,
      "epss_percentile": 0.28542,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in Skia in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17712"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-17686",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00352,
      "epss_percentile": 0.28446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17686"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-12946",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00351,
      "epss_percentile": 0.28308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Remote Code Execution in CUGA Component CodeAgent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12946"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-17778",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.28149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17778"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-17679",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0035,
      "epss_percentile": 0.28138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Print Preview in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17679"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-17683",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0035,
      "epss_percentile": 0.28139,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17683"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-17650",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00349,
      "epss_percentile": 0.28096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Compositing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17650"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-17653",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00349,
      "epss_percentile": 0.28096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17653"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-48910",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00348,
      "epss_percentile": 0.28039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache JSPWiki",
      "cwe": "CWE-80",
      "title": "Apache JSPWiki: Markdown parser allows XSS injection in Markdown error processing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48910"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-17660",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17660"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-17663",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00347,
      "epss_percentile": 0.27859,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17663"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-11536",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00344,
      "epss_percentile": 0.27566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-502",
      "title": "IBM WebSphere Application Server is affected by a remote code execution vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11536"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-58046",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00343,
      "epss_percentile": 0.27452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "Plesk",
      "cwe": "CWE-89",
      "title": "Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58046"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-41186",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00343,
      "epss_percentile": 0.27456,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tigera",
      "product": "Calico",
      "cwe": "CWE-200",
      "title": "Unauthenticated Go pprof exposure in Calico debug server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41186"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-17758",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00342,
      "epss_percentile": 0.27337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17758"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-68501",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00341,
      "epss_percentile": 0.27203,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sylius",
      "product": "MolliePlugin",
      "cwe": "CWE-639",
      "title": "Sylius Mollie Plugin: Unauthenticated IDOR leaks order token and customer PII",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68501"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-17729",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0034,
      "epss_percentile": 0.27085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17729"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-17935",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26947,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17935"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-13395",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Online Scheduling and Appointment Booking System",
      "cwe": "CWE-89",
      "title": "Bookly < 27.8 - Unauthenticated SQL Injection via staff_id",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13395"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-18064",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26954,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NASA",
      "product": "Core Flight System (cFS) Health & Safety (HS) Application",
      "cwe": "CWE-476",
      "title": "NASA Core Flight System (cFS) Health & Safety (HS) Application NULL Pointer Dereference",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18064"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-66418",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00338,
      "epss_percentile": 0.26849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tugcantopaloglu",
      "product": "openclaw-dashboard",
      "cwe": "CWE-79",
      "title": "OpenClaw Dashboard v3.0.0 Stored XSS via Failed Login Username Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66418"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-13379",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00338,
      "epss_percentile": 0.26869,
      "kev": false,
      "kev_due_at": null,
      "vendor": "OpenVPN",
      "product": "OpenVPN",
      "cwe": "CWE-125",
      "title": "The Windows interactive service in OpenVPN 2.7_alpha1 through 2.7.4 allows remote attackers to cause persistent DNS state pollution or a service crash via a crafted search domain during the disconnection process",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13379"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-62663",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.2657,
      "kev": false,
      "kev_due_at": null,
      "vendor": "masci",
      "product": "banks",
      "cwe": "CWE-22",
      "title": "Banks: Arbitrary File Read via Path Traversal in Media Filters (image/audio/video/document)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62663"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-15976",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00332,
      "epss_percentile": 0.26215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SGLang",
      "product": "SGLang",
      "cwe": "CWE-502",
      "title": "CVE-2026-15976",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15976"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-17868",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00332,
      "epss_percentile": 0.26227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Insufficient policy enforcement in USB in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17868"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-54722",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00328,
      "epss_percentile": 0.25804,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HackingRepo",
      "product": "dssrf-js",
      "cwe": "CWE-76",
      "title": "dssrf: there a critical security bug with remove_at_symbol_in_string",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54722"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-44091",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-501",
      "title": "Creation of a new configuration by posting a malicious ID to MQTT",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44091"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-17759",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00326,
      "epss_percentile": 0.25594,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17759"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-17657",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00325,
      "epss_percentile": 0.2545,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17657"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2025-65336",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00321,
      "epss_percentile": 0.24968,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-65336"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-17674",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.2469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in HTML in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17674"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-17703",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.2469,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17703"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-16971",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00318,
      "epss_percentile": 0.24656,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dfir-iris",
      "product": "iris-web",
      "cwe": "CWE-770",
      "title": "DFIR-IRIS Missing Brute Force Protection in OTP Validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16971"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-17989",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00317,
      "epss_percentile": 0.2452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17989"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-14318",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00317,
      "epss_percentile": 0.24517,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "GiveWP",
      "cwe": "CWE-79",
      "title": "GiveWP < 4.16.3 - GiveWP Worker+ Stored XSS via Donation Form Template Settings",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14318"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-17675",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00316,
      "epss_percentile": 0.24446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17675"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-17718",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00316,
      "epss_percentile": 0.24444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17718"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-17721",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00316,
      "epss_percentile": 0.24446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17721"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-17726",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00316,
      "epss_percentile": 0.24445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-190",
      "title": "Integer overflow in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17726"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-17727",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00316,
      "epss_percentile": 0.24445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-787",
      "title": "Out of bounds write in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17727"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-17738",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00316,
      "epss_percentile": 0.24443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17738"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-17768",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00316,
      "epss_percentile": 0.24443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17768"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-17801",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00316,
      "epss_percentile": 0.24444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read and write in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17801"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-17804",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00316,
      "epss_percentile": 0.24443,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17804"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-17752",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24446,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17752"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-17784",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24444,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Audio in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17784"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-17967",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17967"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-15397",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.24182,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpswings",
      "product": "Subscriptions for WooCommerce",
      "cwe": "CWE-862",
      "title": "Subscriptions for WooCommerce <= 2.0.0 - Missing Authorization to Authenticated (Shop Manager+) Arbitrary Plugin Installation via wps_sfw_install_plugin_configuration AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15397"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-12733",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00313,
      "epss_percentile": 0.24149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataPower Gateway 10.6CD",
      "cwe": "CWE-770",
      "title": "IBM DataPower Gateway affected by denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12733"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-67345",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dromara",
      "product": "MaxKey",
      "cwe": "CWE-183",
      "title": "MaxKey 4.1.12 DefaultRedirectResolver OAuth Authorization Code Theft",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67345"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-10842",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0031,
      "epss_percentile": 0.23793,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-289",
      "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by a security bypass vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10842"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-17689",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0031,
      "epss_percentile": 0.23804,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17689"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-44107",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23669,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-749",
      "title": "Exposed Reboot via Modbus",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44107"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-67246",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00307,
      "epss_percentile": 0.23439,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUSTOR Inc.",
      "product": "ADM",
      "cwe": "CWE-22",
      "title": "A path traversal vulnerability was found in the Wallpaper component of ADM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67246"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-17875",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23187,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17875"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-22622",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eaton",
      "product": "PADM",
      "cwe": "CWE-78",
      "title": "Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-22622"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-9322",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00305,
      "epss_percentile": 0.23208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server",
      "cwe": "CWE-400",
      "title": "IBM WebSphere Application Server and WebSphere Application Server Liberty are affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9322"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-11897",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23102,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server - Liberty",
      "cwe": "CWE-770",
      "title": "IBM WebSphere Application Server Liberty is affected by a denial of service vulnerability with HTTP/2",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11897"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-17887",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in TabStrip in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17887"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-52539",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.2303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-798",
      "title": "Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back to the default value which is publicly visible in the source code repository. An unauthenticated remote attacker can exploit this by forging JWT session tokens with arbitrary user data and full administrative permissions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52539"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-17807",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17807"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-17836",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17836"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-17918",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00303,
      "epss_percentile": 0.22946,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Sync in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17918"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-17698",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22808,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17698"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-67247",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00302,
      "epss_percentile": 0.22866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUSTOR Inc.",
      "product": "ADM",
      "cwe": "CWE-22",
      "title": "A path traversal vulnerability was found in the IHM Log handling of ADM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67247"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-59881",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00302,
      "epss_percentile": 0.22815,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aio-libs",
      "product": "aiohttp",
      "cwe": "CWE-20",
      "title": "AIOHTTP: WebSocket client accepts compressed frames without negotiated permessage-deflate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59881"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-65635",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.2277,
      "kev": false,
      "kev_due_at": null,
      "vendor": "malach-it",
      "product": "boruta",
      "cwe": "CWE-653",
      "title": "Boruta dynamic client registration allows creation of over-privileged OAuth clients",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65635"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-67207",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22603,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wolfcms",
      "product": "wolfcms",
      "cwe": "CWE-697",
      "title": "Wolf CMS 0.8.3.1 Authorization Bypass via BackupRestoreController",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67207"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-61536",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.2263,
      "kev": false,
      "kev_due_at": null,
      "vendor": "masci",
      "product": "banks",
      "cwe": "CWE-94",
      "title": "Banks: Unsafe importlib.import_module of attacker-controlled Tool.import_path in CompletionExtension allows RCE",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61536"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2026-16530",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.2257,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Pcp: pcp: remote denial of service and information leakage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16530"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-17796",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.22571,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17796"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-17800",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.22572,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Inappropriate implementation in MediaRecording in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17800"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-18363",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00298,
      "epss_percentile": 0.22482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Enhancesoft LLC",
      "product": "osTicket",
      "cwe": "CWE-640",
      "title": "Weak password recovery mechanism in osTicket by Enhancesoft LLC",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18363"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-15153",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00297,
      "epss_percentile": 0.22393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Hotel Booking",
      "cwe": "CWE-89",
      "title": "WP Hotel Booking < 2.3.2 - Hotel Manager+ SQL Injection via Booking List Search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15153"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2026-12687",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22237,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ProfileGrid",
      "cwe": "CWE-269",
      "title": "ProfileGrid < 5.9.9.8 - Unauthenticated Privilege Escalation via Unrestricted Group ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12687"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-17709",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00295,
      "epss_percentile": 0.22101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17709"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-17711",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00295,
      "epss_percentile": 0.22101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17711"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-13435",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00294,
      "epss_percentile": 0.22051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-94",
      "title": "Python Interpreter Sandbox Bypass Leading to Sensitive Data Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13435"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-15978",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.21978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SGLang",
      "product": "SGLang",
      "cwe": "CWE-306",
      "title": "CVE-2026-15978",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15978"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-57862",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00293,
      "epss_percentile": 0.21906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Kanboard",
      "product": "Kanboard",
      "cwe": "CWE-918",
      "title": "Kanboard 1.2.52 and prior SSRF Filter Bypass via Hexadecimal IP Notation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57862"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-11904",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00293,
      "epss_percentile": 0.21852,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Verify Identity Access",
      "cwe": "CWE-209",
      "title": "Security vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11904"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-17803",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00292,
      "epss_percentile": 0.21796,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Save to Drive in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17803"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-17956",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in Scheduling in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17956"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-17969",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17969"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-17735",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in BFCache in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17735"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2026-67346",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0029,
      "epss_percentile": 0.2162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kyegomez",
      "product": "swarms",
      "cwe": "CWE-918",
      "title": "Swarms 6.8.1 Server-Side Request Forgery via DNS Rebinding Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67346"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-54366",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gladinet",
      "product": "CentreStack",
      "cwe": "CWE-611",
      "title": "CentreStack < 17.4 XXE via SharePoint Storage Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54366"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-67349",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00286,
      "epss_percentile": 0.21137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opencost",
      "product": "opencost",
      "cwe": "CWE-306",
      "title": "OpenCost < 1.121.0 Unauthenticated Helm Values Exposure and Admin Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67349"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-17696",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17696"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2026-17700",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Actor in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17700"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-17706",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00285,
      "epss_percentile": 0.21043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17706"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-66415",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.21028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Leantime",
