{
  "day": "2026-07-31",
  "boundary": "UTC calendar day",
  "published_count": 183,
  "by_severity": {
    "CRITICAL": 26,
    "HIGH": 66,
    "MEDIUM": 76,
    "LOW": 15
  },
  "kev_count": 0,
  "exploit_reference_count": 2,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-38708",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02619,
      "epss_percentile": 0.84223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the system.setclock interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38708"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-38711",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02619,
      "epss_percentile": 0.84222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the system.upgrade_check interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38711"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-38713",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02619,
      "epss_percentile": 0.84223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "TR1200 v2.4.15, TR3000 v2.4.21, WR300 v2.4.25, WR1200 v2.4.23, WR1300 v2.4.22, WR1500 v2.3.10, WR3000 v2.4.19, WR3600 v2.3.16, and WR6500 v2.3.15 were discovered to contain a command injection vulnerability in the ipsec_conn interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38713"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-38710",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.02546,
      "epss_percentile": 0.83737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-77",
      "title": "TR1200 v2.4.15 and TR3000 v2.4.21 were discovered to contain a command injection vulnerability in the system.setclock interface. This vulnerability allows attackers to execute arbitrary commands as root via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38710"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-14483",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.02186,
      "epss_percentile": 0.80965,
      "kev": false,
      "kev_due_at": null,
      "vendor": "realtyna",
      "product": "Realtyna Organic IDX plugin + WPL Real Estate",
      "cwe": "CWE-434",
      "title": "Realtyna Organic IDX plugin + WPL Real Estate <= 5.2.0 - Unauthenticated Arbitrary File Upload via 'files[file]' Parameter via Public I/O 'set_property' Command",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14483"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-51785",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01149,
      "epss_percentile": 0.64328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-94",
      "title": "An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51785"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-9044",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.01129,
      "epss_percentile": 0.63822,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "AXE75 V1",
      "cwe": "CWE-78",
      "title": "Command Injection Vulnerability in OpenVPN of TP-Link Archer AXE75",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9044"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-16843",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00891,
      "epss_percentile": 0.56617,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hikvision",
      "product": "DS-3WAP521-SI",
      "cwe": "CWE-78",
      "title": "Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid credentials can exploit this flaw by sending crafted packets containing malicious commands to affected devices, leading to arbitrary command execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16843"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-15722",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00869,
      "epss_percentile": 0.5596,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11.7 E4S for RHEL 8",
      "cwe": "CWE-121",
      "title": "389-ds-base: 389-ds-base: pre-authentication stack buffer overflow in get_ruvelement_from_berval() via unbounded replica id parsing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15722"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-44615",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0084,
      "epss_percentile": 0.55023,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Zeppelin",
      "cwe": "CWE-22",
      "title": "Path traversal in NotebookRepo note and folder path composition",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-44615"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-52134",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.008,
      "epss_percentile": 0.53734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52134"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-11770",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00687,
      "epss_percentile": 0.49897,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11.7 E4S for RHEL 8",
      "cwe": "CWE-90",
      "title": "389-ds-base: 389-ds-base: pre-auth ldap filter injection in cleanallruv status check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-11770"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-56671",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00661,
      "epss_percentile": 0.48866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Comfy-Org",
      "product": "ComfyUI",
      "cwe": "CWE-22",
      "title": "ComfyUI: Path traversal in /experiment/models/preview allows arbitrary image file read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56671"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-16236",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00629,
      "epss_percentile": 0.47447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "realtyna",
      "product": "Realtyna Organic IDX plugin + WPL Real Estate",
      "cwe": "CWE-434",
      "title": "Realtyna Organic IDX plugin + WPL Real Estate <= 5.3.0 - Authenticated (Subscriber+) Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16236"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-68771",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00623,
      "epss_percentile": 0.47205,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Comfy-Org",
      "product": "ComfyUI",
      "cwe": "CWE-502",
      "title": "ComfyUI 0.23.0 Unauthenticated RCE via LoadTrainingDataset Pickle Deserialization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68771"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-58048",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00561,
      "epss_percentile": 0.4421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "cPanel",
      "cwe": "CWE-89",
      "title": "Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58048"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-55497",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00531,
      "epss_percentile": 0.42625,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cloudreve",
      "product": "cloudreve",
      "cwe": "CWE-400",
      "title": "Cloudreve: Server crash through image decompression/pixel bomb in thumbnail & avatar decoding (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55497"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-62391",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00522,
      "epss_percentile": 0.42127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Kyuubi",
      "cwe": "CWE-22",
      "title": "Apache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliases",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62391"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-18358",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00522,
      "epss_percentile": 0.42114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GNOME",
      "product": "gnome-remote-desktop",
      "cwe": "CWE-400",
      "title": "Gnome-remote-desktop: gnome-remote-desktop system-mode rdp server missing connection throttling allows unauthenticated denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18358"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-68770",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00521,
      "epss_percentile": 0.42028,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Hugging Face",
      "product": "sentence-transformers",
      "cwe": "CWE-94",
      "title": "sentence-transformers Arbitrary Code Execution on Local Model Load Despite trust_remote_code=False",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68770"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-58047",
      "cvss_base": 5.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00519,
      "epss_percentile": 0.4193,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebPros",
      "product": "cPanel",
      "cwe": "CWE-444",
      "title": "HTTP Smuggling in cPanel allows potential leak of credentials.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58047"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-21662",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00504,
      "epss_percentile": 0.41036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "FM Systems Employee",
      "cwe": "CWE-434",
      "title": "FMS Employee Allows Upload of Unrestricted Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21662"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-63223",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00493,
      "epss_percentile": 0.40354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codeigniter4",
      "product": "CodeIgniter4",