      "product": "Leantime",
      "cwe": "CWE-918",
      "title": "Leantime Server-Side Request Forgery and Local File Inclusion in Blueprints::import()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66415"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-56428",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00284,
      "epss_percentile": 0.20975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Bosch",
      "product": "BSH ELP (Electronic Platform) Modules",
      "cwe": "CWE-286",
      "title": "The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuration. An insecure, non-revocable SSH public key is included in the firmware's authorized_keys file for the root user. An attacker in possession of the corresponding private key could leverage it to bypass authentication and gain root-level access to the appliance.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56428"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-47876",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00281,
      "epss_percentile": 0.20677,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VMware",
      "product": "Cloud Foundation",
      "cwe": "CWE-787",
      "title": "VMXNET3 out-of-bounds write vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47876"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-17951",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.2045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-122",
      "title": "Heap buffer overflow in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17951"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-55768",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20424,
      "kev": false,
      "kev_due_at": null,
      "vendor": "allinurl",
      "product": "goaccess",
      "cwe": "CWE-681",
      "title": "GoAccess WebSocket Server: Signed 32 bit truncation of the 64 bit frame length causes a remote pre-authentication denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55768"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-12562",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20368,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Toptech Systems",
      "product": "RCU II+",
      "cwe": "CWE-306",
      "title": "Toptech Systems RCU II+ and Multiload II+ Missing Authentication for Critical Function",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12562"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-66360",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MZ Automation GmbH",
      "product": "libiec61850",
      "cwe": "CWE-125",
      "title": "MZ Automation libiec61850 Out-of-bounds Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66360"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-67244",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20272,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUSTOR Inc.",
      "product": "ADM",
      "cwe": "CWE-134",
      "title": "A format string vulnerability was found in the Notification OAuth settings of ADM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67244"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-17722",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20361,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Object lifecycle issue in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17722"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-17723",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.2036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17723"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-44100",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.20243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-306",
      "title": "JupiCore charging point reconfiguration without auth",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44100"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-67248",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00277,
      "epss_percentile": 0.20172,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUSTOR Inc.",
      "product": "ADM",
      "cwe": "CWE-121",
      "title": "A stack-based buffer overflow vulnerability was found in the File Explorer on the ADM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67248"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-67347",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00277,
      "epss_percentile": 0.20206,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vendurehq",
      "product": "vendure",
      "cwe": "CWE-863",
      "title": "Vendure 3.7.1 Cross-Channel Authorization Bypass via StockLocation and Asset Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67347"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-17847",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00276,
      "epss_percentile": 0.20041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17847"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-17856",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00276,
      "epss_percentile": 0.20041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17856"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-17865",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00276,
      "epss_percentile": 0.20042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17865"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-17884",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.2004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Object lifecycle issue in WebRTC in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17884"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-17886",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17886"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-17894",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.20042,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17894"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-17690",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19678,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in PDF in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17690"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-17756",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Presentation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17756"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-17764",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in FedCM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17764"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-17814",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17814"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-58040",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00272,
      "epss_percentile": 0.19633,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodejs",
      "product": "node",
      "cwe": "CWE-297",
      "title": "An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58040"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-17971",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00271,
      "epss_percentile": 0.19448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Inappropriate implementation in Frame in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17971"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-17946",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17946"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-17968",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0027,
      "epss_percentile": 0.19234,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in WebXR in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17968"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-14356",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.1921,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fleekdash",
      "product": "FleekDash V2",
      "cwe": "CWE-862",
      "title": "FleekDash V2 <= 2.6.2.2 - Missing Authorization to Authenticated (Subscriber+) Administrator Account Takeover via /users/{id} REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14356"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-17950",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in Safebrowsing in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code via a malicious file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17950"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-62246",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00269,
      "epss_percentile": 0.19207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "clastix",
      "product": "kamaji",
      "cwe": "CWE-284",
      "title": "Kamaji: TenantControlPlane namespace/name collision binds two tenants to the same SQL datastore schema + DB user, breaking per-tenant isolation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62246"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-18360",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19029,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dfir-iris",
      "product": "iris-web",
      "cwe": "CWE-79",
      "title": "DFIR-IRIS Stored XSS in Custom Attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18360"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-18361",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dfir-iris",
      "product": "iris-web",
      "cwe": "CWE-79",
      "title": "DFIR-IRIS Stored XSS in Datastore Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18361"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-17816",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00268,
      "epss_percentile": 0.19043,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Insufficient policy enforcement in Speech in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17816"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-18382",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00268,
      "epss_percentile": 0.19094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Cost Management Metrics Operator",
      "cwe": "CWE-918",
      "title": "Project-koku/koku-metrics-operator: koku-metrics-operator: service-account client credentials sent to user-controlled token_url",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18382"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-64816",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00266,
      "epss_percentile": 0.18888,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CyberTimon",
      "product": "RapidRAW",
      "cwe": "CWE-73",
      "title": "RapidRAW < 1.6.0 NTLMv2 Credential Leak via UNC Path in lutPath",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64816"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-65834",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "projectcapsule",
      "product": "capsule",
      "cwe": "CWE-20",
      "title": "Capsule: CapsuleConfiguration NodeMetadata regex fields lack webhook validation, allowing MustCompile panic on all Node admission requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65834"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-17740",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17740"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-17757",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17757"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-17771",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17771"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-17785",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17785"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-17790",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17790"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-17808",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18607,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in WebGL in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17808"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-17810",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00266,
      "epss_percentile": 0.18606,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17810"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2026-18186",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.18525,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUSTOR Inc.",
      "product": "ADM",
      "cwe": "CWE-134",
      "title": "A stored format string vulnerability was found in the FTP Backup on the ADM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18186"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-18187",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.18525,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUSTOR Inc.",
      "product": "ADM",
      "cwe": "CWE-134",
      "title": "A format string vulnerability was found in the Internal Backup on the ADM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18187"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-18188",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00265,
      "epss_percentile": 0.18526,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUSTOR Inc.",
      "product": "ADM",
      "cwe": "CWE-134",
      "title": "A format string vulnerability was found in the Rsync Backup on the ADM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18188"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-61893",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MZ Automation",
      "product": "lib60870",
      "cwe": "CWE-125",
      "title": "MZ Automation lib60870 Out-of-bounds Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61893"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-63033",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18375,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MZ Automation",
      "product": "lib60870",
      "cwe": "CWE-125",
      "title": "MZ Automation lib60870 Out-of-bounds Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63033"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-17791",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17791"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-17792",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Credential Management in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17792"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-17793",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Messages in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17793"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-17831",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00264,
      "epss_percentile": 0.18475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17831"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2024-25039",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Engineering Requirements Management DOORS and DOORS Web Access",
      "cwe": "CWE-400",
      "title": "IBM Engineering Requirements Management DOORS and DOORS Web Access is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-25039"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-54715",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "allinurl",
      "product": "goaccess",
      "cwe": "CWE-122",
      "title": "GoAccess: Heap Out-of-Bounds Write in parse_browser()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54715"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-17892",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17892"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-55777",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18229,
      "kev": false,
      "kev_due_at": null,
      "vendor": "allinurl",
      "product": "goaccess",
      "cwe": "CWE-125",
      "title": "GoAccess: Out-of-bounds heap read in parse_ios() via crafted User-Agent leads to remote crash/DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55777"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-17830",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00262,
      "epss_percentile": 0.18198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17830"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-17869",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00261,
      "epss_percentile": 0.18041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17869"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2025-69930",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69930"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2025-69931",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69931"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2025-69933",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69933"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2025-69934",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69934"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2025-69935",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69935"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2025-69936",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69936"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2025-69937",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69937"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2025-69938",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17937,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69938"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2025-69941",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69941"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2025-69947",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17939,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69947"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-4978",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "UMAI Vision",
      "product": "Traffic Analysis System",
      "cwe": "CWE-89",
      "title": "SQLi in UMAI Vision's Traffic Analysis System",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4978"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-14923",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Sync Post With Other Site",
      "cwe": "CWE-863",
      "title": "Sync Post With Other Site < 1.9.3 - Contributor+ Arbitrary Page Creation/Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14923"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-17992",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17992"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-17851",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17851"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-17859",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17763,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Inappropriate implementation in Favicons in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17859"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-44094",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00258,
      "epss_percentile": 0.1772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-636",
      "title": "Fallback to second RAUC slot with default credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44094"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-12722",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00255,
      "epss_percentile": 0.17273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "FTC Software IT Services",
      "product": "FTC E-Commerce Management Panel",
      "cwe": "CWE-306",
      "title": "Authentication Bypass in FTC Software's E-Commerce Management Panel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12722"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-17848",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00254,
      "epss_percentile": 0.17225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Integer overflow in Codecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17848"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-17832",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00253,
      "epss_percentile": 0.16971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17832"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-17834",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00253,
      "epss_percentile": 0.16971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17834"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-17837",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00253,
      "epss_percentile": 0.1697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17837"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-17924",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00253,
      "epss_percentile": 0.16969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in DNS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17924"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-17940",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00253,
      "epss_percentile": 0.1697,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Picture-in-Picture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17940"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-17947",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00253,
      "epss_percentile": 0.16969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in WebSockets in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17947"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-67348",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.1702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "julep-ai",
      "product": "julep",
      "cwe": "CWE-639",
      "title": "Julep Insecure Direct Object Reference via GET /executions/{execution_id}",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67348"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-12500",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.1709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Travel Engine",
      "cwe": "CWE-862",
      "title": "WP Travel Engine < 6.8.2 - Unauthenticated Trip Difficulty Level Option Update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12500"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-13178",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00253,
      "epss_percentile": 0.17091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Eventin",
      "cwe": "CWE-639",
      "title": "Eventin < 4.1.16 - Unauthenticated Payment Bypass via Order Status Manipulation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13178"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-54364",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00252,
      "epss_percentile": 0.16904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gladinet",
      "product": "CentreStack",
      "cwe": "CWE-116",
      "title": "CentreStack < 17.4 Session Injection via SelectProvider.aspx",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54364"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-63550",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00249,
      "epss_percentile": 0.16512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MZ Automation GmbH",
      "product": "libiec61850",
      "cwe": "CWE-125",
      "title": "MZ Automation libiec61850 Out-of-bounds Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63550"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-16092",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "labelblanc",
      "product": "Improved Save Button",
      "cwe": "CWE-89",
      "title": "Improved Save Button <= 1.2.1 - Authenticated (Author+) Second-Order SQL Injection via 'meta_key' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16092"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-13345",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00245,
      "epss_percentile": 0.16091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Essential Addons for Elementor",
      "cwe": "CWE-639",
      "title": "Essential Addons for Elementor - Lite < 6.6.10 - Unauthenticated Draft/Private WooCommerce Product Disclosure via Compare Table",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13345"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-58066",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00244,
      "epss_percentile": 0.15918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rocket.Chat",
      "product": "Rocket.Chat",
      "cwe": "CWE-287",
      "title": "Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp:Response / saml:Assertion. An attacker could submit a wrapped document carrying forged identity attributes alongside any valid signature made by the trusted IdP certificate, and log in as an arbitrary user.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58066"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-44097",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15883,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-434",
      "title": "File Upload vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44097"
    },
    {
      "rank": 311,
      "cve_id": "CVE-2026-17730",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15852,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17730"
    },
    {
      "rank": 312,
      "cve_id": "CVE-2026-17760",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in NoStatePrefetch in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17760"
    },
    {
      "rank": 313,
      "cve_id": "CVE-2026-17767",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17767"
    },
    {
      "rank": 314,
      "cve_id": "CVE-2026-17769",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15854,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17769"
    },
    {
      "rank": 315,
      "cve_id": "CVE-2026-17772",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17772"
    },
    {
      "rank": 316,
      "cve_id": "CVE-2026-17773",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17773"
    },
    {
      "rank": 317,
      "cve_id": "CVE-2026-17795",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00244,
      "epss_percentile": 0.15853,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Inappropriate implementation in GetUserMedia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17795"