      "cwe": "CWE-434",
      "title": "CodeIgniter: Uploaded file extension validation bypass in is_image and mime_in rules",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63223"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-63222",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0045,
      "epss_percentile": 0.37558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codeigniter4",
      "product": "CodeIgniter4",
      "cwe": "CWE-22",
      "title": "CodeIgniter: Path traversal in UploadedFile::move() when using client-provided filenames",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63222"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-18452",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00432,
      "epss_percentile": 0.36151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Rich Source",
      "product": "DMS+ (Non-Mobile)",
      "cwe": "CWE-798",
      "title": "Rich Source｜DMS+ (Non-Mobile) - Use of Hard-coded Credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18452"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-56673",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0043,
      "epss_percentile": 0.36044,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Comfy-Org",
      "product": "ComfyUI",
      "cwe": "CWE-22",
      "title": "ComfyUI: Path traversal in LoadImage via the /prompt API allows arbitrary file existence probing and image exfiltration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56673"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-53551",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00429,
      "epss_percentile": 0.35952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "free5gc",
      "product": "free5gc",
      "cwe": "CWE-20",
      "title": "free5GC AUSF: null byte injection in supiOrSuci causes HTTP 500 internal service failure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53551"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-17346",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00424,
      "epss_percentile": 0.35585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgadmin.org",
      "product": "pgAdmin 4",
      "cwe": "CWE-89",
      "title": "pgAdmin 4: SQL injection via unescaped object names in index Statistics and publication/subscription dependency views (incomplete fix for CVE-2026-12044)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17346"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-53503",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00417,
      "epss_percentile": 0.34996,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thumbor",
      "product": "thumbor",
      "cwe": "CWE-20",
      "title": "Thumbor convolution filter allows divide-by-zero in C extension leading to remote DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53503"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-17566",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00408,
      "epss_percentile": 0.34198,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgadmin.org",
      "product": "pgAdmin 4",
      "cwe": "CWE-78",
      "title": "pgAdmin 4: RCE via backslash-escape mismatch in Import/Export Data query guard (incomplete defense, sibling gap to CVE-2025-13780)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17566"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-53510",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.32948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "savonrb",
      "product": "savon",
      "cwe": "CWE-94",
      "title": "Savon::Model evaluates WSDL operation names as Ruby source",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53510"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-62959",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00384,
      "epss_percentile": 0.31692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coturn",
      "product": "coturn",
      "cwe": "CWE-125",
      "title": "Coturn: Pre-authentication heap memory disclosure in ACME redirect (`try_acme_redirect`)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62959"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-55100",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00382,
      "epss_percentile": 0.31527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "kyndryl-open-source",
      "product": "hashi-vault-js",
      "cwe": "CWE-23",
      "title": "hashi-vault-js has a path traversal and query parameter injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55100"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-17351",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00381,
      "epss_percentile": 0.31432,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgadmin.org",
      "product": "pgAdmin 4",
      "cwe": "CWE-89",
      "title": "pgAdmin 4: AI Assistant read-only transaction bypass via sqlparse/PostgreSQL lexer disagreement (incomplete fix for CVE-2026-12045)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17351"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-63221",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00377,
      "epss_percentile": 0.30989,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codeigniter4",
      "product": "CodeIgniter4",
      "cwe": "CWE-89",
      "title": "CodeIgniter: SQL injection is possible via Query Builder deleteBatch() when used with where() conditions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63221"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-17567",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00377,
      "epss_percentile": 0.3098,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wpmanageninja",
      "product": "Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder",
      "cwe": "CWE-639",
      "title": "Fluent Forms <= 6.2.8 - Unauthenticated Sensitive Information Exposure via Insecure Direct Object Reference and Weak Transaction Hash in 'transaction' Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17567"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-53573",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00377,
      "epss_percentile": 0.30995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "geonetwork",
      "product": "core-geonetwork",
      "cwe": "CWE-601",
      "title": "core-geonetwork has an Open Redirect Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53573"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-55495",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00376,
      "epss_percentile": 0.3094,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cloudreve",
      "product": "cloudreve",
      "cwe": "CWE-22",
      "title": "Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55495"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-54909",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00371,
      "epss_percentile": 0.30388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pion",
      "product": "stun",
      "cwe": "CWE-20",
      "title": "Pion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54909"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-13392",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.0037,
      "epss_percentile": 0.30231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ElementsKit Elementor Addons",
      "cwe": "CWE-94",
      "title": "ElementsKit Lite < 3.10.01 - Subsite Administrator+ PHP Code Injection via Custom Widget Builder (Multisite)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13392"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-55496",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00361,
      "epss_percentile": 0.29326,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cloudreve",
      "product": "cloudreve",
      "cwe": "CWE-200",
      "title": "Cloudreve: Inactive/banned account emails leaked via GET /api/v4/user/search because SearchActive() omits the active-status predicate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55496"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-64607",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00359,
      "epss_percentile": 0.29146,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache HttpComponents Client",
      "cwe": "CWE-772",
      "title": "Apache HttpComponents Client: Connection Leak on Content-Encoding Decode Error Leads to Pool Exhaustion DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64607"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-53502",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00357,
      "epss_percentile": 0.2892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thumbor",
      "product": "thumbor",
      "cwe": "CWE-22",
      "title": "Thumbor has path traversal via post-validation URL decoding bypass in file_loader",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53502"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-46594",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00348,
      "epss_percentile": 0.27963,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHP Jabbers",
      "product": "PHP Poll Script",
      "cwe": "CWE-79",
      "title": "Reflected XSS in PHP Poll Script",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46594"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-45376",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00341,
      "epss_percentile": 0.27284,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decidim",