    },
    {
      "rank": 318,
      "cve_id": "CVE-2026-17991",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00243,
      "epss_percentile": 0.15709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17991"
    },
    {
      "rank": 319,
      "cve_id": "CVE-2026-18017",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15685,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18017"
    },
    {
      "rank": 320,
      "cve_id": "CVE-2026-67527",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00242,
      "epss_percentile": 0.15648,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-862",
      "title": "OpenProject: Improper Access Control through /api/v3/work_packages/<X.id> via PATCH parameter \"fileLinks\"",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67527"
    },
    {
      "rank": 321,
      "cve_id": "CVE-2026-17779",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00242,
      "epss_percentile": 0.156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in Site Isolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17779"
    },
    {
      "rank": 322,
      "cve_id": "CVE-2026-14222",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00242,
      "epss_percentile": 0.15621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Easy Appointments",
      "cwe": "CWE-284",
      "title": "Easy Appointments < 3.12.28 - Contributor+ Connection Deletion via Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14222"
    },
    {
      "rank": 323,
      "cve_id": "CVE-2026-17749",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00241,
      "epss_percentile": 0.15555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17749"
    },
    {
      "rank": 324,
      "cve_id": "CVE-2026-44104",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00241,
      "epss_percentile": 0.15536,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-347",
      "title": "ControllerAgent does not perform validation of firmware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44104"
    },
    {
      "rank": 325,
      "cve_id": "CVE-2026-17786",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17786"
    },
    {
      "rank": 326,
      "cve_id": "CVE-2026-15977",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SGLang",
      "product": "SGLang",
      "cwe": "CWE-522",
      "title": "CVE-2026-15977",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15977"
    },
    {
      "rank": 327,
      "cve_id": "CVE-2025-36374",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00241,
      "epss_percentile": 0.15533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "DataPower Gateway 10.6CD",
      "cwe": "CWE-611",
      "title": "IBM DataPower Gateway affected by XML external entity injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36374"
    },
    {
      "rank": 328,
      "cve_id": "CVE-2026-17913",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0024,
      "epss_percentile": 0.15348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17913"
    },
    {
      "rank": 329,
      "cve_id": "CVE-2026-14188",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.0024,
      "epss_percentile": 0.15406,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Easy Appointments",
      "cwe": "CWE-200",
      "title": "Easy Appointments < 3.12.28 - Contributor+ Customer Data Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14188"
    },
    {
      "rank": 330,
      "cve_id": "CVE-2026-18353",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00239,
      "epss_percentile": 0.15309,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eclipse Foundation",
      "product": "Eclipse CSI - PIA",
      "cwe": "CWE-918",
      "title": "Unauthenticated SSRF in PIA via OIDC issuer allowlist bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18353"
    },
    {
      "rank": 331,
      "cve_id": "CVE-2026-48499",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00238,
      "epss_percentile": 0.15103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "activepieces",
      "product": "activepieces",
      "cwe": "CWE-200",
      "title": "Activepieces: Cross-tenant data exposure and code injection via the Code piece sandbox cache",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48499"
    },
    {
      "rank": 332,
      "cve_id": "CVE-2026-17840",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17840"
    },
    {
      "rank": 333,
      "cve_id": "CVE-2026-17850",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Permissions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17850"
    },
    {
      "rank": 334,
      "cve_id": "CVE-2026-17852",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Media Router in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17852"
    },
    {
      "rank": 335,
      "cve_id": "CVE-2026-17662",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in Prefetch in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17662"
    },
    {
      "rank": 336,
      "cve_id": "CVE-2026-17693",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in FileSystem in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17693"
    },
    {
      "rank": 337,
      "cve_id": "CVE-2026-17934",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17934"
    },
    {
      "rank": 338,
      "cve_id": "CVE-2026-17930",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.14993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17930"
    },
    {
      "rank": 339,
      "cve_id": "CVE-2026-17824",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17824"
    },
    {
      "rank": 340,
      "cve_id": "CVE-2026-17873",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17873"
    },
    {
      "rank": 341,
      "cve_id": "CVE-2026-17975",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.1503,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in IME in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17975"
    },
    {
      "rank": 342,
      "cve_id": "CVE-2026-67529",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00237,
      "epss_percentile": 0.14975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-200",
      "title": "OpenProject: Private work package subject/identity disclosure through the global Time Entries and Cost Entries APIs (linked work package rendered without visibility check)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67529"
    },
    {
      "rank": 343,
      "cve_id": "CVE-2026-17995",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00236,
      "epss_percentile": 0.14849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17995"
    },
    {
      "rank": 344,
      "cve_id": "CVE-2026-44103",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00236,
      "epss_percentile": 0.14881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-434",
      "title": "JupiCore does not perform validation of firmware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44103"
    },
    {
      "rank": 345,
      "cve_id": "CVE-2026-14980",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00235,
      "epss_percentile": 0.14699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "WebSphere Application Server - Liberty",
      "cwe": "CWE-269",
      "title": "IBM WebSphere Application Server Liberty is affected by a cross-site request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14980"
    },
    {
      "rank": 346,
      "cve_id": "CVE-2026-17858",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.14482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in WebNN in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17858"
    },
    {
      "rank": 347,
      "cve_id": "CVE-2026-17889",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00233,
      "epss_percentile": 0.14482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17889"
    },
    {
      "rank": 348,
      "cve_id": "CVE-2026-44093",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-78",
      "title": "Local Privilege Escalation vulnerability in /etc/init.d/user-applications via user-application start script",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44093"
    },
    {
      "rank": 349,
      "cve_id": "CVE-2026-44095",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-78",
      "title": "Local Privilege Escalation via Network scripts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44095"
    },
    {
      "rank": 350,
      "cve_id": "CVE-2026-44096",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-78",
      "title": "udhcpc Privilege Escalation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44096"
    },
    {
      "rank": 351,
      "cve_id": "CVE-2026-44099",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14285,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-78",
      "title": "Local Privilege Escalation via pppd password injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44099"
    },
    {
      "rank": 352,
      "cve_id": "CVE-2026-44106",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-78",
      "title": "Local Privilege Escalation vulnerability in /etc/init.d/user-applications via customer website file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44106"
    },
    {
      "rank": 353,
      "cve_id": "CVE-2026-14305",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Delicious",
      "cwe": "CWE-287",
      "title": "WP Delicious < 1.10.2 - Unauthenticated Arbitrary Post Meta Update via recipe_likes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14305"
    },
    {
      "rank": 354,
      "cve_id": "CVE-2026-17782",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17782"
    },
    {
      "rank": 355,
      "cve_id": "CVE-2026-17794",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17794"
    },
    {
      "rank": 356,
      "cve_id": "CVE-2026-17938",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14132,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in FullScreen in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17938"
    },
    {
      "rank": 357,
      "cve_id": "CVE-2026-17941",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17941"
    },
    {
      "rank": 358,
      "cve_id": "CVE-2026-18378",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00229,
      "epss_percentile": 0.13908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Cost Management Metrics Operator",
      "cwe": "CWE-918",
      "title": "Project-koku/koku-metrics-operator: koku-metrics-operator: cluster pull-secret token exfiltration via user-controlled api_url (ssrf / confused deputy)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18378"
    },
    {
      "rank": 359,
      "cve_id": "CVE-2026-15382",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13573,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ultimate Addons for WPBakery Page Builder",
      "cwe": "CWE-73",
      "title": "Ultimate Addons for WPBakery Page Builder < 3.21.4 - Unauthenticated Custom Icon Font Deletion via delete-bsf-fonts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15382"
    },
    {
      "rank": 360,
      "cve_id": "CVE-2026-17849",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.1356,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17849"
    },
    {
      "rank": 361,
      "cve_id": "CVE-2026-17805",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Glic in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17805"
    },
    {
      "rank": 362,
      "cve_id": "CVE-2026-17813",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17813"
    },
    {
      "rank": 363,
      "cve_id": "CVE-2026-17921",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17921"
    },
    {
      "rank": 364,
      "cve_id": "CVE-2026-17926",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17926"
    },
    {
      "rank": 365,
      "cve_id": "CVE-2026-17931",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17931"
    },
    {
      "rank": 366,
      "cve_id": "CVE-2026-17953",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17953"
    },
    {
      "rank": 367,
      "cve_id": "CVE-2026-17659",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13414,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17659"
    },
    {
      "rank": 368,
      "cve_id": "CVE-2026-17987",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00224,
      "epss_percentile": 0.13294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Notifications in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17987"
    },
    {
      "rank": 369,
      "cve_id": "CVE-2026-17990",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00224,
      "epss_percentile": 0.13294,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17990"
    },
    {
      "rank": 370,
      "cve_id": "CVE-2026-14226",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Easy Appointments",
      "cwe": "CWE-200",
      "title": "Easy Appointments < 3.12.28 - Subscriber+ Sensitive Information Disclosure via REST Appointments Listing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14226"
    },
    {
      "rank": 371,
      "cve_id": "CVE-2026-14231",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.1332,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "LifterLMS",
      "cwe": "CWE-200",
      "title": "LifterLMS < 10.0.10 - Subscriber+ Sensitive Information Disclosure via select2_query_posts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14231"
    },
    {
      "rank": 372,
      "cve_id": "CVE-2026-15235",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "MotoPress Hotel Booking",
      "cwe": "CWE-200",
      "title": "Hotel Booking Lite < 6.0.4 - Subscriber+ Sensitive Data Disclosure via Admin Calendar AJAX Action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15235"
    },
    {
      "rank": 373,
      "cve_id": "CVE-2026-18012",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00223,
      "epss_percentile": 0.13241,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18012"
    },
    {
      "rank": 374,
      "cve_id": "CVE-2026-17920",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13081,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17920"
    },
    {
      "rank": 375,
      "cve_id": "CVE-2026-14227",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00222,
      "epss_percentile": 0.13079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MikroTik",
      "product": "RouterOS",
      "cwe": "CWE-613",
      "title": "Insufficient session expiration in MikroTik RouterOS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14227"
    },
    {
      "rank": 376,
      "cve_id": "CVE-2026-10545",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Planning Analytics Local",
      "cwe": "CWE-601",
      "title": "IBM Planning Analytics Local is affected by Open Redirect",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10545"
    },
    {
      "rank": 377,
      "cve_id": "CVE-2026-11782",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Points and Rewards for WooCommerce",
      "cwe": "CWE-284",
      "title": "Points and Rewards for WooCommerce < 2.10.1 - Unauthenticated Arbitrary User Wallet & Points Manipulation via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11782"
    },
    {
      "rank": 378,
      "cve_id": "CVE-2026-13143",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Travel",
      "cwe": "CWE-290",
      "title": "WP Travel < 11.8.1 - Unauthenticated Payment Bypass via Forged PayPal IPN",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13143"
    },
    {
      "rank": 379,
      "cve_id": "CVE-2026-17855",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0022,
      "epss_percentile": 0.12797,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in DevTools in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17855"
    },
    {
      "rank": 380,
      "cve_id": "CVE-2026-41187",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tigera",
      "product": "Calico",
      "cwe": "CWE-285",
      "title": "Calico Tier Authorization Bypass via DeleteCollection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41187"
    },
    {
      "rank": 381,
      "cve_id": "CVE-2026-17914",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.12756,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17914"
    },
    {
      "rank": 382,
      "cve_id": "CVE-2026-17949",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0022,
      "epss_percentile": 0.1273,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-457",
      "title": "Uninitialized Use in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17949"
    },
    {
      "rank": 383,
      "cve_id": "CVE-2026-68562",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12722,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-610",
      "title": "Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure via leapp report tampering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68562"
    },
    {
      "rank": 384,
      "cve_id": "CVE-2026-17743",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in ControlledFrame in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17743"
    },
    {
      "rank": 385,
      "cve_id": "CVE-2026-17748",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17748"
    },
    {
      "rank": 386,
      "cve_id": "CVE-2026-17754",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17754"
    },
    {
      "rank": 387,
      "cve_id": "CVE-2026-17787",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17787"
    },
    {
      "rank": 388,
      "cve_id": "CVE-2026-17819",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in WebAppInstalls in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17819"
    },
    {
      "rank": 389,
      "cve_id": "CVE-2026-17828",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17828"
    },
    {
      "rank": 390,
      "cve_id": "CVE-2026-17835",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17835"
    },
    {
      "rank": 391,
      "cve_id": "CVE-2026-17838",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12597,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17838"
    },
    {
      "rank": 392,
      "cve_id": "CVE-2026-17839",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00218,
      "epss_percentile": 0.12598,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17839"
    },
    {
      "rank": 393,
      "cve_id": "CVE-2026-11707",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00217,
      "epss_percentile": 0.12434,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Tivoli System Automation Application Manager",
      "cwe": "CWE-79",
      "title": "Multiple vulnerabilities have been identified in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11707"
    },
    {
      "rank": 394,
      "cve_id": "CVE-2026-17825",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in Passwords in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17825"
    },
    {
      "rank": 395,
      "cve_id": "CVE-2026-17917",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12411,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17917"
    },
    {
      "rank": 396,
      "cve_id": "CVE-2025-51684",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00217,
      "epss_percentile": 0.12457,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data received via window.postMessage before injecting it into the page DOM. An attacker can craft a malicious message that, when processed by renderCustomHtml, results in execution of arbitrary JavaScript in the context of the hosting site.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-51684"
    },
    {
      "rank": 397,
      "cve_id": "CVE-2026-54365",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00216,
      "epss_percentile": 0.12374,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gladinet",
      "product": "CentreStack",
      "cwe": "CWE-306",
      "title": "CentreStack < 17.3 Unauthenticated User Creation via Deserialization in GSNamespace.dll",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54365"
    },
    {
      "rank": 398,
      "cve_id": "CVE-2026-17985",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17985"
    },
    {
      "rank": 399,
      "cve_id": "CVE-2026-17988",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12351,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17988"
    },
    {
      "rank": 400,
      "cve_id": "CVE-2026-17747",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Payments in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17747"
    },
    {
      "rank": 401,
      "cve_id": "CVE-2026-12945",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.1218,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-639",
      "title": "Langflow is affected by exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12945"
    },
    {
      "rank": 402,
      "cve_id": "CVE-2026-67245",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00215,
      "epss_percentile": 0.1225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUSTOR Inc.",
      "product": "ADM",
      "cwe": "CWE-22",
      "title": "A path traversal vulnerability was found in the VPN Clients on the ADM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67245"
    },
    {
      "rank": 403,
      "cve_id": "CVE-2026-64870",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00215,
      "epss_percentile": 0.12211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "1Panel-dev",
      "product": "MaxKB",
      "cwe": "CWE-918",
      "title": "MaxKB: UpdateStoreTool fetches caller-supplied app-store URLs without host validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64870"
    },
    {
      "rank": 404,
      "cve_id": "CVE-2026-17909",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00214,
      "epss_percentile": 0.12127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via malicious network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17909"
    },
    {
      "rank": 405,
      "cve_id": "CVE-2026-17879",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17879"
    },
    {
      "rank": 406,
      "cve_id": "CVE-2026-17880",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17880"
    },
    {
      "rank": 407,
      "cve_id": "CVE-2026-13444",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11809,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Langflow OSS",
      "cwe": "CWE-520",
      "title": "Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13444"
    },
    {
      "rank": 408,
      "cve_id": "CVE-2026-11867",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.1183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Frontend Admin by DynamiApps",
      "cwe": "CWE-862",
      "title": "Frontend Admin by DynamiApps < 3.29.7 - Subscriber+ Taxonomy Term Creation/Modification/Deletion via Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11867"
    },
    {
      "rank": 409,
      "cve_id": "CVE-2026-15250",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Appointment Booking Plugin",
      "cwe": "CWE-284",
      "title": "LatePoint < 5.6.8 - Unauthenticated Booking Object Mass Assignment via Public Booking Funnel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15250"
    },
    {
      "rank": 410,
      "cve_id": "CVE-2026-17978",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00211,
      "epss_percentile": 0.1167,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in WebCodecs in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17978"
    },
    {
      "rank": 411,
      "cve_id": "CVE-2026-17874",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17874"
    },
    {
      "rank": 412,
      "cve_id": "CVE-2026-67528",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.1149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "opf",
      "product": "openproject",
      "cwe": "CWE-863",
      "title": "OpenProject: Improper Access Control through /api/v3/custom_options/:id via Path \"id\" leads to Sensitive Data Exposure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67528"
    },
    {
      "rank": 413,
      "cve_id": "CVE-2026-44102",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11389,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-362",
      "title": "OCPP Firmware download is not properly locked",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44102"
    },
    {
      "rank": 414,
      "cve_id": "CVE-2026-15974",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11317,
      "kev": false,
      "kev_due_at": null,
      "vendor": "SGLang",
      "product": "SGLang",
      "cwe": "CWE-918",
      "title": "CVE-2026-15974",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15974"
    },
    {
      "rank": 415,
      "cve_id": "CVE-2026-17780",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.1143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17780"
    },
    {
      "rank": 416,
      "cve_id": "CVE-2026-14592",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00209,
      "epss_percentile": 0.11419,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Real IP-based Access Control",
      "cwe": "CWE-79",
      "title": "WP Real IP-based Access Control <= 1.3.1 - Unauthenticated Stored XSS via acl_ctrl_addr",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14592"
    },
    {
      "rank": 417,
      "cve_id": "CVE-2026-17789",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.1122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17789"
    },
    {
      "rank": 418,
      "cve_id": "CVE-2026-17923",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.1122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Policy bypass in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted domain name. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17923"
    },
    {
      "rank": 419,
      "cve_id": "CVE-2026-17929",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.1122,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17929"
    },
    {
      "rank": 420,
      "cve_id": "CVE-2026-17986",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17986"