      "product": "decidim",
      "cwe": "CWE-89",
      "title": "Decidim: Admin user search allows SQL injection through similarity-based sorting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45376"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-53505",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00339,
      "epss_percentile": 0.26958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thumbor",
      "product": "thumbor",
      "cwe": "CWE-400",
      "title": "Thumbor proportion filter allows unbounded post-transform resize leading to remote DoS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53505"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-55502",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00338,
      "epss_percentile": 0.26901,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cloudreve",
      "product": "cloudreve",
      "cwe": "CWE-863",
      "title": "Cloudreve: OAuth Admin.Read scope can update OneDrive storage policy credentials",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55502"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2025-69946",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00337,
      "epss_percentile": 0.26694,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters district_id , division_id, region_id, and ward_id.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69946"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-52856",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pterodactyl",
      "product": "wings",
      "cwe": "CWE-129",
      "title": "Wings: Maliciously crafted packet during SFTP connection handshake causes denial of service",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52856"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-53504",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00335,
      "epss_percentile": 0.26484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thumbor",
      "product": "thumbor",
      "cwe": "CWE-400",
      "title": "Thumbor has Regex Denial of Service (ReDoS) in `convolution` filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53504"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-55499",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00331,
      "epss_percentile": 0.26103,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cloudreve",
      "product": "cloudreve",
      "cwe": "CWE-863",
      "title": "Cloudreve: Broken access control in file event stream leaks activity events for unshared siblings to single-file share recipients",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55499"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-54725",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0032,
      "epss_percentile": 0.24927,
      "kev": false,
      "kev_due_at": null,
      "vendor": "bank-vaults",
      "product": "vault-secrets-webhook",
      "cwe": "CWE-918",
      "title": "vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via TokenRequest API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54725"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-65310",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00318,
      "epss_percentile": 0.24687,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ANDRITZ",
      "product": "HIPASE-250",
      "cwe": "CWE-306",
      "title": "Missing authentication and permissive CORS policy",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65310"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-14319",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00316,
      "epss_percentile": 0.24425,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "GiveWP",
      "cwe": "CWE-200",
      "title": "GiveWP < 4.16.3 - Unauthenticated Recurring Donor Information Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14319"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-17561",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00314,
      "epss_percentile": 0.24185,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Innotim Software, Telecommunications and Consulting Trade Ltd. Co.",
      "product": "Logsign SIEM",
      "cwe": "CWE-94",
      "title": "Unauthenticated RCE in Innotim Software's Logsign SIEM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17561"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2026-43830",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00314,
      "epss_percentile": 0.24186,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tbc",
      "product": "tbc",
      "cwe": "CWE-77",
      "title": "tbc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43830"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-53599",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00314,
      "epss_percentile": 0.24231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "redaxo",
      "product": "core",
      "cwe": "CWE-434",
      "title": "Redaxo has a Mediapool isAllowedExtension bypass via multi-segment filename that leads to authenticated RCE on Apache mod_php multi-extension handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53599"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-18141",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00309,
      "epss_percentile": 0.23609,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Ansible Automation Platform 2.6 for RHEL 9",
      "cwe": "CWE-295",
      "title": "Aap-gateway: aap-gateway: authentication bypass in event-driven ansible via forged http header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18141"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2025-69948",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00307,
      "epss_percentile": 0.2338,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-69948"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-62323",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00306,
      "epss_percentile": 0.23304,
      "kev": false,
      "kev_due_at": null,
      "vendor": "cloudreve",
      "product": "cloudreve",
      "cwe": "CWE-863",
      "title": "Cloudreve: Unauthorized file write via WOPI view sessions whose access token secret is ignored",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62323"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-59232",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.2316,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Roskus",
      "product": "Prospero Flow CRM",
      "cwe": "CWE-79",
      "title": "Stored Cross-site Scripting in Prospero Flow CRM lead name field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59232"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-12720",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00304,
      "epss_percentile": 0.23147,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Kirki",
      "cwe": "CWE-502",
      "title": "Kirki < 6.0.13 - Unauthenticated PHP Object Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12720"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-65841",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.003,
      "epss_percentile": 0.22692,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xdan",
      "product": "jodit",
      "cwe": "CWE-80",
      "title": "Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65841"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-46593",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHP Jabbers",
      "product": "PHP Poll Script",
      "cwe": "CWE-89",
      "title": "Authenticated SQL Injection in PHP Poll Script",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46593"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-18437",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00297,
      "epss_percentile": 0.2231,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mailerpress",
      "product": "MailerPress – Newsletter, email marketing & AI automation",
      "cwe": "CWE-862",
      "title": "MailPress <= 1.5.0 - Missing Authorization to Unauthenticated Contact Updates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18437"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-17347",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgadmin.org",
      "product": "pgAdmin 4",
      "cwe": "CWE-78",
      "title": "pgAdmin 4: OS command injection in MASTER_PASSWORD_HOOK via untrusted username substitution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17347"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-14333",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00296,
      "epss_percentile": 0.22236,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Demi",
      "cwe": "CWE-269",
      "title": "Demi - One Click Demo Import, Backup & Site Migration < 0.0.7 - Unauthenticated Sensitive Data Exposure via Public Backup Directory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14333"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-67822",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00295,
      "epss_percentile": 0.2208,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack overflow.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67822"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-67607",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00295,
      "epss_percentile": 0.2211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "hfiref0x",
      "product": "LightFTP",
      "cwe": "CWE-367",
      "title": "LightFTP 2.3.1 Race Condition DoS via worker_thread_cleanup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67607"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-10686",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.22036,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-835",
      "title": "Missing hop-limit decrement on IPv6 forwarding path allows unbounded packet looping (DoS) in Zephyr routers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10686"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-62999",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00294,
      "epss_percentile": 0.22064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "copier-org",
      "product": "copier",
      "cwe": "CWE-22",
      "title": "Copier: Percent-encoded dot segments in template URLs can allow trusted-prefix escape (Incomplete fix for trust-prefix bypass)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62999"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-18394",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.22021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "Strands Agents Tools",
      "cwe": "CWE-863",
      "title": "Incorrect authorization in Strands Agents Tools http_request proxy credential exfiltration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18394"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-54729",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21827,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HackingRepo",
      "product": "dssrf-js",
      "cwe": "CWE-918",
      "title": "dssrf: any users using 1.1.1.1 DNS is impacted by SSRF",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54729"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-12695",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21779,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "miniOrange 2FA",
      "cwe": "CWE-287",
      "title": "miniOrange 2FA < 6.2.6 - 2FA Bypass via Attacker-Controlled ga_secret",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12695"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-17349",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00288,
      "epss_percentile": 0.21328,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgadmin.org",
      "product": "pgAdmin 4",
      "cwe": "CWE-522",
      "title": "pgAdmin 4: Adhoc server clone leaks another user's stored database credentials and ownership to a non-owner",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17349"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-53500",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00287,
      "epss_percentile": 0.21267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thumbor",
      "product": "thumbor",
      "cwe": "CWE-918",
      "title": "Thumbor treats ALLOWED_SOURCES string patterns as unescaped regex, allowing hostname bypass via wildcard dot",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53500"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-18481",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "AWS Ops Wheel",
      "cwe": "CWE-79",
      "title": "Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18481"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2025-67650",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00279,
      "epss_percentile": 0.20472,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHP Jabbers",
      "product": "Appointment Scheduler",
      "cwe": "CWE-89",
      "title": "Authenticated SQL Injection in PHP Jabbers scripts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67650"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-45330",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00279,
      "epss_percentile": 0.20442,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decidim",
      "product": "decidim",
      "cwe": "CWE-639",
      "title": "Decidim: Veriﬁcation admins can access supplied IDs from other organisations",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45330"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-54768",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00278,
      "epss_percentile": 0.20279,
      "kev": false,
      "kev_due_at": null,
      "vendor": "wp-graphql",
      "product": "wp-graphql",
      "cwe": "CWE-204",
      "title": "WPGraphQL has deprecated `user` field on SendPasswordResetEmailPayload that leaks user existence + profile (defeats explicit anti-enumeration design)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54768"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-14919",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00277,
      "epss_percentile": 0.2021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ShopMonitor.io",
      "cwe": "CWE-287",
      "title": "ShopMonitor.io < 1.2.0 - Unauthenticated Administrator Account Takeover via Password-Reset Email Reroute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14919"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-51953",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00276,
      "epss_percentile": 0.2015,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-613",
      "title": "An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management module, authentication logic, logout handler components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51953"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-52855",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00274,
      "epss_percentile": 0.19903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pterodactyl",
      "product": "wings",
      "cwe": "CWE-200",
      "title": "Wings exposes node configuration secrets through egg configuration-file templating",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52855"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2025-67649",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00274,
      "epss_percentile": 0.19834,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHP Jabbers",
      "product": "Car Rental Script",
      "cwe": "CWE-89",
      "title": "Unauthenticated SQL Injection in PHP Jabbers - Car Rental Script script",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67649"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-45377",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00274,
      "epss_percentile": 0.19865,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decidim",
      "product": "decidim",
      "cwe": "CWE-200",
      "title": "Decidim: Private exports can be downloaded through reusable links",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45377"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-65311",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00269,
      "epss_percentile": 0.1913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ANDRITZ",
      "product": "HIPASE-250",
      "cwe": "CWE-284",
      "title": "Missing authentication for logging-configuration endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65311"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-16504",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00268,
      "epss_percentile": 0.19085,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VPS.org",
      "product": "Zulip template",
      "cwe": "CWE-321",
      "title": "VPS.org one-click Zulip template deployment instance contains multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16504"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-12721",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Kirki",
      "cwe": "CWE-89",
      "title": "Kirki < 6.0.13 - Unauthenticated SQL Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12721"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-54737",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00262,
      "epss_percentile": 0.18137,
      "kev": false,
      "kev_due_at": null,
      "vendor": "phun-ky",
      "product": "defaults-deep",
      "cwe": "CWE-1321",
      "title": "@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54737"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-59231",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00259,
      "epss_percentile": 0.17754,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ccyl13",
      "product": "Pentestify",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery in Pentestify PDF export via unvalidated image URLs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59231"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-15048",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00256,
      "epss_percentile": 0.17421,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Geeky Bot",
      "cwe": "CWE-200",
      "title": "GeekyBot < 1.2.8 - Unauthenticated Sensitive Information Exposure via Chat History",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15048"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2026-65981",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0025,
      "epss_percentile": 0.16618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "coturn",
      "product": "coturn",
      "cwe": "CWE-639",
      "title": "Coturn: MOBILITY-TICKET session-resume authorization bypass allows cross-user TURN allocation takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65981"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-16503",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00246,
      "epss_percentile": 0.16216,