    },
    {
      "rank": 421,
      "cve_id": "CVE-2026-17797",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17797"
    },
    {
      "rank": 422,
      "cve_id": "CVE-2026-17728",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17728"
    },
    {
      "rank": 423,
      "cve_id": "CVE-2026-17734",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17734"
    },
    {
      "rank": 424,
      "cve_id": "CVE-2026-14223",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00206,
      "epss_percentile": 0.10926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Easy Appointments",
      "cwe": "CWE-639",
      "title": "Easy Appointments < 3.12.28 - Subscriber+ Customer PII Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14223"
    },
    {
      "rank": 425,
      "cve_id": "CVE-2026-17702",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00206,
      "epss_percentile": 0.10927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17702"
    },
    {
      "rank": 426,
      "cve_id": "CVE-2026-17715",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00206,
      "epss_percentile": 0.10926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17715"
    },
    {
      "rank": 427,
      "cve_id": "CVE-2026-15240",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.10753,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Customer Switching",
      "cwe": "CWE-287",
      "title": "Customer Switching for WooCommerce < 2.1.3 - Customer+ Privilege Escalation to Administrator via Insecure Operator Resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15240"
    },
    {
      "rank": 428,
      "cve_id": "CVE-2026-17741",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.10742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17741"
    },
    {
      "rank": 429,
      "cve_id": "CVE-2026-17750",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00204,
      "epss_percentile": 0.10742,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17750"
    },
    {
      "rank": 430,
      "cve_id": "CVE-2026-17979",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.10619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17979"
    },
    {
      "rank": 431,
      "cve_id": "CVE-2026-18002",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00202,
      "epss_percentile": 0.10497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18002"
    },
    {
      "rank": 432,
      "cve_id": "CVE-2026-18015",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00202,
      "epss_percentile": 0.10497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18015"
    },
    {
      "rank": 433,
      "cve_id": "CVE-2026-15255",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00202,
      "epss_percentile": 0.10436,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "RegistrationMagic",
      "cwe": "CWE-639",
      "title": "RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15255"
    },
    {
      "rank": 434,
      "cve_id": "CVE-2026-15658",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00201,
      "epss_percentile": 0.10304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "foreUP",
      "product": "foreUP",
      "cwe": "CWE-639",
      "title": "foreUP customer REST API allows unauthenticated endpoint access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15658"
    },
    {
      "rank": 435,
      "cve_id": "CVE-2026-15657",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "foreUP",
      "product": "foreUP",
      "cwe": "CWE-522",
      "title": "foreUP customer REST API allows authenticated users to read cleartext payment-processor merchant credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15657"
    },
    {
      "rank": 436,
      "cve_id": "CVE-2026-17731",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Autofill in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17731"
    },
    {
      "rank": 437,
      "cve_id": "CVE-2026-17733",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in QUIC in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17733"
    },
    {
      "rank": 438,
      "cve_id": "CVE-2026-17742",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17742"
    },
    {
      "rank": 439,
      "cve_id": "CVE-2026-17753",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17753"
    },
    {
      "rank": 440,
      "cve_id": "CVE-2026-17762",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17762"
    },
    {
      "rank": 441,
      "cve_id": "CVE-2026-17763",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10322,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in GPU in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17763"
    },
    {
      "rank": 442,
      "cve_id": "CVE-2026-17765",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10324,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in WebProtect in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17765"
    },
    {
      "rank": 443,
      "cve_id": "CVE-2026-17775",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in PresentationAPI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17775"
    },
    {
      "rank": 444,
      "cve_id": "CVE-2026-17777",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17777"
    },
    {
      "rank": 445,
      "cve_id": "CVE-2026-17788",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17788"
    },
    {
      "rank": 446,
      "cve_id": "CVE-2026-17798",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17798"
    },
    {
      "rank": 447,
      "cve_id": "CVE-2026-17802",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in GPU in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17802"
    },
    {
      "rank": 448,
      "cve_id": "CVE-2026-17815",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10325,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in GuestView in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17815"
    },
    {
      "rank": 449,
      "cve_id": "CVE-2026-17820",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17820"
    },
    {
      "rank": 450,
      "cve_id": "CVE-2026-17829",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10323,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17829"
    },
    {
      "rank": 451,
      "cve_id": "CVE-2026-17928",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in DataTransfer in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17928"
    },
    {
      "rank": 452,
      "cve_id": "CVE-2026-17942",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10381,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17942"
    },
    {
      "rank": 453,
      "cve_id": "CVE-2026-15054",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00201,
      "epss_percentile": 0.10329,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Bit Form",
      "cwe": "CWE-862",
      "title": "Bit Form < 3.1.2 - Unauthenticated Inactive Form Submission",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15054"
    },
    {
      "rank": 454,
      "cve_id": "CVE-2026-17799",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass discretionary access control via a malicious file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17799"
    },
    {
      "rank": 455,
      "cve_id": "CVE-2026-17812",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in DigitalCredentials in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17812"
    },
    {
      "rank": 456,
      "cve_id": "CVE-2026-17915",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00198,
      "epss_percentile": 0.09973,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17915"
    },
    {
      "rank": 457,
      "cve_id": "CVE-2026-47858",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00197,
      "epss_percentile": 0.09832,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Tools for Eclipse",
      "cwe": "CWE-306",
      "title": "live information startup mode is vulnerable for remote code execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47858"
    },
    {
      "rank": 458,
      "cve_id": "CVE-2026-17744",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00197,
      "epss_percentile": 0.09761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in File Input in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17744"
    },
    {
      "rank": 459,
      "cve_id": "CVE-2026-18001",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18001"
    },
    {
      "rank": 460,
      "cve_id": "CVE-2026-18005",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09896,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18005"
    },
    {
      "rank": 461,
      "cve_id": "CVE-2026-66414",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09899,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Leantime",
      "product": "Leantime",
      "cwe": "CWE-601",
      "title": "Leantime Open Redirect in Login Controller via redirectUrl Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66414"
    },
    {
      "rank": 462,
      "cve_id": "CVE-2026-13145",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09792,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Travel",
      "cwe": "CWE-639",
      "title": "WP Travel < 11.8.1 - Subscriber+ Booking PII Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13145"
    },
    {
      "rank": 463,
      "cve_id": "CVE-2026-1982",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09649,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mohammadr3z",
      "product": "المنتور فارسی",
      "cwe": "CWE-472",
      "title": "Persian Elementor (المنتور فارسی) <= 2.8.1 - Unauthenticated Price Manipulation via ZarinPal Widget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-1982"
    },
    {
      "rank": 464,
      "cve_id": "CVE-2026-62845",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "clastix",
      "product": "kamaji",
      "cwe": "CWE-89",
      "title": "Kamaji: SQL injection via unescaped datastore identifiers in PostgreSQL/MySQL drivers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62845"
    },
    {
      "rank": 465,
      "cve_id": "CVE-2026-17937",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17937"
    },
    {
      "rank": 466,
      "cve_id": "CVE-2026-17943",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09728,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Inappropriate implementation in Parser in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17943"
    },
    {
      "rank": 467,
      "cve_id": "CVE-2026-17960",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass no-referrer policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17960"
    },
    {
      "rank": 468,
      "cve_id": "CVE-2026-18369",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00195,
      "epss_percentile": 0.09531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Certificate System 10",
      "cwe": "CWE-918",
      "title": "Dogtag-pki: pki-core: redhat-pki: pki: acme http-01 validation ssrf via ip literal identifiers and unvalidated redirects",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18369"
    },
    {
      "rank": 469,
      "cve_id": "CVE-2026-17898",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.0952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17898"
    },
    {
      "rank": 470,
      "cve_id": "CVE-2026-17948",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00194,
      "epss_percentile": 0.0952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17948"
    },
    {
      "rank": 471,
      "cve_id": "CVE-2026-17842",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.0948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17842"
    },
    {
      "rank": 472,
      "cve_id": "CVE-2026-17846",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Media in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17846"
    },
    {
      "rank": 473,
      "cve_id": "CVE-2026-17854",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09479,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in WebMCP in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17854"
    },
    {
      "rank": 474,
      "cve_id": "CVE-2026-17883",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.0948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Headless in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17883"
    },
    {
      "rank": 475,
      "cve_id": "CVE-2026-61526",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.0943,
      "kev": false,
      "kev_due_at": null,
      "vendor": "adonisjs",
      "product": "http-server",
      "cwe": "CWE-79",
      "title": "AdonisJS HTTP Server is vulnerable to reflected XSS through its exception handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61526"
    },
    {
      "rank": 476,
      "cve_id": "CVE-2026-14221",
      "cvss_base": 3.8,
      "cvss_severity": "LOW",
      "epss_score": 0.00194,
      "epss_percentile": 0.09442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Easy Appointments",
      "cwe": "CWE-284",
      "title": "Easy Appointments <= 4.0 - Contributor+ Appointment Data Disclosure & Modification via Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14221"
    },
    {
      "rank": 477,
      "cve_id": "CVE-2026-17899",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00193,
      "epss_percentile": 0.09304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17899"
    },
    {
      "rank": 478,
      "cve_id": "CVE-2026-17907",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17907"
    },
    {
      "rank": 479,
      "cve_id": "CVE-2026-65835",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.0925,
      "kev": false,
      "kev_due_at": null,
      "vendor": "projectcapsule",
      "product": "capsule",
      "cwe": "CWE-269",
      "title": "Capsule: Incomplete fix of CVE-2026-22872: TenantResource RawItems and Generators still allow cluster-scoped resource creation (cross-tenant privilege escalation)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65835"
    },
    {
      "rank": 480,
      "cve_id": "CVE-2026-14207",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09261,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "LifterLMS",
      "cwe": "CWE-79",
      "title": "LifterLMS < 10.0.10 - Instructor+ Stored XSS via Featured Pricing Information",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14207"
    },
    {
      "rank": 481,
      "cve_id": "CVE-2026-17736",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09204,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17736"
    },
    {
      "rank": 482,
      "cve_id": "CVE-2026-17761",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17761"
    },
    {
      "rank": 483,
      "cve_id": "CVE-2026-28813",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0019,
      "epss_percentile": 0.09026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache JSPWiki",
      "cwe": "CWE-352",
      "title": "Apache JSPWiki: JSPWiki vulnerable to JSON hijacking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28813"
    },
    {
      "rank": 484,
      "cve_id": "CVE-2026-15257",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.0897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "RegistrationMagic",
      "cwe": "CWE-639",
      "title": "RegistrationMagic < 6.0.9.4 - Unauthenticated Form Submission and User Profile Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15257"
    },
    {
      "rank": 485,
      "cve_id": "CVE-2026-64635",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.09044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Veeam",
      "product": "Service Provider Console",
      "cwe": "CWE-640",
      "title": "Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an unauthenticated attacker to control the domain of the generated password reset link. When the targeted user clicks the link delivered by email, the reset code is transmitted to an attacker-controlled host, allowing the attacker to take over the account.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64635"
    },
    {
      "rank": 486,
      "cve_id": "CVE-2026-17945",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.09056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17945"
    },
    {
      "rank": 487,
      "cve_id": "CVE-2026-17955",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.09057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17955"
    },
    {
      "rank": 488,
      "cve_id": "CVE-2026-17958",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.09058,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Views in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17958"
    },
    {
      "rank": 489,
      "cve_id": "CVE-2026-17964",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.09057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17964"
    },
    {
      "rank": 490,
      "cve_id": "CVE-2026-17965",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.09057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17965"
    },
    {
      "rank": 491,
      "cve_id": "CVE-2026-17972",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0019,
      "epss_percentile": 0.09057,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17972"
    },
    {
      "rank": 492,
      "cve_id": "CVE-2026-17902",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.0019,
      "epss_percentile": 0.0907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in Editing in Google Chrome on Linux prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17902"
    },
    {
      "rank": 493,
      "cve_id": "CVE-2026-17666",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00189,
      "epss_percentile": 0.08872,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-325",
      "title": "Cryptographic Flaw in Enterprise in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to bypass discretionary access control via malicious network traffic. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17666"
    },
    {
      "rank": 494,
      "cve_id": "CVE-2026-17912",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-601",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17912"
    },
    {
      "rank": 495,
      "cve_id": "CVE-2026-17944",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17944"
    },
    {
      "rank": 496,
      "cve_id": "CVE-2026-17961",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00189,
      "epss_percentile": 0.08881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Session in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17961"
    },
    {
      "rank": 497,
      "cve_id": "CVE-2026-54367",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.08713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Gladinet",
      "product": "CentreStack",
      "cwe": "CWE-306",
      "title": "CentreStack < 17.2 Unauthenticated API Authorization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54367"
    },
    {
      "rank": 498,
      "cve_id": "CVE-2026-18381",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.08779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Cost Management Metrics Operator",
      "cwe": "CWE-918",
      "title": "Project-koku/koku-metrics-operator: koku-metrics-operator: operator service-account token exfiltration via user-controlled prometheus service_address",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18381"
    },
    {
      "rank": 499,
      "cve_id": "CVE-2026-11870",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.0875,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Ghost (Hide My WP Ghost)",
      "cwe": "CWE-290",
      "title": "Hide My WP Ghost < 7.0.05 - IP Address Spoofing via Trusted Proxy Headers Leading to Protection Mechanism Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11870"
    },
    {
      "rank": 500,
      "cve_id": "CVE-2026-17982",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00188,
      "epss_percentile": 0.08823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17982"
    },
    {
      "rank": 501,
      "cve_id": "CVE-2026-17952",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00187,
      "epss_percentile": 0.08687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17952"
    },
    {
      "rank": 502,
      "cve_id": "CVE-2026-17882",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08702,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Policy bypass in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17882"
    },
    {
      "rank": 503,
      "cve_id": "CVE-2026-18003",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00187,
      "epss_percentile": 0.08625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18003"
    },
    {
      "rank": 504,
      "cve_id": "CVE-2026-47873",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00184,
      "epss_percentile": 0.08337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Tools for Eclipse",
      "cwe": "CWE-1327",
      "title": "Spring Tools Docker integration publishes unauthenticated debug (JDWP) and JMX ports on all network interfaces",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47873"
    },
    {
      "rank": 505,
      "cve_id": "CVE-2026-16969",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00183,
      "epss_percentile": 0.08249,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dfir-iris",
      "product": "iris-web",
      "cwe": "CWE-79",
      "title": "DFIR-IRIS Stored XSS in Assets",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16969"
    },
    {
      "rank": 506,
      "cve_id": "CVE-2026-17983",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00183,
      "epss_percentile": 0.08193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Global Media Controls in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17983"
    },
    {
      "rank": 507,
      "cve_id": "CVE-2026-17845",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08126,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17845"
    },
    {
      "rank": 508,
      "cve_id": "CVE-2026-16970",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dfir-iris",
      "product": "iris-web",
      "cwe": "CWE-613",
      "title": "DFIR-IRIS Insufficient Logout Implementation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16970"
    },
    {
      "rank": 509,
      "cve_id": "CVE-2022-4994",
      "cvss_base": null,
      "cvss_severity": null,
      "epss_score": 0.00182,
      "epss_percentile": 0.08117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Linux",
      "product": "Linux",
      "cwe": null,
      "title": "KVM: x86: wean fast IN from emulator_pio_in",
      "url": "https://www.cve.org/CVERecord?id=CVE-2022-4994"
    },
    {
      "rank": 510,
      "cve_id": "CVE-2026-56758",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MZ Automation GmbH",
      "product": "libiec61850",
      "cwe": "CWE-125",
      "title": "MZ Automation libiec61850 Out-of-bounds Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56758"
    },
    {
      "rank": 511,
      "cve_id": "CVE-2026-66349",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07967,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MZ Automation GmbH",
      "product": "libiec61850",
      "cwe": "CWE-125",
      "title": "MZ Automation libiec61850 Out-of-bounds Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66349"
    },
    {
      "rank": 512,
      "cve_id": "CVE-2026-11881",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07993,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Fluent Forms",
      "cwe": "CWE-79",
      "title": "Fluent Forms < 6.2.6 - Contributor+ Stored XSS via Date/Time Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11881"
    },
    {
      "rank": 513,
      "cve_id": "CVE-2026-13330",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Animation Addons for Elementor",
      "cwe": "CWE-79",
      "title": "Animation Addons for Elementor < 2.7.0 - Author+ Stored XSS via SVG Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13330"
    },
    {
      "rank": 514,
      "cve_id": "CVE-2026-17776",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Policy bypass in Receiver in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17776"
    },
    {
      "rank": 515,
      "cve_id": "CVE-2026-17901",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.08007,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Sharing in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via malicious network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17901"
    },
    {
      "rank": 516,
      "cve_id": "CVE-2026-17994",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.08044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Media in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17994"
    },
    {
      "rank": 517,
      "cve_id": "CVE-2026-10031",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00181,
      "epss_percentile": 0.08051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "drakkan",
      "product": "SFTPGo",
      "cwe": "CWE-863",
      "title": "SFTPGo 2.7.4 Permission Bypass via Symbolic Link Creation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10031"
    },
    {
      "rank": 518,
      "cve_id": "CVE-2026-17745",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.0781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17745"
    },
    {
      "rank": 519,
      "cve_id": "CVE-2026-17746",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.0781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in GPU in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17746"
    },
    {
      "rank": 520,
      "cve_id": "CVE-2026-17770",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07811,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-125",
      "title": "Out of bounds read in Media in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17770"
    },
    {
      "rank": 521,