      "kev": false,
      "kev_due_at": null,
      "vendor": "VPS.org",
      "product": "Supabase template",
      "cwe": "CWE-1188",
      "title": "VPS.org one-click Supabase template deployment instance contains multiple vulnerabilities",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16503"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-13609",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00246,
      "epss_percentile": 0.16179,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Frontend Admin by DynamiApps",
      "cwe": "CWE-79",
      "title": "Frontend Admin by DynamiApps < 3.29.9 - Unauthenticated Stored Cross-Site Scripting via Form Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13609"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-43829",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tbc",
      "product": "tbc",
      "cwe": "CWE-121",
      "title": "tbc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43829"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2026-43831",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tbc",
      "product": "tbc",
      "cwe": "CWE-121",
      "title": "tbc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43831"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-43832",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00245,
      "epss_percentile": 0.16024,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tbc",
      "product": "tbc",
      "cwe": "CWE-121",
      "title": "tbc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43832"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-54706",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "onionshare",
      "product": "onionshare",
      "cwe": "CWE-59",
      "title": "OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54706"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-18157",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15496,
      "kev": false,
      "kev_due_at": null,
      "vendor": "RedHatInsights",
      "product": "yggdrasil-worker-package-manager",
      "cwe": "CWE-88",
      "title": "Yggdrasil-worker-package-manager: yggdrasil-worker-package-manager: remote code execution via apt argument injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18157"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-14930",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0024,
      "epss_percentile": 0.15337,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "JS Help Desk",
      "cwe": "CWE-862",
      "title": "JS Help Desk < 3.1.4 - Unauthenticated Arbitrary Ticket File Attachment Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14930"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-17348",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00238,
      "epss_percentile": 0.15163,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgadmin.org",
      "product": "pgAdmin 4",
      "cwe": "CWE-306",
      "title": "pgAdmin 4: Missing authentication decorator on Constraints, preferences, Debugger and Schema Diff routes allows unauthenticated access in SERVER mode (incomplete fix for CVE-2026-12046)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17348"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-56672",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00237,
      "epss_percentile": 0.1495,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Comfy-Org",
      "product": "ComfyUI",
      "cwe": "CWE-79",
      "title": "ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56672"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-14833",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00235,
      "epss_percentile": 0.14785,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Lightbox with PhotoSwipe",
      "cwe": "CWE-79",
      "title": "Lightbox with PhotoSwipe < 5.9.0 - Author+ Stored XSS via data-lbwps-caption Attribute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14833"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-14541",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14516,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "mcp-toolbox",
      "cwe": "CWE-287",
      "title": "Authentication Bypass and Audience Confusion in MCP Toolbox OAuth Provider",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14541"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-34495",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "FM Systems Employee",
      "cwe": "CWE-79",
      "title": "FMS Employee vulnerable to XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34495"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-34497",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14616,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "FM Systems Employee",
      "cwe": "CWE-80",
      "title": "FMS Employee Vulnerable to HTML Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34497"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-14554",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Check & Log Email",
      "cwe": "CWE-89",
      "title": "Check & Log Email < 2.0.15 - Admin+ SQL Injection via d and s Parameters",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14554"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-54707",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "onionshare",
      "product": "onionshare",
      "cwe": "CWE-863",
      "title": "OnionShare Receive mode writes uploaded files even when file uploads are disabled",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54707"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-18436",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00227,
      "epss_percentile": 0.13696,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mailerpress",
      "product": "MailerPress – Newsletter, email marketing & AI automation",
      "cwe": "CWE-862",
      "title": "MailerPress <= 1.5.0 - Missing Authorization to Unauthenticated Arbitrary Modification via REST API Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18436"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-12251",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00226,
      "epss_percentile": 0.13604,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ultimate Member",
      "cwe": "CWE-269",
      "title": "Ultimate Member < 2.12.1 - Unauthenticated Privilege Escalation via Role Selection Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12251"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-56670",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00224,
      "epss_percentile": 0.133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Comfy-Org",
      "product": "ComfyUI",
      "cwe": "CWE-79",
      "title": "ComfyUI: Stored XSS via SVG file upload on the /view endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56670"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-52371",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00224,
      "epss_percentile": 0.13335,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-918",
      "title": "A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticated attackers to scan resources via supplying a crafted HTTP request.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52371"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-15258",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12958,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Product Feed Manager For WooCommerce",
      "cwe": "CWE-89",
      "title": "Product Feed Manager for WooCommerce < 7.6.1 - Contributor+ SQL Injection via Feed Filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15258"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-18446",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.1298,
      "kev": false,
      "kev_due_at": null,
      "vendor": "fast-uri",
      "product": "fast-uri",
      "cwe": "CWE-436",
      "title": "fast-uri vulnerable to host confusion via backslash authority introducer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18446"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-14317",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00221,
      "epss_percentile": 0.12923,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "GiveWP",
      "cwe": "CWE-862",
      "title": "GiveWP < 4.16.3 - Unauthenticated Payment Gateway Restriction Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14317"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-14928",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12641,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "JS Help Desk",
      "cwe": "CWE-200",
      "title": "JS Help Desk < 3.1.4 - Subscriber+ Sensitive Information Disclosure via checkAIReplyTicketsBySubject",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14928"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-14931",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00219,
      "epss_percentile": 0.12642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "JS Help Desk",
      "cwe": "CWE-200",
      "title": "JS Help Desk < 3.1.4 - Contributor+ User Email Disclosure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14931"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-14537",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00216,
      "epss_percentile": 0.12345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "mcp-toolbox",
      "cwe": "CWE-863",