      "cve_id": "CVE-2026-17737",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.0781,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Bluetooth in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17737"
    },
    {
      "rank": 522,
      "cve_id": "CVE-2026-10569",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07924,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "UCD - IBM UrbanCode Deploy",
      "cwe": "CWE-200",
      "title": "IBM DevOps Deploy / IBM UrbanCode Deploy (UCD) is susceptible to an Exposure of Sensitive Information Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10569"
    },
    {
      "rank": 523,
      "cve_id": "CVE-2026-17867",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00179,
      "epss_percentile": 0.07764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17867"
    },
    {
      "rank": 524,
      "cve_id": "CVE-2026-17781",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00179,
      "epss_percentile": 0.07749,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17781"
    },
    {
      "rank": 525,
      "cve_id": "CVE-2026-17823",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07627,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17823"
    },
    {
      "rank": 526,
      "cve_id": "CVE-2026-17936",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-352",
      "title": "Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17936"
    },
    {
      "rank": 527,
      "cve_id": "CVE-2026-15252",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Search Atlas SEO",
      "cwe": "CWE-862",
      "title": "Search Atlas SEO < 2.6.12 - Subscriber+ Google Indexing API Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15252"
    },
    {
      "rank": 528,
      "cve_id": "CVE-2026-17755",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17755"
    },
    {
      "rank": 529,
      "cve_id": "CVE-2026-17939",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17939"
    },
    {
      "rank": 530,
      "cve_id": "CVE-2026-17720",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00176,
      "epss_percentile": 0.07442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17720"
    },
    {
      "rank": 531,
      "cve_id": "CVE-2026-15929",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07245,
      "kev": false,
      "kev_due_at": null,
      "vendor": "LG Electronics",
      "product": "SmartShare",
      "cwe": "CWE-89",
      "title": "Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection. This issue affects SmartShare: through 2.3.1712.1202, which is supported on Microsoft Windows 10 and earlier versions.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15929"
    },
    {
      "rank": 532,
      "cve_id": "CVE-2026-65421",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MZ Automation GmbH",
      "product": "libiec61850",
      "cwe": "CWE-125",
      "title": "MZ Automation libiec61850 Out-of-bounds Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65421"
    },
    {
      "rank": 533,
      "cve_id": "CVE-2026-66364",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MZ Automation GmbH",
      "product": "libiec61850",
      "cwe": "CWE-125",
      "title": "MZ Automation libiec61850 Out-of-bounds Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66364"
    },
    {
      "rank": 534,
      "cve_id": "CVE-2026-66369",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.0725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MZ Automation GmbH",
      "product": "libiec61850",
      "cwe": "CWE-125",
      "title": "MZ Automation libiec61850 Out-of-bounds Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66369"
    },
    {
      "rank": 535,
      "cve_id": "CVE-2026-66720",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MZ Automation GmbH",
      "product": "libiec61850",
      "cwe": "CWE-125",
      "title": "MZ Automation libiec61850 Out-of-bounds Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66720"
    },
    {
      "rank": 536,
      "cve_id": "CVE-2026-17853",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07312,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17853"
    },
    {
      "rank": 537,
      "cve_id": "CVE-2026-17878",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07312,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17878"
    },
    {
      "rank": 538,
      "cve_id": "CVE-2026-14310",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00175,
      "epss_percentile": 0.07331,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Tutor LMS",
      "cwe": "CWE-639",
      "title": "Tutor LMS < 4.0.0 - Subscriber+ Cross-Course Q&A Content Disclosure and Reply Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14310"
    },
    {
      "rank": 539,
      "cve_id": "CVE-2026-47882",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.07181,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Tools for Eclipse",
      "cwe": "CWE-338",
      "title": "Spring Boot DevTools remote secret generated with a non-cryptographic PRNG",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47882"
    },
    {
      "rank": 540,
      "cve_id": "CVE-2026-17822",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17822"
    },
    {
      "rank": 541,
      "cve_id": "CVE-2026-17841",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07217,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17841"
    },
    {
      "rank": 542,
      "cve_id": "CVE-2026-17843",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17843"
    },
    {
      "rank": 543,
      "cve_id": "CVE-2026-17857",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17857"
    },
    {
      "rank": 544,
      "cve_id": "CVE-2026-17871",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17871"
    },
    {
      "rank": 545,
      "cve_id": "CVE-2026-17876",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Payments in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17876"
    },
    {
      "rank": 546,
      "cve_id": "CVE-2026-17885",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07192,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Paint in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17885"
    },
    {
      "rank": 547,
      "cve_id": "CVE-2026-17895",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in DataTransfer in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17895"
    },
    {
      "rank": 548,
      "cve_id": "CVE-2026-17897",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00174,
      "epss_percentile": 0.07191,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in ORB in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17897"
    },
    {
      "rank": 549,
      "cve_id": "CVE-2026-17732",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00174,
      "epss_percentile": 0.0713,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17732"
    },
    {
      "rank": 550,
      "cve_id": "CVE-2026-17826",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00174,
      "epss_percentile": 0.07131,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17826"
    },
    {
      "rank": 551,
      "cve_id": "CVE-2026-13344",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07089,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Essential Addons for Elementor",
      "cwe": "CWE-79",
      "title": "Essential Addons for Elementor - Lite < 6.6.10 - Contributor+ Stored XSS via Pricing Table Title Tag",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13344"
    },
    {
      "rank": 552,
      "cve_id": "CVE-2026-17821",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06932,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17821"
    },
    {
      "rank": 553,
      "cve_id": "CVE-2026-17866",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-843",
      "title": "Type Confusion in Tab in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17866"
    },
    {
      "rank": 554,
      "cve_id": "CVE-2026-17980",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00172,
      "epss_percentile": 0.06944,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in UI in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17980"
    },
    {
      "rank": 555,
      "cve_id": "CVE-2026-17974",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-602",
      "title": "Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed a local attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17974"
    },
    {
      "rank": 556,
      "cve_id": "CVE-2026-17818",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17818"
    },
    {
      "rank": 557,
      "cve_id": "CVE-2026-17827",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17827"
    },
    {
      "rank": 558,
      "cve_id": "CVE-2026-17962",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06912,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17962"
    },
    {
      "rank": 559,
      "cve_id": "CVE-2026-11980",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0017,
      "epss_percentile": 0.06747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Aspera Desktop App",
      "cwe": "CWE-242",
      "title": "Code execution in IBM Desktop App",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11980"
    },
    {
      "rank": 560,
      "cve_id": "CVE-2026-17811",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00169,
      "epss_percentile": 0.0664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17811"
    },
    {
      "rank": 561,
      "cve_id": "CVE-2026-18014",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06623,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18014"
    },
    {
      "rank": 562,
      "cve_id": "CVE-2026-17890",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.0658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17890"
    },
    {
      "rank": 563,
      "cve_id": "CVE-2026-17893",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00168,
      "epss_percentile": 0.06581,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17893"
    },
    {
      "rank": 564,
      "cve_id": "CVE-2026-17916",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00166,
      "epss_percentile": 0.06297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17916"
    },
    {
      "rank": 565,
      "cve_id": "CVE-2026-11383",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06281,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Tivoli System Automation Application Manager",
      "cwe": "CWE-79",
      "title": "Cross-site Scripting in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11383"
    },
    {
      "rank": 566,
      "cve_id": "CVE-2026-66420",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Ylianst",
      "product": "MeshCentral",
      "cwe": "CWE-346",
      "title": "MeshCentral Cross-Site WebSocket Hijacking via Origin Validation Bypass on Self-Signed Certificate Deployments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66420"
    },
    {
      "rank": 567,
      "cve_id": "CVE-2025-36298",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06252,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Sterling B2B Integrator",
      "cwe": "CWE-79",
      "title": "Security Vulnerability in Ebics server affects IBM Sterling B2B Integrator and IBM Sterling File Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36298"
    },
    {
      "rank": 568,
      "cve_id": "CVE-2025-36431",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Sterling B2B Integrator",
      "cwe": "CWE-79",
      "title": "XSS Security Vulnerability in response header affects IBM Sterling B2B Integrator and IBM Sterling File Gateway",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-36431"
    },
    {
      "rank": 569,
      "cve_id": "CVE-2026-17783",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Loader in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17783"
    },
    {
      "rank": 570,
      "cve_id": "CVE-2026-17817",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in ReportingAndNEL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17817"
    },
    {
      "rank": 571,
      "cve_id": "CVE-2026-17833",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17833"
    },
    {
      "rank": 572,
      "cve_id": "CVE-2026-17904",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in NFC in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17904"
    },
    {
      "rank": 573,
      "cve_id": "CVE-2026-17905",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06088,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in SurfaceCapture in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17905"
    },
    {
      "rank": 574,
      "cve_id": "CVE-2026-17910",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06086,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in NFC in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17910"
    },
    {
      "rank": 575,
      "cve_id": "CVE-2026-17911",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17911"
    },
    {
      "rank": 576,
      "cve_id": "CVE-2026-17933",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in DOMStorage in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17933"
    },
    {
      "rank": 577,
      "cve_id": "CVE-2026-17959",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17959"
    },
    {
      "rank": 578,
      "cve_id": "CVE-2026-17963",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in SVG in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17963"
    },
    {
      "rank": 579,
      "cve_id": "CVE-2026-17724",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17724"
    },
    {
      "rank": 580,
      "cve_id": "CVE-2026-5846",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00163,
      "epss_percentile": 0.05979,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Watchfire",
      "product": "BC550",
      "cwe": "CWE-321",
      "title": "Hard-coded Cryptographic Key in Watchfire Controllers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5846"
    },
    {
      "rank": 581,
      "cve_id": "CVE-2026-18019",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.06013,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-1300",
      "title": "Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18019"
    },
    {
      "rank": 582,
      "cve_id": "CVE-2026-66416",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00162,
      "epss_percentile": 0.05957,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Leantime",
      "product": "Leantime",
      "cwe": "CWE-352",
      "title": "Leantime CSRF Protection Globally Disabled by Omission of Laravel VerifyCsrfToken Middleware",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66416"
    },
    {
      "rank": 583,
      "cve_id": "CVE-2025-0152",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05911,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Engineering Requirements Management DOORS and DOORS Web Access",
      "cwe": "CWE-79",
      "title": "IBM Engineering Requirements Management DOORS and DOORS Web Access is affected by multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-0152"
    },
    {
      "rank": 584,
      "cve_id": "CVE-2026-17977",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Policy bypass in CSS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17977"
    },
    {
      "rank": 585,
      "cve_id": "CVE-2026-59328",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05953,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Tools for Eclipse",
      "cwe": "CWE-79",
      "title": "Cross-Site Scripting in Eclipse Spring Boot Starter Wizard Dependency Tooltips",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59328"
    },
    {
      "rank": 586,
      "cve_id": "CVE-2026-17806",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17806"
    },
    {
      "rank": 587,
      "cve_id": "CVE-2026-17809",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17809"
    },
    {
      "rank": 588,
      "cve_id": "CVE-2026-17891",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17891"
    },
    {
      "rank": 589,
      "cve_id": "CVE-2026-17906",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17906"
    },
    {
      "rank": 590,
      "cve_id": "CVE-2026-17908",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05521,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17908"
    },
    {
      "rank": 591,
      "cve_id": "CVE-2026-56847",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00158,
      "epss_percentile": 0.05518,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodejs",
      "product": "node",
      "cwe": "CWE-1119",
      "title": "A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56847"
    },
    {
      "rank": 592,
      "cve_id": "CVE-2026-17981",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05427,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Blink in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17981"
    },
    {
      "rank": 593,
      "cve_id": "CVE-2026-18004",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00157,
      "epss_percentile": 0.05404,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18004"
    },
    {
      "rank": 594,
      "cve_id": "CVE-2026-17888",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00156,
      "epss_percentile": 0.05343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in WebUI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17888"
    },
    {
      "rank": 595,
      "cve_id": "CVE-2026-67530",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05254,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ArnasDon",
      "product": "wacrm",
      "cwe": "CWE-918",
      "title": "WACRM: SSRF via the automation `send_webhook` action",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67530"
    },
    {
      "rank": 596,
      "cve_id": "CVE-2026-17954",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00156,
      "epss_percentile": 0.05275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Policy bypass in MHTML in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted MHTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17954"
    },
    {
      "rank": 597,
      "cve_id": "CVE-2026-17925",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00155,
      "epss_percentile": 0.05184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Cast in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17925"
    },
    {
      "rank": 598,
      "cve_id": "CVE-2024-40683",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Operations Analytics - Log Analysis",
      "cwe": "CWE-613",
      "title": "IBM Operations Analytics - Log Analysis is affected by a TOCTOU weakness allowing active sessions to persist beyond a password change",
      "url": "https://www.cve.org/CVERecord?id=CVE-2024-40683"
    },
    {
      "rank": 599,
      "cve_id": "CVE-2026-18006",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05117,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18006"
    },
    {
      "rank": 600,
      "cve_id": "CVE-2026-18007",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Input in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18007"
    },
    {
      "rank": 601,
      "cve_id": "CVE-2026-18013",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00154,
      "epss_percentile": 0.05118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18013"
    },
    {
      "rank": 602,
      "cve_id": "CVE-2026-18000",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00152,
      "epss_percentile": 0.04927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in USB in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18000"
    },
    {
      "rank": 603,
      "cve_id": "CVE-2026-17716",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via malicious network traffic. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17716"
    },
    {
      "rank": 604,
      "cve_id": "CVE-2026-17774",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00151,
      "epss_percentile": 0.04764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Variations in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17774"
    },
    {
      "rank": 605,
      "cve_id": "CVE-2026-17900",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.04826,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Enterprise in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a malicious file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17900"
    },
    {
      "rank": 606,
      "cve_id": "CVE-2026-17699",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00149,
      "epss_percentile": 0.04619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17699"
    },
    {
      "rank": 607,
      "cve_id": "CVE-2025-65341",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.0461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-65341"
    },
    {
      "rank": 608,
      "cve_id": "CVE-2025-65342",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.0461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-65342"
    },
    {
      "rank": 609,
      "cve_id": "CVE-2026-7260",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04522,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHP Group",
      "product": "PHP",
      "cwe": "CWE-121",
      "title": "Stack overflow in phar with circular symlinks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-7260"
    },
    {
      "rank": 610,
      "cve_id": "CVE-2026-17999",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00146,
      "epss_percentile": 0.04382,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in PictureInPicture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17999"
    },
    {
      "rank": 611,
      "cve_id": "CVE-2026-17957",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00146,
      "epss_percentile": 0.04358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in CORS in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17957"
    },
    {
      "rank": 612,
      "cve_id": "CVE-2026-17970",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00145,
      "epss_percentile": 0.04304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed an attacker in a privileged network position to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17970"
    },
    {
      "rank": 613,
      "cve_id": "CVE-2026-18008",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.04046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Settings in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18008"
    },
    {
      "rank": 614,
      "cve_id": "CVE-2026-18009",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.04046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18009"
    },
    {
      "rank": 615,
      "cve_id": "CVE-2026-18010",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00142,
      "epss_percentile": 0.04046,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18010"
    },
    {
      "rank": 616,
      "cve_id": "CVE-2026-17739",
      "cvss_base": 4.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00141,
      "epss_percentile": 0.03914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted Chrome Extension. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17739"
    },
    {
      "rank": 617,
      "cve_id": "CVE-2026-58043",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0014,
      "epss_percentile": 0.03802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodejs",
      "product": "node",
      "cwe": "CWE-284",
      "title": "A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58043"
    },
    {
      "rank": 618,
      "cve_id": "CVE-2026-17976",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Insufficient policy enforcement in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted domain name. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17976"
    },
    {
      "rank": 619,
      "cve_id": "CVE-2026-54522",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00136,
      "epss_percentile": 0.03507,
      "kev": false,
      "kev_due_at": null,
      "vendor": "msgpack",
      "product": "msgpack-ruby",
      "cwe": "CWE-416",
      "title": "MessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54522"
    },
    {
      "rank": 620,
      "cve_id": "CVE-2026-5219",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03362,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Softtr Information Technology Trade Ltd. Co.",
      "product": "E-Commerce Pack",
      "cwe": "CWE-352",
      "title": "CSRF in Softtr's E-Commerce Pack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5219"
    },
    {
      "rank": 621,
      "cve_id": "CVE-2026-62363",
      "cvss_base": 5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03243,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-787",
      "title": "ImageMagick: Heap Buffer Over-Write in fx operation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62363"
    },
    {
      "rank": 622,
      "cve_id": "CVE-2026-5582",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fusewp",
      "product": "FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)",
      "cwe": "CWE-352",
      "title": "FuseWP <= 1.1.24.2 - Cross-Site Request Forgery to Sync Rule Status Toggle",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-5582"
    },
    {
      "rank": 623,
      "cve_id": "CVE-2026-18016",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00132,
      "epss_percentile": 0.03216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18016"
    },
    {
      "rank": 624,
      "cve_id": "CVE-2026-68499",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00129,
      "epss_percentile": 0.02991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uhop",
      "product": "node-re2",
      "cwe": "CWE-835",
      "title": "re2: Global `String.prototype.match` with an empty-matchable pattern never advances → infinite loop with unbounded native memory growth (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68499"
    },
    {
      "rank": 625,
      "cve_id": "CVE-2026-17997",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00128,