      "title": "Authorization Bypass in MCP Toolbox Legacy HTTP Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14537"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-17350",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00216,
      "epss_percentile": 0.12343,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pgadmin.org",
      "product": "pgAdmin 4",
      "cwe": "CWE-862",
      "title": "pgAdmin 4: Tool permission bypass via backend routes and Socket.IO handlers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-17350"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-14539",
      "cvss_base": 6.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0021,
      "epss_percentile": 0.11475,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "mcp-toolbox",
      "cwe": "CWE-770",
      "title": "Denial of Service via Unrestricted Payload Buffering in MCP Toolbox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14539"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-53501",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00208,
      "epss_percentile": 0.11259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "thumbor",
      "product": "thumbor",
      "cwe": "CWE-347",
      "title": "Thumbor has HMAC validation bypass via multiple .replace() calls when removing URL signature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-53501"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-14830",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00208,
      "epss_percentile": 0.11291,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "FlxWoo",
      "cwe": "CWE-287",
      "title": "FlxWoo < 3.1.1 - Unauthenticated Payment Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14830"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-55825",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00208,
      "epss_percentile": 0.113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "contao",
      "product": "contao",
      "cwe": "CWE-22",
      "title": "Contao: Possible path traversal in job download URIs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55825"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-15227",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00207,
      "epss_percentile": 0.11121,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Checkmk GmbH",
      "product": "Checkmk",
      "cwe": "CWE-862",
      "title": "Missing Authorization Allows Editing of Foreign Reports",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15227"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-67350",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00205,
      "epss_percentile": 0.10806,
      "kev": false,
      "kev_due_at": null,
      "vendor": "s9y",
      "product": "Serendipity",
      "cwe": "CWE-601",
      "title": "Serendipity < 2.6.1 Open Redirect via exit.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67350"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-15209",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "JS Help Desk",
      "cwe": "CWE-639",
      "title": "JS Help Desk – AI-Powered Support & Ticketing System < 3.1.5 - Subscriber+ Cross-User Support Ticket Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15209"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-18208",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10371,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: inactive out-of-audience token introspection leaks signed jwt claim",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18208"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-18206",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00201,
      "epss_percentile": 0.10327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-20",
      "title": "Keycloak-services: keycloak-services: client policy source-host wildcard domain matching bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18206"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-43833",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00197,
      "epss_percentile": 0.09881,
      "kev": false,
      "kev_due_at": null,
      "vendor": "tbc",
      "product": "tbc",
      "cwe": null,
      "title": "tbc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-43833"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-56568",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00196,
      "epss_percentile": 0.09725,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL iControl",
      "cwe": "CWE-209",
      "title": "HCL iControl is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56568"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-18209",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09286,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-1288",
      "title": "Keycloak-services: keycloak-services: oidc redirect_uri fragment bypass in http parameter pollution check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18209"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-18217",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00193,
      "epss_percentile": 0.09287,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-20",
      "title": "Keycloak-services: keycloak-services: saml http-redirect binding response preserves query string leading to parameter pollution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18217"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-16105",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00192,
      "epss_percentile": 0.09235,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: missing per-role authorization on rolecontainerresource composite endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16105"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-10685",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-416",
      "title": "Use-after-free of GATT subscribe params in Bluetooth host CCC-write response handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10685"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-18214",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00189,
      "epss_percentile": 0.08885,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: google external access-token exchange bypasses hosted-domain restriction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18214"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-18215",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00188,
      "epss_percentile": 0.0871,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-287",
      "title": "Keycloak-services: keycloak-services: microsoft external access-token exchange bypasses configured tenant",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18215"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-14538",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00186,
      "epss_percentile": 0.08573,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "mcp-toolbox",
      "cwe": "CWE-285",
      "title": "BigQuery Dataset Allowlist Bypass via Metadata Dry-Run in MCP Toolbox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14538"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2025-62347",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08453,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL",
      "product": "HCL iControl",
      "cwe": "CWE-20",
      "title": "HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and potential security bypasses. This was caused by an implementation flaw in an architectural security tactic that fails to properly validate whether the received input matches the expected type.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-62347"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-18203",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08084,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-863",
      "title": "Keycloak-services: keycloak-services: group policy extendchildren matches sibling group path prefixes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18203"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-14843",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Events Made Easy",
      "cwe": "CWE-639",
      "title": "Events Made Easy < 3.1.4 - Unauthenticated Person Data Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14843"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-57232",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00182,
      "epss_percentile": 0.08096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "contao",
      "product": "contao",
      "cwe": "CWE-918",
      "title": "Contao: Server-Side Request Forgery (SSRF) via Unvalidated RSS Feed URL in Feed Reader Module",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-57232"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-62324",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0018,
      "epss_percentile": 0.07823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "xdan",
      "product": "jodit",
      "cwe": "CWE-79",
      "title": "Jodit has incomplete javascript: scheme normalization in sanitizeHTMLElement href check that allows link XSS",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62324"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-18211",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00178,
      "epss_percentile": 0.07654,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-20",