      "epss_percentile": 0.02871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Passwords in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17997"
    },
    {
      "rank": 626,
      "cve_id": "CVE-2026-13584",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00127,
      "epss_percentile": 0.02791,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Mitsubishi Electric Corporation",
      "product": "MELSEC MX Controller MX-R model MXR300-16",
      "cwe": "CWE-924",
      "title": "Information tampering and Denial-of-service (DoS) vulnerability in CC-Link IE TSN communication protocol",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13584"
    },
    {
      "rank": 627,
      "cve_id": "CVE-2026-17927",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00125,
      "epss_percentile": 0.02625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17927"
    },
    {
      "rank": 628,
      "cve_id": "CVE-2026-62946",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02494,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ImageMagick",
      "product": "ImageMagick",
      "cwe": "CWE-190",
      "title": "ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit builds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62946"
    },
    {
      "rank": 629,
      "cve_id": "CVE-2026-67550",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "uhop",
      "product": "node-re2",
      "cwe": "CWE-125",
      "title": "re2: Out-of-bounds heap read in `exec`/`test`/`match` via attacker-influenced `lastIndex` on a non-ASCII subject → uncatchable process crash (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67550"
    },
    {
      "rank": 630,
      "cve_id": "CVE-2026-17654",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.0012,
      "epss_percentile": 0.02149,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Critical)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17654"
    },
    {
      "rank": 631,
      "cve_id": "CVE-2026-17919",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0012,
      "epss_percentile": 0.02153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-693",
      "title": "Insufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via physical access to the device. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17919"
    },
    {
      "rank": 632,
      "cve_id": "CVE-2026-17766",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.0012,
      "epss_percentile": 0.0215,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Clipboard in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17766"
    },
    {
      "rank": 633,
      "cve_id": "CVE-2026-17998",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00118,
      "epss_percentile": 0.01992,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Incorrect security UI in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17998"
    },
    {
      "rank": 634,
      "cve_id": "CVE-2026-17903",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01974,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-79",
      "title": "Insufficient policy enforcement in Chromecast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local network segment to inject scripts or HTML into a privileged page via malicious network traffic. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17903"
    },
    {
      "rank": 635,
      "cve_id": "CVE-2026-17844",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local network segment to leak cross-origin data via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17844"
    },
    {
      "rank": 636,
      "cve_id": "CVE-2026-17870",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Cast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local network segment to leak cross-origin data via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17870"
    },
    {
      "rank": 637,
      "cve_id": "CVE-2026-10535",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00113,
      "epss_percentile": 0.01621,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-121",
      "title": "IBM® Db2® is vulnerable to buffer overflow in setgid helper db2flacc which can lead to privilege escalation and instance compromise from an unprivileged shell",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10535"
    },
    {
      "rank": 638,
      "cve_id": "CVE-2026-17862",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01556,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in Tracing in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17862"
    },
    {
      "rank": 639,
      "cve_id": "CVE-2026-14239",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00109,
      "epss_percentile": 0.01409,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "tourmaster",
      "cwe": "CWE-79",
      "title": "Tourmaster < 5.4.8 - Stored XSS via CSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14239"
    },
    {
      "rank": 640,
      "cve_id": "CVE-2026-67596",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00108,
      "epss_percentile": 0.0138,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CSL Mobile Limited",
      "product": "CSL 1010 M2M 3G WiFi Module",
      "cwe": "CWE-261",
      "title": "CSL 1010 M2M 3G WiFi Module 2.2.1.4 Weak Encryption via Router.cfg",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67596"
    },
    {
      "rank": 641,
      "cve_id": "CVE-2026-17863",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00107,
      "epss_percentile": 0.01327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in Browser in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17863"
    },
    {
      "rank": 642,
      "cve_id": "CVE-2026-10695",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.01266,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "Db2",
      "cwe": "CWE-400",
      "title": "IBM® Db2® is vulnerable to a denial of service when running non fenced federated queries",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10695"
    },
    {
      "rank": 643,
      "cve_id": "CVE-2026-17932",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00106,
      "epss_percentile": 0.0128,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-416",
      "title": "Use after free in DataTransfer in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17932"
    },
    {
      "rank": 644,
      "cve_id": "CVE-2026-17861",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00105,
      "epss_percentile": 0.0124,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Updater in Google Chrome prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17861"
    },
    {
      "rank": 645,
      "cve_id": "CVE-2026-17877",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00103,
      "epss_percentile": 0.01125,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17877"
    },
    {
      "rank": 646,
      "cve_id": "CVE-2026-17966",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01136,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17966"
    },
    {
      "rank": 647,
      "cve_id": "CVE-2026-17864",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00102,
      "epss_percentile": 0.01053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-269",
      "title": "Inappropriate implementation in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17864"
    },
    {
      "rank": 648,
      "cve_id": "CVE-2026-11885",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00101,
      "epss_percentile": 0.01021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "IBM",
      "product": "PowerVM Hypervisor",
      "cwe": "CWE-120",
      "title": "Power System update in Buffer Copy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11885"
    },
    {
      "rank": 649,
      "cve_id": "CVE-2026-17973",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.01018,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in Views in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17973"
    },
    {
      "rank": 650,
      "cve_id": "CVE-2026-68563",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00101,
      "epss_percentile": 0.01014,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-732",
      "title": "Ansible-collection-redhat-leapp: ansible-collection-redhat-leapp: information disclosure of postgresql data via insecure backup permissions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68563"
    },
    {
      "rank": 651,
      "cve_id": "CVE-2026-59326",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00095,
      "epss_percentile": 0.00779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Tools for Eclipse",
      "cwe": "CWE-532",
      "title": "HTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59326"
    },
    {
      "rank": 652,
      "cve_id": "CVE-2026-44105",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00094,
      "epss_percentile": 0.00699,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Phoenix Contact",
      "product": "CHARX SEC-3150",
      "cwe": "CWE-532",
      "title": "Cleartext password in logs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44105"
    },
    {
      "rank": 653,
      "cve_id": "CVE-2026-17860",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00094,
      "epss_percentile": 0.00718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-20",
      "title": "Insufficient validation of untrusted input in Mobile in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to spoof the contents of the Omnibox (URL bar) via a malicious file. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17860"
    },
    {
      "rank": 654,
      "cve_id": "CVE-2026-17984",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00092,
      "epss_percentile": 0.0059,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-346",
      "title": "Inappropriate implementation in Browser in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17984"
    },
    {
      "rank": 655,
      "cve_id": "CVE-2026-18011",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00091,
      "epss_percentile": 0.00566,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-200",
      "title": "Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a local attacker to obtain potentially sensitive information from process memory via physical access to the device. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18011"
    },
    {
      "rank": 656,
      "cve_id": "CVE-2026-16727",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00087,
      "epss_percentile": 0.0041,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ASUS",
      "product": "Armoury Crate",
      "cwe": "CWE-362",
      "title": "Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbitrary code with elevated privileges via a crafted file replacement. Refer to the ' Security Update for ASUS Armoury Crate ' section on the ASUS Security Advisory for more information.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16727"
    },
    {
      "rank": 657,
      "cve_id": "CVE-2026-17996",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00085,
      "epss_percentile": 0.00369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-284",
      "title": "Inappropriate implementation in Browser in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17996"
    },
    {
      "rank": 658,
      "cve_id": "CVE-2026-59327",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00085,
      "epss_percentile": 0.00369,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Spring",
      "product": "Spring Tools for Eclipse",
      "cwe": "CWE-312",
      "title": "Cleartext Storage of Spring Boot DevTools Remote Secret in Eclipse Launch Configurations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59327"
    },
    {
      "rank": 659,
      "cve_id": "CVE-2026-18018",
      "cvss_base": 4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00083,
      "epss_percentile": 0.00278,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-451",
      "title": "Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18018"
    },
    {
      "rank": 660,
      "cve_id": "CVE-2026-56850",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00082,
      "epss_percentile": 0.00269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodejs",
      "product": "node",
      "cwe": "CWE-287",
      "title": "A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56850"
    },
    {
      "rank": 661,
      "cve_id": "CVE-2026-17993",
      "cvss_base": 7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0008,
      "epss_percentile": 0.00202,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-362",
      "title": "Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: Low)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17993"
    },
    {
      "rank": 662,
      "cve_id": "CVE-2026-17872",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00066,
      "epss_percentile": 0.00026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "Chrome",
      "cwe": "CWE-347",
      "title": "Cryptographic Flaw in WebAppInstalls in Google Chrome on Android prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17872"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-37899",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-37899 (Linux). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-38002",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-38002 (Linux). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-38089",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-38089 (Linux). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-12436",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-12436 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14234",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14234 (Unknown WOLF). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14300",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14300 (Unknown miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn)). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41939",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41939 (Care Everywhere LLC Care Everywhere Gateway). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-45309",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-45309 (ronf asyncssh). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47143",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47143 (capstone-engine capstone). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-47671",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-47671 (nhost cli). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-54522",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-54522 (msgpack-ruby). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56819",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56819 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56820",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56820 (netty). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-6267",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-6267 (GitLab). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66729",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66729 (boazsegev facil.io). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66730",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66730 (boazsegev facil.io). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66731",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66731 (boazsegev facil.io). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2023-4346",
      "detail": "DUE DATE PASSED — CVE-2023-4346 (KNX Association KNX Protocol Connection Authorization Option 1). CISA remediation deadline was July 29, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-4244",
      "detail": "RESCORED — CVE-2023-4244 (Linux Kernel). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21629",
      "detail": "RESCORED — CVE-2025-21629 (Linux). CVSS 8.2 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21637",
      "detail": "RESCORED — CVE-2025-21637 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21638",
      "detail": "RESCORED — CVE-2025-21638 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21640",
      "detail": "RESCORED — CVE-2025-21640 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21646",
      "detail": "RESCORED — CVE-2025-21646 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21647",
      "detail": "RESCORED — CVE-2025-21647 (Linux). CVSS 7.3 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21650",
      "detail": "RESCORED — CVE-2025-21650 (Linux). CVSS 7.1 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21655",
      "detail": "RESCORED — CVE-2025-21655 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21659",
      "detail": "RESCORED — CVE-2025-21659 (Linux). CVSS 8.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21661",
      "detail": "RESCORED — CVE-2025-21661 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21663",
      "detail": "RESCORED — CVE-2025-21663 (Linux). CVSS 10 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21664",
      "detail": "RESCORED — CVE-2025-21664 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21669",
      "detail": "RESCORED — CVE-2025-21669 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21673",
      "detail": "RESCORED — CVE-2025-21673 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21676",
      "detail": "RESCORED — CVE-2025-21676 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21677",
      "detail": "RESCORED — CVE-2025-21677 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21678",
      "detail": "RESCORED — CVE-2025-21678 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21682",
      "detail": "RESCORED — CVE-2025-21682 (Linux). CVSS 7.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21697",
      "detail": "RESCORED — CVE-2025-21697 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21699",
      "detail": "RESCORED — CVE-2025-21699 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21701",
      "detail": "RESCORED — CVE-2025-21701 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21707",
      "detail": "RESCORED — CVE-2025-21707 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21709",
      "detail": "RESCORED — CVE-2025-21709 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21710",
      "detail": "RESCORED — CVE-2025-21710 (Linux). CVSS 8.2 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21712",
      "detail": "RESCORED — CVE-2025-21712 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21717",
      "detail": "RESCORED — CVE-2025-21717 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21718",
      "detail": "RESCORED — CVE-2025-21718 (Linux). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21720",
      "detail": "RESCORED — CVE-2025-21720 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21725",
      "detail": "RESCORED — CVE-2025-21725 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21730",
      "detail": "RESCORED — CVE-2025-21730 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21735",
      "detail": "RESCORED — CVE-2025-21735 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21738",
      "detail": "RESCORED — CVE-2025-21738 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21748",
      "detail": "RESCORED — CVE-2025-21748 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21758",
      "detail": "RESCORED — CVE-2025-21758 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21765",
      "detail": "RESCORED — CVE-2025-21765 (Linux). CVSS 8.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21766",
      "detail": "RESCORED — CVE-2025-21766 (Linux). CVSS 8.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21778",
      "detail": "RESCORED — CVE-2025-21778 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21788",
      "detail": "RESCORED — CVE-2025-21788 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21789",
      "detail": "RESCORED — CVE-2025-21789 (Linux). CVSS 7.3 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21792",
      "detail": "RESCORED — CVE-2025-21792 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21795",
      "detail": "RESCORED — CVE-2025-21795 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21801",
      "detail": "RESCORED — CVE-2025-21801 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21804",
      "detail": "RESCORED — CVE-2025-21804 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21805",
      "detail": "RESCORED — CVE-2025-21805 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21808",
      "detail": "RESCORED — CVE-2025-21808 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21809",
      "detail": "RESCORED — CVE-2025-21809 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21810",
      "detail": "RESCORED — CVE-2025-21810 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21823",
      "detail": "RESCORED — CVE-2025-21823 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21825",
      "detail": "RESCORED — CVE-2025-21825 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21826",
      "detail": "RESCORED — CVE-2025-21826 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21827",
      "detail": "RESCORED — CVE-2025-21827 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21828",
      "detail": "RESCORED — CVE-2025-21828 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21829",
      "detail": "RESCORED — CVE-2025-21829 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21830",
      "detail": "RESCORED — CVE-2025-21830 (Linux). CVSS 7.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21832",
      "detail": "RESCORED — CVE-2025-21832 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21836",
      "detail": "RESCORED — CVE-2025-21836 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21839",
      "detail": "RESCORED — CVE-2025-21839 (Linux). CVSS 7.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21842",
      "detail": "RESCORED — CVE-2025-21842 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21844",
      "detail": "RESCORED — CVE-2025-21844 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21850",
      "detail": "RESCORED — CVE-2025-21850 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21851",
      "detail": "RESCORED — CVE-2025-21851 (Linux). CVSS 7.8 → 3.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21855",
      "detail": "RESCORED — CVE-2025-21855 (Linux). CVSS 8.6 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21864",
      "detail": "RESCORED — CVE-2025-21864 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21868",
      "detail": "RESCORED — CVE-2025-21868 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21870",
      "detail": "RESCORED — CVE-2025-21870 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21875",
      "detail": "RESCORED — CVE-2025-21875 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21876",
      "detail": "RESCORED — CVE-2025-21876 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21882",
      "detail": "RESCORED — CVE-2025-21882 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21884",
      "detail": "RESCORED — CVE-2025-21884 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21885",
      "detail": "RESCORED — CVE-2025-21885 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21889",
      "detail": "RESCORED — CVE-2025-21889 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21890",
      "detail": "RESCORED — CVE-2025-21890 (Linux). CVSS 8.2 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21899",
      "detail": "RESCORED — CVE-2025-21899 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21900",
      "detail": "RESCORED — CVE-2025-21900 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21901",
      "detail": "RESCORED — CVE-2025-21901 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21906",
      "detail": "RESCORED — CVE-2025-21906 (Linux). CVSS 7.6 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21915",
      "detail": "RESCORED — CVE-2025-21915 (Linux). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21924",
      "detail": "RESCORED — CVE-2025-21924 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21926",
      "detail": "RESCORED — CVE-2025-21926 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21927",
      "detail": "RESCORED — CVE-2025-21927 (Linux). CVSS 9.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21932",
      "detail": "RESCORED — CVE-2025-21932 (Linux). CVSS 7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21938",
      "detail": "RESCORED — CVE-2025-21938 (Linux). CVSS 7.5 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21939",
      "detail": "RESCORED — CVE-2025-21939 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21945",
      "detail": "RESCORED — CVE-2025-21945 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21946",
      "detail": "RESCORED — CVE-2025-21946 (Linux). CVSS 8.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21949",
      "detail": "RESCORED — CVE-2025-21949 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21954",
      "detail": "RESCORED — CVE-2025-21954 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21955",
      "detail": "RESCORED — CVE-2025-21955 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21958",
      "detail": "RESCORED — CVE-2025-21958 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21959",
      "detail": "RESCORED — CVE-2025-21959 (Linux). CVSS 7.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21960",
      "detail": "RESCORED — CVE-2025-21960 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21961",
      "detail": "RESCORED — CVE-2025-21961 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21965",
      "detail": "RESCORED — CVE-2025-21965 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21967",
      "detail": "RESCORED — CVE-2025-21967 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21969",
      "detail": "RESCORED — CVE-2025-21969 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21970",
      "detail": "RESCORED — CVE-2025-21970 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21971",
      "detail": "RESCORED — CVE-2025-21971 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21972",