      "title": "Keycloak-services: keycloak-services: secure-client-uris policy bypass via localhost-prefixed domains",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18211"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-14849",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00178,
      "epss_percentile": 0.0762,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Paid Membership Subscriptions",
      "cwe": "CWE-552",
      "title": "Paid Member Subscriptions < 3.0.7 - Unauthenticated Sensitive Information Exposure via Residual Export Files",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14849"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-15381",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00178,
      "epss_percentile": 0.07664,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Go Maps",
      "cwe": "CWE-89",
      "title": "WP Go Maps < 10.1.04 - Unauthenticated SQL Injection via Markers REST filter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15381"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-56570",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07593,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL iControl",
      "cwe": "CWE-522",
      "title": "HCL iControl is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56570"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-65313",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00176,
      "epss_percentile": 0.07474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ANDRITZ",
      "product": "HIPASE-250",
      "cwe": "CWE-798",
      "title": "Use of hard-coded VNC credentials in the engineering-workstation provisioning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65313"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-28144",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00176,
      "epss_percentile": 0.07462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Flipper Code",
      "product": "WP Maps",
      "cwe": "CWE-201",
      "title": "WordPress WP Maps plugin <= 4.9.6 - Sensitive Data Exposure vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28144"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-58039",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00175,
      "epss_percentile": 0.07373,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nodejs",
      "product": "node",
      "cwe": "CWE-284",
      "title": "A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58039"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-25552",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00173,
      "epss_percentile": 0.07064,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TryGhost",
      "product": "Ghost-CLI",
      "cwe": "CWE-348",
      "title": "Ghost CLI < 1.30.1 IP Spoofing via X-Forwarded-For Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-25552"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-56571",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00172,
      "epss_percentile": 0.06969,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL iControl",
      "cwe": "CWE-209",
      "title": "HCL iControl is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56571"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-45086",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00171,
      "epss_percentile": 0.06904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "decidim",
      "product": "decidim",
      "cwe": "CWE-862",
      "title": "Decidim: Forms admin question editor lacks authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-45086"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-12697",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06738,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "wpForo Forum",
      "cwe": "CWE-639",
      "title": "wpForo Forum < 3.1.2 - Subscriber+ Cross-User AI Chat Message Deletion via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12697"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2025-67651",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06379,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PHP Jabbers",
      "product": "Appointment Scheduler",
      "cwe": "CWE-352",
      "title": "CSRF in PHP Jabbers scripts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-67651"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-14862",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00166,
      "epss_percentile": 0.06388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Support Genix",
      "cwe": "CWE-862",
      "title": "Support Genix Lite < 1.4.48 - Unauthenticated Ticket Attachment Download via Missing Authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14862"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-10079",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00165,
      "epss_percentile": 0.06253,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Advanced Cluster Security 4",
      "cwe": "CWE-345",
      "title": "Stackrox: stackrox: deploy-time policy enforcement and visibility bypass via label injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10079"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-14834",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00164,
      "epss_percentile": 0.06151,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Mailgun for WordPress",
      "cwe": "CWE-284",
      "title": "Mailgun for WordPress < 2.2.1 - Unauthenticated Arbitrary Mailgun List Subscription via add_list AJAX",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14834"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-14845",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "NewStatPress",
      "cwe": "CWE-79",
      "title": "NewStatPress < 1.4.5 - Unauthenticated Stored XSS via Top Post Widget",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14845"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-12376",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05878,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Academy LMS",
      "cwe": "CWE-639",
      "title": "Academy LMS <= 3.8.2 - Subscriber+ Sensitive Information Disclosure via quiz_attempts REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12376"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-14847",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05874,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Paid Membership Subscriptions",
      "cwe": "CWE-639",
      "title": "Paid Member Subscriptions < 3.0.7 - Subscriber+ Payment Data Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14847"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-14927",
      "cvss_base": 3.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00162,
      "epss_percentile": 0.05918,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "FluentCart A New Era of eCommerce",
      "cwe": "CWE-639",
      "title": "FluentCart < 1.5.3 - Unauthenticated Order PII Disclosure via Print Routes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14927"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-55824",
      "cvss_base": 2.6,
      "cvss_severity": "LOW",
      "epss_score": 0.00154,
      "epss_percentile": 0.05093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "contao",
      "product": "contao",
      "cwe": "CWE-200",
      "title": "Contao crawler leaks auth credentials to external hosts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-55824"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-65309",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00152,
      "epss_percentile": 0.04914,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ANDRITZ",
      "product": "HIPASE-250",
      "cwe": "CWE-257",
      "title": "Storage of passwords in a reversible format",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65309"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-14929",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04908,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "JS Help Desk",
      "cwe": "CWE-863",
      "title": "JS Help Desk < 3.1.4 - Subscriber+ Ticket Reply Modification via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14929"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-54785",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00151,
      "epss_percentile": 0.04839,
      "kev": false,
      "kev_due_at": null,
      "vendor": "eLyiN",
      "product": "gemini-bridge",
      "cwe": "CWE-22",
      "title": "gemini-bridge vulnerable to arbitrary local file read via consult_gemini_with_files inline mode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54785"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-14921",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Ultimate Addons for WPBakery Page Builder",
      "cwe": "CWE-79",
      "title": "Ultimate Addons for WPBakery Page Builder < 3.21.5 - Contributor+ Stored XSS via ult_buttons Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14921"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-14922",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04611,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "WP Photo Album Plus",
      "cwe": "CWE-79",
      "title": "WP Photo Album Plus < 9.2.04.003 - Subscriber+ Stored XSS via Photo Comment",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14922"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-52232",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04615,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "A reflected cross-site scripting (XSS) vulnerability in the /logo.asp component of FS Inc S3150-8T2F Switch 2.2.0D Build 118101 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted URL.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52232"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-13393",
      "cvss_base": 3.5,
      "cvss_severity": "LOW",
      "epss_score": 0.00142,
      "epss_percentile": 0.04034,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ElementsKit Elementor Addons",
      "cwe": "CWE-79",
      "title": "ElementsKit Lite < 3.10.01 - Subsite Administrator+ Stored XSS via Megamenu Menu-Item Settings (Multisite)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13393"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-65636",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00141,
      "epss_percentile": 0.03926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ufirstgroup",
      "product": "ymlr",
      "cwe": "CWE-93",
      "title": "YAML injection via unescaped newlines in ymlr document comments",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65636"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-34641",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00139,
      "epss_percentile": 0.03737,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Premiere",
      "cwe": "CWE-787",
      "title": "Premiere Pro | Out-of-bounds Write (CWE-787)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34641"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-8155",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00138,
      "epss_percentile": 0.03639,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "BuddyPress",
      "cwe": "CWE-639",
      "title": "BuddyPress < 14.5.0 - Subscriber+ Private Messages Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8155"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-50986",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00135,
      "epss_percentile": 0.03437,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-352",
      "title": "PrestaShop module, totadministrativemandate <1.8.1 is vulnerable to Cross Site Request Forgery (CSRF). The payment validation controller has no CSRF token. An attacker can confirm an order in an awaiting status by hijacking a link.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-50986"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-63220",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00135,
      "epss_percentile": 0.03455,
      "kev": false,
      "kev_due_at": null,
      "vendor": "codeigniter4",
      "product": "CodeIgniter4",
      "cwe": "CWE-348",
      "title": "CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63220"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-18218",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.03178,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Build of Keycloak",
      "cwe": "CWE-862",
      "title": "Keycloak-services: keycloak-services: client not-before revocation ignored when realm not-before is older but nonzero",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18218"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-14540",
      "cvss_base": 8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01842,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Google",
      "product": "mcp-toolbox",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery via Unrestricted HTTP Redirection in MCP Toolbox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14540"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-52857",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pterodactyl",
      "product": "wings",
      "cwe": "CWE-400",
      "title": "Wings: Maliciously or erroneously created parsed config files can cause wings process to OOM",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52857"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2026-28145",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00111,
      "epss_percentile": 0.01505,
      "kev": false,
      "kev_due_at": null,
      "vendor": "StylemixThemes",
      "product": "MasterStudy LMS",
      "cwe": "CWE-345",
      "title": "WordPress MasterStudy LMS plugin <= 3.7.39 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28145"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-34490",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00103,
      "epss_percentile": 0.01107,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Johnson Controls",
      "product": "XAAP Application",
      "cwe": "CWE-312",
      "title": "XAAP Android Data Stored in Unencrypted Database",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-34490"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-56567",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00101,
      "epss_percentile": 0.01027,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL iControl",
      "cwe": "CWE-15",
      "title": "HCL iControl is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56567"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-56569",
      "cvss_base": 3.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00101,
      "epss_percentile": 0.01039,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL iControl",
      "cwe": "CWE-497",
      "title": "HCL iControl is affected by multiple security vulnerabilities.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56569"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-54787",
      "cvss_base": 3.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0009,
      "epss_percentile": 0.00531,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sigstore",
      "product": "sigstore-go",
      "cwe": "CWE-324",
      "title": "sigstore-go fails to check signature timestamps against a signing key's validity period",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-54787"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-18321",
      "cvss_base": 4.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00084,
      "epss_percentile": 0.00308,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NTPsec",
      "product": "ntpsec",
      "cwe": "CWE-120",
      "title": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in ntpsec",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18321"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2009-3960",
      "detail": "EXPLOIT PUBLISHED — CVE-2009-3960. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-12615",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-12615 (Apache Software Foundation Apache Tomcat). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2022-47966",
      "detail": "EXPLOIT PUBLISHED — CVE-2022-47966. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-47246",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-47246. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10685",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10685 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10686",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10686 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-56968",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-56968 (GNU SASL). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66066",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66066 (rails). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67206",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67206 (wolfcms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67207",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67207 (wolfcms). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67345",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67345 (dromara MaxKey). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67347",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67347 (vendurehq vendure). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67348",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67348 (julep-ai julep). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-67349",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-67349 (opencost). Public exploit reference added."
    },
    {
      "type": "DUE_DATE_PASSED",
      "cve_id": "CVE-2026-16812",
      "detail": "DUE DATE PASSED — CVE-2026-16812 (Arista Networks VeloCloud Orchestrator On-Prem). CISA remediation deadline was July 30, 2026; still in catalog."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-27997",
      "detail": "RESCORED — CVE-2023-27997 (Fortinet FortiOS-6K7K). CVSS 9.2 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-4966",
      "detail": "RESCORED — CVE-2023-4966 (Citrix NetScaler ADC). CVSS 9.4 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2023-6507",
      "detail": "RESCORED — CVE-2023-6507 (Python Software Foundation CPython). CVSS 6.1 → 4.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-4526",
      "detail": "RESCORED — CVE-2025-4526 (Dígitro NGC Explorer). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-4527",
      "detail": "RESCORED — CVE-2025-4527 (Dígitro NGC Explorer). CVSS 6.3 → 2.9 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-4528",
      "detail": "RESCORED — CVE-2025-4528 (Dígitro NGC Explorer). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-56968",
      "detail": "RESCORED — CVE-2026-56968 (GNU SASL). CVSS 3.7 → 5.3 (NVD)."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