      "detail": "RESCORED — CVE-2025-21972 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21976",
      "detail": "RESCORED — CVE-2025-21976 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21984",
      "detail": "RESCORED — CVE-2025-21984 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21985",
      "detail": "RESCORED — CVE-2025-21985 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21988",
      "detail": "RESCORED — CVE-2025-21988 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-21994",
      "detail": "RESCORED — CVE-2025-21994 (Linux). CVSS 7.6 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22001",
      "detail": "RESCORED — CVE-2025-22001 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22012",
      "detail": "RESCORED — CVE-2025-22012 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22013",
      "detail": "RESCORED — CVE-2025-22013 (Linux). CVSS 7.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22015",
      "detail": "RESCORED — CVE-2025-22015 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22019",
      "detail": "RESCORED — CVE-2025-22019 (Linux). CVSS 7.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22021",
      "detail": "RESCORED — CVE-2025-22021 (Linux). CVSS 10 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22025",
      "detail": "RESCORED — CVE-2025-22025 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22034",
      "detail": "RESCORED — CVE-2025-22034 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22036",
      "detail": "RESCORED — CVE-2025-22036 (Linux). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22037",
      "detail": "RESCORED — CVE-2025-22037 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22038",
      "detail": "RESCORED — CVE-2025-22038 (Linux). CVSS 8.3 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22039",
      "detail": "RESCORED — CVE-2025-22039 (Linux). CVSS 8.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22042",
      "detail": "RESCORED — CVE-2025-22042 (Linux). CVSS 8.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22043",
      "detail": "RESCORED — CVE-2025-22043 (Linux). CVSS 8.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22044",
      "detail": "RESCORED — CVE-2025-22044 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22045",
      "detail": "RESCORED — CVE-2025-22045 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22047",
      "detail": "RESCORED — CVE-2025-22047 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22048",
      "detail": "RESCORED — CVE-2025-22048 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22049",
      "detail": "RESCORED — CVE-2025-22049 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22055",
      "detail": "RESCORED — CVE-2025-22055 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22057",
      "detail": "RESCORED — CVE-2025-22057 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22059",
      "detail": "RESCORED — CVE-2025-22059 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22061",
      "detail": "RESCORED — CVE-2025-22061 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22062",
      "detail": "RESCORED — CVE-2025-22062 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22072",
      "detail": "RESCORED — CVE-2025-22072 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22074",
      "detail": "RESCORED — CVE-2025-22074 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22077",
      "detail": "RESCORED — CVE-2025-22077 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22079",
      "detail": "RESCORED — CVE-2025-22079 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22080",
      "detail": "RESCORED — CVE-2025-22080 (Linux). CVSS 8.4 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22081",
      "detail": "RESCORED — CVE-2025-22081 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22086",
      "detail": "RESCORED — CVE-2025-22086 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22087",
      "detail": "RESCORED — CVE-2025-22087 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22089",
      "detail": "RESCORED — CVE-2025-22089 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22090",
      "detail": "RESCORED — CVE-2025-22090 (Linux). CVSS 7.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22094",
      "detail": "RESCORED — CVE-2025-22094 (Linux). CVSS 7.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22100",
      "detail": "RESCORED — CVE-2025-22100 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22102",
      "detail": "RESCORED — CVE-2025-22102 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22108",
      "detail": "RESCORED — CVE-2025-22108 (Linux). CVSS 8.6 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22109",
      "detail": "RESCORED — CVE-2025-22109 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22110",
      "detail": "RESCORED — CVE-2025-22110 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22114",
      "detail": "RESCORED — CVE-2025-22114 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22115",
      "detail": "RESCORED — CVE-2025-22115 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22117",
      "detail": "RESCORED — CVE-2025-22117 (Linux). CVSS 8.7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22118",
      "detail": "RESCORED — CVE-2025-22118 (Linux). CVSS 8.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22121",
      "detail": "RESCORED — CVE-2025-22121 (Linux). CVSS 8.4 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-22124",
      "detail": "RESCORED — CVE-2025-22124 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-23132",
      "detail": "RESCORED — CVE-2025-23132 (Linux). CVSS 7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-23133",
      "detail": "RESCORED — CVE-2025-23133 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-23141",
      "detail": "RESCORED — CVE-2025-23141 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-23145",
      "detail": "RESCORED — CVE-2025-23145 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-23150",
      "detail": "RESCORED — CVE-2025-23150 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-23151",
      "detail": "RESCORED — CVE-2025-23151 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-23155",
      "detail": "RESCORED — CVE-2025-23155 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-23156",
      "detail": "RESCORED — CVE-2025-23156 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-23157",
      "detail": "RESCORED — CVE-2025-23157 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-23159",
      "detail": "RESCORED — CVE-2025-23159 (Linux). CVSS 8.4 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37741",
      "detail": "RESCORED — CVE-2025-37741 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37749",
      "detail": "RESCORED — CVE-2025-37749 (Linux). CVSS 8.2 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37750",
      "detail": "RESCORED — CVE-2025-37750 (Linux). CVSS 9.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37751",
      "detail": "RESCORED — CVE-2025-37751 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37756",
      "detail": "RESCORED — CVE-2025-37756 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37757",
      "detail": "RESCORED — CVE-2025-37757 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37765",
      "detail": "RESCORED — CVE-2025-37765 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37776",
      "detail": "RESCORED — CVE-2025-37776 (Linux). CVSS 8.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37777",
      "detail": "RESCORED — CVE-2025-37777 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37779",
      "detail": "RESCORED — CVE-2025-37779 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37791",
      "detail": "RESCORED — CVE-2025-37791 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37799",
      "detail": "RESCORED — CVE-2025-37799 (Linux). CVSS 8.6 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37800",
      "detail": "RESCORED — CVE-2025-37800 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37801",
      "detail": "RESCORED — CVE-2025-37801 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37802",
      "detail": "RESCORED — CVE-2025-37802 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37813",
      "detail": "RESCORED — CVE-2025-37813 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37814",
      "detail": "RESCORED — CVE-2025-37814 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37820",
      "detail": "RESCORED — CVE-2025-37820 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37849",
      "detail": "RESCORED — CVE-2025-37849 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37856",
      "detail": "RESCORED — CVE-2025-37856 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37871",
      "detail": "RESCORED — CVE-2025-37871 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37873",
      "detail": "RESCORED — CVE-2025-37873 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37876",
      "detail": "RESCORED — CVE-2025-37876 (Linux). CVSS 7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37879",
      "detail": "RESCORED — CVE-2025-37879 (Linux). CVSS 9.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37885",
      "detail": "RESCORED — CVE-2025-37885 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37886",
      "detail": "RESCORED — CVE-2025-37886 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37887",
      "detail": "RESCORED — CVE-2025-37887 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37893",
      "detail": "RESCORED — CVE-2025-37893 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37894",
      "detail": "RESCORED — CVE-2025-37894 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37899",
      "detail": "RESCORED — CVE-2025-37899 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37901",
      "detail": "RESCORED — CVE-2025-37901 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37906",
      "detail": "RESCORED — CVE-2025-37906 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37911",
      "detail": "RESCORED — CVE-2025-37911 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37915",
      "detail": "RESCORED — CVE-2025-37915 (Linux). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37917",
      "detail": "RESCORED — CVE-2025-37917 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37918",
      "detail": "RESCORED — CVE-2025-37918 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37920",
      "detail": "RESCORED — CVE-2025-37920 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37926",
      "detail": "RESCORED — CVE-2025-37926 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37931",
      "detail": "RESCORED — CVE-2025-37931 (Linux). CVSS 7.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37935",
      "detail": "RESCORED — CVE-2025-37935 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37936",
      "detail": "RESCORED — CVE-2025-37936 (Linux). CVSS 8.7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37938",
      "detail": "RESCORED — CVE-2025-37938 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37943",
      "detail": "RESCORED — CVE-2025-37943 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37944",
      "detail": "RESCORED — CVE-2025-37944 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37947",
      "detail": "RESCORED — CVE-2025-37947 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37949",
      "detail": "RESCORED — CVE-2025-37949 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37952",
      "detail": "RESCORED — CVE-2025-37952 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37954",
      "detail": "RESCORED — CVE-2025-37954 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37956",
      "detail": "RESCORED — CVE-2025-37956 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37957",
      "detail": "RESCORED — CVE-2025-37957 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37959",
      "detail": "RESCORED — CVE-2025-37959 (Linux). CVSS 9.4 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37964",
      "detail": "RESCORED — CVE-2025-37964 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37973",
      "detail": "RESCORED — CVE-2025-37973 (Linux). CVSS 8.1 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37977",
      "detail": "RESCORED — CVE-2025-37977 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37984",
      "detail": "RESCORED — CVE-2025-37984 (Linux). CVSS 7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37988",
      "detail": "RESCORED — CVE-2025-37988 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37996",
      "detail": "RESCORED — CVE-2025-37996 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37997",
      "detail": "RESCORED — CVE-2025-37997 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-37998",
      "detail": "RESCORED — CVE-2025-37998 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38001",
      "detail": "RESCORED — CVE-2025-38001 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38002",
      "detail": "RESCORED — CVE-2025-38002 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38003",
      "detail": "RESCORED — CVE-2025-38003 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38004",
      "detail": "RESCORED — CVE-2025-38004 (Linux). CVSS 7.3 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38005",
      "detail": "RESCORED — CVE-2025-38005 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38012",
      "detail": "RESCORED — CVE-2025-38012 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38016",
      "detail": "RESCORED — CVE-2025-38016 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38018",
      "detail": "RESCORED — CVE-2025-38018 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38028",
      "detail": "RESCORED — CVE-2025-38028 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38035",
      "detail": "RESCORED — CVE-2025-38035 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38051",
      "detail": "RESCORED — CVE-2025-38051 (Linux). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38052",
      "detail": "RESCORED — CVE-2025-38052 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38057",
      "detail": "RESCORED — CVE-2025-38057 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38058",
      "detail": "RESCORED — CVE-2025-38058 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38060",
      "detail": "RESCORED — CVE-2025-38060 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38062",
      "detail": "RESCORED — CVE-2025-38062 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38064",
      "detail": "RESCORED — CVE-2025-38064 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38065",
      "detail": "RESCORED — CVE-2025-38065 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38074",
      "detail": "RESCORED — CVE-2025-38074 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38075",
      "detail": "RESCORED — CVE-2025-38075 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38078",
      "detail": "RESCORED — CVE-2025-38078 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38080",
      "detail": "RESCORED — CVE-2025-38080 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38083",
      "detail": "RESCORED — CVE-2025-38083 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38084",
      "detail": "RESCORED — CVE-2025-38084 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38085",
      "detail": "RESCORED — CVE-2025-38085 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38089",
      "detail": "RESCORED — CVE-2025-38089 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38090",
      "detail": "RESCORED — CVE-2025-38090 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38092",
      "detail": "RESCORED — CVE-2025-38092 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38095",
      "detail": "RESCORED — CVE-2025-38095 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38097",
      "detail": "RESCORED — CVE-2025-38097 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38098",
      "detail": "RESCORED — CVE-2025-38098 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38102",
      "detail": "RESCORED — CVE-2025-38102 (Linux). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38107",
      "detail": "RESCORED — CVE-2025-38107 (Linux). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38108",
      "detail": "RESCORED — CVE-2025-38108 (Linux). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38110",
      "detail": "RESCORED — CVE-2025-38110 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38111",
      "detail": "RESCORED — CVE-2025-38111 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38115",
      "detail": "RESCORED — CVE-2025-38115 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38120",
      "detail": "RESCORED — CVE-2025-38120 (Linux). CVSS 9.4 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38123",
      "detail": "RESCORED — CVE-2025-38123 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38124",
      "detail": "RESCORED — CVE-2025-38124 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38127",
      "detail": "RESCORED — CVE-2025-38127 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38139",
      "detail": "RESCORED — CVE-2025-38139 (Linux). CVSS 9.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38146",
      "detail": "RESCORED — CVE-2025-38146 (Linux). CVSS 9.4 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38150",
      "detail": "RESCORED — CVE-2025-38150 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38161",
      "detail": "RESCORED — CVE-2025-38161 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38162",
      "detail": "RESCORED — CVE-2025-38162 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38164",
      "detail": "RESCORED — CVE-2025-38164 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38165",
      "detail": "RESCORED — CVE-2025-38165 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38166",
      "detail": "RESCORED — CVE-2025-38166 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38168",
      "detail": "RESCORED — CVE-2025-38168 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38169",
      "detail": "RESCORED — CVE-2025-38169 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38173",
      "detail": "RESCORED — CVE-2025-38173 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38174",
      "detail": "RESCORED — CVE-2025-38174 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38177",
      "detail": "RESCORED — CVE-2025-38177 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38181",
      "detail": "RESCORED — CVE-2025-38181 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38184",
      "detail": "RESCORED — CVE-2025-38184 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38189",
      "detail": "RESCORED — CVE-2025-38189 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38191",
      "detail": "RESCORED — CVE-2025-38191 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38192",
      "detail": "RESCORED — CVE-2025-38192 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38193",
      "detail": "RESCORED — CVE-2025-38193 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38197",
      "detail": "RESCORED — CVE-2025-38197 (Linux). CVSS 7.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38204",
      "detail": "RESCORED — CVE-2025-38204 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38209",
      "detail": "RESCORED — CVE-2025-38209 (Linux). CVSS 9.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38211",
      "detail": "RESCORED — CVE-2025-38211 (Linux). CVSS 9.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38216",
      "detail": "RESCORED — CVE-2025-38216 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38218",
      "detail": "RESCORED — CVE-2025-38218 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38224",
      "detail": "RESCORED — CVE-2025-38224 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38232",
      "detail": "RESCORED — CVE-2025-38232 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38234",
      "detail": "RESCORED — CVE-2025-38234 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38238",
      "detail": "RESCORED — CVE-2025-38238 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38239",
      "detail": "RESCORED — CVE-2025-38239 (Linux). CVSS 7.3 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38242",
      "detail": "RESCORED — CVE-2025-38242 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38244",
      "detail": "RESCORED — CVE-2025-38244 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38246",
      "detail": "RESCORED — CVE-2025-38246 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38252",
      "detail": "RESCORED — CVE-2025-38252 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38253",
      "detail": "RESCORED — CVE-2025-38253 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38257",
      "detail": "RESCORED — CVE-2025-38257 (Linux). CVSS 7.3 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38261",
      "detail": "RESCORED — CVE-2025-38261 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38262",
      "detail": "RESCORED — CVE-2025-38262 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38264",
      "detail": "RESCORED — CVE-2025-38264 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38273",
      "detail": "RESCORED — CVE-2025-38273 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38276",
      "detail": "RESCORED — CVE-2025-38276 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38278",
      "detail": "RESCORED — CVE-2025-38278 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38283",
      "detail": "RESCORED — CVE-2025-38283 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38287",
      "detail": "RESCORED — CVE-2025-38287 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38290",
      "detail": "RESCORED — CVE-2025-38290 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38291",
      "detail": "RESCORED — CVE-2025-38291 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38292",
      "detail": "RESCORED — CVE-2025-38292 (Linux). CVSS 8.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38293",
      "detail": "RESCORED — CVE-2025-38293 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38303",
      "detail": "RESCORED — CVE-2025-38303 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38306",
      "detail": "RESCORED — CVE-2025-38306 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38314",
      "detail": "RESCORED — CVE-2025-38314 (Linux). CVSS 7.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38321",
      "detail": "RESCORED — CVE-2025-38321 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38325",
      "detail": "RESCORED — CVE-2025-38325 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38331",
      "detail": "RESCORED — CVE-2025-38331 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38333",
      "detail": "RESCORED — CVE-2025-38333 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38339",
      "detail": "RESCORED — CVE-2025-38339 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38342",
      "detail": "RESCORED — CVE-2025-38342 (Linux). CVSS 7 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38343",
      "detail": "RESCORED — CVE-2025-38343 (Linux). CVSS 8.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38365",
      "detail": "RESCORED — CVE-2025-38365 (Linux). CVSS 9.1 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38367",
      "detail": "RESCORED — CVE-2025-38367 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38372",
      "detail": "RESCORED — CVE-2025-38372 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38375",
      "detail": "RESCORED — CVE-2025-38375 (Linux). CVSS 8.4 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38377",
      "detail": "RESCORED — CVE-2025-38377 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38379",
      "detail": "RESCORED — CVE-2025-38379 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38382",
      "detail": "RESCORED — CVE-2025-38382 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38386",
      "detail": "RESCORED — CVE-2025-38386 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38393",
      "detail": "RESCORED — CVE-2025-38393 (Linux). CVSS 7.5 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38395",
      "detail": "RESCORED — CVE-2025-38395 (Linux). CVSS 8.4 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38398",
      "detail": "RESCORED — CVE-2025-38398 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38399",
      "detail": "RESCORED — CVE-2025-38399 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38405",
      "detail": "RESCORED — CVE-2025-38405 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38408",
      "detail": "RESCORED — CVE-2025-38408 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38411",
      "detail": "RESCORED — CVE-2025-38411 (Linux). CVSS 9.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38412",
      "detail": "RESCORED — CVE-2025-38412 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38413",
      "detail": "RESCORED — CVE-2025-38413 (Linux). CVSS 7.7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38424",
      "detail": "RESCORED — CVE-2025-38424 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38429",
      "detail": "RESCORED — CVE-2025-38429 (Linux). CVSS 10 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38430",
      "detail": "RESCORED — CVE-2025-38430 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38434",
      "detail": "RESCORED — CVE-2025-38434 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38435",
      "detail": "RESCORED — CVE-2025-38435 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38437",
      "detail": "RESCORED — CVE-2025-38437 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38439",
      "detail": "RESCORED — CVE-2025-38439 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38440",
      "detail": "RESCORED — CVE-2025-38440 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38446",
      "detail": "RESCORED — CVE-2025-38446 (Linux). CVSS 7.3 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38447",
      "detail": "RESCORED — CVE-2025-38447 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38449",
      "detail": "RESCORED — CVE-2025-38449 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38453",
      "detail": "RESCORED — CVE-2025-38453 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38455",
      "detail": "RESCORED — CVE-2025-38455 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38460",
      "detail": "RESCORED — CVE-2025-38460 (Linux). CVSS 7 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38461",
      "detail": "RESCORED — CVE-2025-38461 (Linux). CVSS 7 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38463",
      "detail": "RESCORED — CVE-2025-38463 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38466",
      "detail": "RESCORED — CVE-2025-38466 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38470",
      "detail": "RESCORED — CVE-2025-38470 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38471",
      "detail": "RESCORED — CVE-2025-38471 (Linux). CVSS 9.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38472",
      "detail": "RESCORED — CVE-2025-38472 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38475",
      "detail": "RESCORED — CVE-2025-38475 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38476",
      "detail": "RESCORED — CVE-2025-38476 (Linux). CVSS 9.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38477",
      "detail": "RESCORED — CVE-2025-38477 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38478",
      "detail": "RESCORED — CVE-2025-38478 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38486",
      "detail": "RESCORED — CVE-2025-38486 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38488",
      "detail": "RESCORED — CVE-2025-38488 (Linux). CVSS 9.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38490",
      "detail": "RESCORED — CVE-2025-38490 (Linux). CVSS 9.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38491",
      "detail": "RESCORED — CVE-2025-38491 (Linux). CVSS 8.2 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38495",
      "detail": "RESCORED — CVE-2025-38495 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38498",
      "detail": "RESCORED — CVE-2025-38498 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38499",
      "detail": "RESCORED — CVE-2025-38499 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38502",
      "detail": "RESCORED — CVE-2025-38502 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38505",
      "detail": "RESCORED — CVE-2025-38505 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38508",
      "detail": "RESCORED — CVE-2025-38508 (Linux). CVSS 7.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38511",
      "detail": "RESCORED — CVE-2025-38511 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38512",
      "detail": "RESCORED — CVE-2025-38512 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38514",
      "detail": "RESCORED — CVE-2025-38514 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38523",
      "detail": "RESCORED — CVE-2025-38523 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38524",
      "detail": "RESCORED — CVE-2025-38524 (Linux). CVSS 7.5 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38526",
      "detail": "RESCORED — CVE-2025-38526 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38527",
      "detail": "RESCORED — CVE-2025-38527 (Linux). CVSS 9.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38528",
      "detail": "RESCORED — CVE-2025-38528 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38532",
      "detail": "RESCORED — CVE-2025-38532 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38533",
      "detail": "RESCORED — CVE-2025-38533 (Linux). CVSS 9.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38539",
      "detail": "RESCORED — CVE-2025-38539 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38542",
      "detail": "RESCORED — CVE-2025-38542 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38545",
      "detail": "RESCORED — CVE-2025-38545 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38547",
      "detail": "RESCORED — CVE-2025-38547 (Linux). CVSS 7.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38552",
      "detail": "RESCORED — CVE-2025-38552 (Linux). CVSS 9.4 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38560",
      "detail": "RESCORED — CVE-2025-38560 (Linux). CVSS 9.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38561",
      "detail": "RESCORED — CVE-2025-38561 (Linux). CVSS 9.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38566",
      "detail": "RESCORED — CVE-2025-38566 (Linux). CVSS 9.8 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38571",
      "detail": "RESCORED — CVE-2025-38571 (Linux). CVSS 8.2 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38573",
      "detail": "RESCORED — CVE-2025-38573 (Linux). CVSS 7.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38574",
      "detail": "RESCORED — CVE-2025-38574 (Linux). CVSS 8.6 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38577",
      "detail": "RESCORED — CVE-2025-38577 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38578",
      "detail": "RESCORED — CVE-2025-38578 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38584",
      "detail": "RESCORED — CVE-2025-38584 (Linux). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38586",
      "detail": "RESCORED — CVE-2025-38586 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38590",
      "detail": "RESCORED — CVE-2025-38590 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38592",
      "detail": "RESCORED — CVE-2025-38592 (Linux). CVSS 8.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38599",
      "detail": "RESCORED — CVE-2025-38599 (Linux). CVSS 8.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38600",
      "detail": "RESCORED — CVE-2025-38600 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38601",
      "detail": "RESCORED — CVE-2025-38601 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38604",
      "detail": "RESCORED — CVE-2025-38604 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38607",
      "detail": "RESCORED — CVE-2025-38607 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38608",
      "detail": "RESCORED — CVE-2025-38608 (Linux). CVSS 8.6 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38614",
      "detail": "RESCORED — CVE-2025-38614 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38615",
      "detail": "RESCORED — CVE-2025-38615 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38616",
      "detail": "RESCORED — CVE-2025-38616 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38617",
      "detail": "RESCORED — CVE-2025-38617 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38619",
      "detail": "RESCORED — CVE-2025-38619 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38639",
      "detail": "RESCORED — CVE-2025-38639 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38640",
      "detail": "RESCORED — CVE-2025-38640 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38643",
      "detail": "RESCORED — CVE-2025-38643 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38652",
      "detail": "RESCORED — CVE-2025-38652 (Linux). CVSS 7.3 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38657",
      "detail": "RESCORED — CVE-2025-38657 (Linux). CVSS 7.3 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38658",
      "detail": "RESCORED — CVE-2025-38658 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38659",
      "detail": "RESCORED — CVE-2025-38659 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38660",
      "detail": "RESCORED — CVE-2025-38660 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38661",
      "detail": "RESCORED — CVE-2025-38661 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38662",
      "detail": "RESCORED — CVE-2025-38662 (Linux). CVSS 7.1 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38670",
      "detail": "RESCORED — CVE-2025-38670 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38675",
      "detail": "RESCORED — CVE-2025-38675 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38677",
      "detail": "RESCORED — CVE-2025-38677 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38678",
      "detail": "RESCORED — CVE-2025-38678 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38679",
      "detail": "RESCORED — CVE-2025-38679 (Linux). CVSS 7.3 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38687",
      "detail": "RESCORED — CVE-2025-38687 (Linux). CVSS 7.3 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38688",
      "detail": "RESCORED — CVE-2025-38688 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38707",
      "detail": "RESCORED — CVE-2025-38707 (Linux). CVSS 7.1 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38708",
      "detail": "RESCORED — CVE-2025-38708 (Linux). CVSS 9.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38710",
      "detail": "RESCORED — CVE-2025-38710 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38714",
      "detail": "RESCORED — CVE-2025-38714 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38715",
      "detail": "RESCORED — CVE-2025-38715 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38717",
      "detail": "RESCORED — CVE-2025-38717 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38724",
      "detail": "RESCORED — CVE-2025-38724 (Linux). CVSS 9.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38728",
      "detail": "RESCORED — CVE-2025-38728 (Linux). CVSS 9.1 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38733",
      "detail": "RESCORED — CVE-2025-38733 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38734",
      "detail": "RESCORED — CVE-2025-38734 (Linux). CVSS 9.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38735",
      "detail": "RESCORED — CVE-2025-38735 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-38737",
      "detail": "RESCORED — CVE-2025-38737 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39673",
      "detail": "RESCORED — CVE-2025-39673 (Linux). CVSS 9.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39677",
      "detail": "RESCORED — CVE-2025-39677 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39680",
      "detail": "RESCORED — CVE-2025-39680 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39682",
      "detail": "RESCORED — CVE-2025-39682 (Linux). CVSS 9.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39683",
      "detail": "RESCORED — CVE-2025-39683 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39688",
      "detail": "RESCORED — CVE-2025-39688 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39694",
      "detail": "RESCORED — CVE-2025-39694 (Linux). CVSS 7.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39696",
      "detail": "RESCORED — CVE-2025-39696 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39697",
      "detail": "RESCORED — CVE-2025-39697 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39698",
      "detail": "RESCORED — CVE-2025-39698 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39702",
      "detail": "RESCORED — CVE-2025-39702 (Linux). CVSS 9.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39703",
      "detail": "RESCORED — CVE-2025-39703 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39704",
      "detail": "RESCORED — CVE-2025-39704 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39710",
      "detail": "RESCORED — CVE-2025-39710 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39714",
      "detail": "RESCORED — CVE-2025-39714 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39718",
      "detail": "RESCORED — CVE-2025-39718 (Linux). CVSS 8.4 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39720",
      "detail": "RESCORED — CVE-2025-39720 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39723",
      "detail": "RESCORED — CVE-2025-39723 (Linux). CVSS 7.1 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39726",
      "detail": "RESCORED — CVE-2025-39726 (Linux). CVSS 9.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39732",
      "detail": "RESCORED — CVE-2025-39732 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39738",
      "detail": "RESCORED — CVE-2025-39738 (Linux). CVSS 7.3 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39750",
      "detail": "RESCORED — CVE-2025-39750 (Linux). CVSS 8.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39758",
      "detail": "RESCORED — CVE-2025-39758 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39761",
      "detail": "RESCORED — CVE-2025-39761 (Linux). CVSS 8.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39770",
      "detail": "RESCORED — CVE-2025-39770 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39776",
      "detail": "RESCORED — CVE-2025-39776 (Linux). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39779",
      "detail": "RESCORED — CVE-2025-39779 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39780",
      "detail": "RESCORED — CVE-2025-39780 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39785",
      "detail": "RESCORED — CVE-2025-39785 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39786",
      "detail": "RESCORED — CVE-2025-39786 (Linux). CVSS 7.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39787",
      "detail": "RESCORED — CVE-2025-39787 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39789",
      "detail": "RESCORED — CVE-2025-39789 (Linux). CVSS 7.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39790",
      "detail": "RESCORED — CVE-2025-39790 (Linux). CVSS 8.4 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39791",
      "detail": "RESCORED — CVE-2025-39791 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39792",
      "detail": "RESCORED — CVE-2025-39792 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39798",
      "detail": "RESCORED — CVE-2025-39798 (Linux). CVSS 7.3 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39800",
      "detail": "RESCORED — CVE-2025-39800 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39802",
      "detail": "RESCORED — CVE-2025-39802 (Linux). CVSS 7.5 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39804",
      "detail": "RESCORED — CVE-2025-39804 (Linux). CVSS 7.5 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39806",
      "detail": "RESCORED — CVE-2025-39806 (Linux). CVSS 8.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39809",
      "detail": "RESCORED — CVE-2025-39809 (Linux). CVSS 8.4 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39815",
      "detail": "RESCORED — CVE-2025-39815 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39825",
      "detail": "RESCORED — CVE-2025-39825 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39826",
      "detail": "RESCORED — CVE-2025-39826 (Linux). CVSS 8.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39827",
      "detail": "RESCORED — CVE-2025-39827 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39839",
      "detail": "RESCORED — CVE-2025-39839 (Linux). CVSS 8.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39841",
      "detail": "RESCORED — CVE-2025-39841 (Linux). CVSS 9.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39848",
      "detail": "RESCORED — CVE-2025-39848 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39849",
      "detail": "RESCORED — CVE-2025-39849 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39851",
      "detail": "RESCORED — CVE-2025-39851 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39857",
      "detail": "RESCORED — CVE-2025-39857 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39860",
      "detail": "RESCORED — CVE-2025-39860 (Linux). CVSS 8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39862",
      "detail": "RESCORED — CVE-2025-39862 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39864",
      "detail": "RESCORED — CVE-2025-39864 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39869",
      "detail": "RESCORED — CVE-2025-39869 (Linux). CVSS 8.4 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39872",
      "detail": "RESCORED — CVE-2025-39872 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39880",
      "detail": "RESCORED — CVE-2025-39880 (Linux). CVSS 9.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39882",
      "detail": "RESCORED — CVE-2025-39882 (Linux). CVSS 8.4 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39894",
      "detail": "RESCORED — CVE-2025-39894 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39897",
      "detail": "RESCORED — CVE-2025-39897 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39902",
      "detail": "RESCORED — CVE-2025-39902 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39906",
      "detail": "RESCORED — CVE-2025-39906 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39908",
      "detail": "RESCORED — CVE-2025-39908 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39918",
      "detail": "RESCORED — CVE-2025-39918 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39919",
      "detail": "RESCORED — CVE-2025-39919 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39924",
      "detail": "RESCORED — CVE-2025-39924 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39927",
      "detail": "RESCORED — CVE-2025-39927 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39928",
      "detail": "RESCORED — CVE-2025-39928 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39929",
      "detail": "RESCORED — CVE-2025-39929 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39930",
      "detail": "RESCORED — CVE-2025-39930 (Linux). CVSS 8.4 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39931",
      "detail": "RESCORED — CVE-2025-39931 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39932",
      "detail": "RESCORED — CVE-2025-39932 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39933",
      "detail": "RESCORED — CVE-2025-39933 (Linux). CVSS 9.4 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39941",
      "detail": "RESCORED — CVE-2025-39941 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39942",
      "detail": "RESCORED — CVE-2025-39942 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39943",
      "detail": "RESCORED — CVE-2025-39943 (Linux). CVSS 9.4 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39948",
      "detail": "RESCORED — CVE-2025-39948 (Linux). CVSS 9.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39949",
      "detail": "RESCORED — CVE-2025-39949 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39952",
      "detail": "RESCORED — CVE-2025-39952 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39956",
      "detail": "RESCORED — CVE-2025-39956 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39957",
      "detail": "RESCORED — CVE-2025-39957 (Linux). CVSS 7.1 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39960",
      "detail": "RESCORED — CVE-2025-39960 (Linux). CVSS 7.3 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39961",
      "detail": "RESCORED — CVE-2025-39961 (Linux). CVSS 8.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39962",
      "detail": "RESCORED — CVE-2025-39962 (Linux). CVSS 7.5 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39964",
      "detail": "RESCORED — CVE-2025-39964 (Linux). CVSS 7.8 → 3.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39965",
      "detail": "RESCORED — CVE-2025-39965 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-39966",
      "detail": "RESCORED — CVE-2025-39966 (Linux). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-40039",
      "detail": "RESCORED — CVE-2025-40039 (Linux). CVSS 8.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-40040",
      "detail": "RESCORED — CVE-2025-40040 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-40090",
      "detail": "RESCORED — CVE-2025-40090 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-40251",
      "detail": "RESCORED — CVE-2025-40251 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-68340",
      "detail": "RESCORED — CVE-2025-68340 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-68365",
      "detail": "RESCORED — CVE-2025-68365 (Linux). CVSS 8.2 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-68749",
      "detail": "RESCORED — CVE-2025-68749 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-68817",
      "detail": "RESCORED — CVE-2025-68817 (Linux). CVSS 9.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71068",
      "detail": "RESCORED — CVE-2025-71068 (Linux). CVSS 9.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71072",
      "detail": "RESCORED — CVE-2025-71072 (Linux). CVSS 8.2 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71074",
      "detail": "RESCORED — CVE-2025-71074 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71080",
      "detail": "RESCORED — CVE-2025-71080 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71085",
      "detail": "RESCORED — CVE-2025-71085 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71090",
      "detail": "RESCORED — CVE-2025-71090 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71093",
      "detail": "RESCORED — CVE-2025-71093 (Linux). CVSS 9.1 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71095",
      "detail": "RESCORED — CVE-2025-71095 (Linux). CVSS 9.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71100",
      "detail": "RESCORED — CVE-2025-71100 (Linux). CVSS 7.6 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71109",
      "detail": "RESCORED — CVE-2025-71109 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71112",
      "detail": "RESCORED — CVE-2025-71112 (Linux). CVSS 8.8 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71116",
      "detail": "RESCORED — CVE-2025-71116 (Linux). CVSS 9.1 → 7.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71120",
      "detail": "RESCORED — CVE-2025-71120 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71126",
      "detail": "RESCORED — CVE-2025-71126 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71127",
      "detail": "RESCORED — CVE-2025-71127 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71128",
      "detail": "RESCORED — CVE-2025-71128 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71130",
      "detail": "RESCORED — CVE-2025-71130 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71131",
      "detail": "RESCORED — CVE-2025-71131 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71132",
      "detail": "RESCORED — CVE-2025-71132 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71146",
      "detail": "RESCORED — CVE-2025-71146 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71150",
      "detail": "RESCORED — CVE-2025-71150 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71158",
      "detail": "RESCORED — CVE-2025-71158 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71159",
      "detail": "RESCORED — CVE-2025-71159 (Linux). CVSS 9.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71161",
      "detail": "RESCORED — CVE-2025-71161 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71183",
      "detail": "RESCORED — CVE-2025-71183 (Linux). CVSS 9.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71202",
      "detail": "RESCORED — CVE-2025-71202 (Linux). CVSS 8.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71204",
      "detail": "RESCORED — CVE-2025-71204 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71221",
      "detail": "RESCORED — CVE-2025-71221 (Linux). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71234",
      "detail": "RESCORED — CVE-2025-71234 (Linux). CVSS 8.8 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71236",
      "detail": "RESCORED — CVE-2025-71236 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71268",
      "detail": "RESCORED — CVE-2025-71268 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71269",
      "detail": "RESCORED — CVE-2025-71269 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71274",
      "detail": "RESCORED — CVE-2025-71274 (Linux). CVSS 7.8 → 4.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71286",
      "detail": "RESCORED — CVE-2025-71286 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71289",
      "detail": "RESCORED — CVE-2025-71289 (Linux). CVSS 7.1 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71292",
      "detail": "RESCORED — CVE-2025-71292 (Linux). CVSS 7.5 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71300",
      "detail": "RESCORED — CVE-2025-71300 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71302",
      "detail": "RESCORED — CVE-2025-71302 (Linux). CVSS 7.8 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-71311",
      "detail": "RESCORED — CVE-2025-71311 (Linux). CVSS 8.2 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-12086",
      "detail": "RESCORED — CVE-2026-12086 (IBM UCD - IBM UrbanCode Deploy). CVSS 6.2 → 5.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-20816",
      "detail": "RESCORED — CVE-2026-20816 (Microsoft Windows 10 Version 1607). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-20826",
      "detail": "RESCORED — CVE-2026-20826 (Microsoft Windows 10 Version 1607). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-20831",
      "detail": "RESCORED — CVE-2026-20831 (Microsoft Windows 10 Version 1607). CVSS 7.8 → 7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-46189",
      "detail": "RESCORED — CVE-2026-46189 (Linux). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-50148",
      "detail": "RESCORED — CVE-2026-50148 (metabase). CVSS 10 → 9.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-7364",
      "detail": "RESCORED — CVE-2026-7364 (IBM Verify Identity Access). CVSS 3.1 → 6.1 (NVD)."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2021-20322",
      "detail": "ENRICHED — CVE-2021-20322 (kernel). Received CVSS 7.4 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-53167",
      "detail": "ENRICHED — CVE-2026-53167 (Linux). Received CVSS 5.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
