{
  "day": "2026-08-03",
  "boundary": "UTC calendar day",
  "published_count": 310,
  "by_severity": {
    "CRITICAL": 47,
    "HIGH": 127,
    "MEDIUM": 118,
    "LOW": 18
  },
  "kev_count": 1,
  "exploit_reference_count": 13,
  "awaiting_enrichment_count": 0,
  "ranking": "Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.",
  "results": [
    {
      "rank": 1,
      "cve_id": "CVE-2026-18577",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.04103,
      "epss_percentile": 0.89935,
      "kev": true,
      "kev_due_at": "2026-08-06",
      "vendor": "N-able",
      "product": "N-central",
      "cwe": "CWE-288",
      "title": "Incomplete patch leads to administrative account takeover",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18577"
    },
    {
      "rank": 2,
      "cve_id": "CVE-2026-18601",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.0238,
      "epss_percentile": 0.82546,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL.iNet",
      "product": "GL-MT3000",
      "cwe": "CWE-74",
      "title": "GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.check_config command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18601"
    },
    {
      "rank": 3,
      "cve_id": "CVE-2026-18612",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.02157,
      "epss_percentile": 0.80719,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL-iNet",
      "product": "GL-MT3000",
      "cwe": "CWE-74",
      "title": "GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.install_package command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18612"
    },
    {
      "rank": 4,
      "cve_id": "CVE-2026-18684",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.02028,
      "epss_percentile": 0.79468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL.iNet",
      "product": "GL-MT3000",
      "cwe": "CWE-74",
      "title": "GL.iNet GL-MT3000 modem.so glc remove_profile command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18684"
    },
    {
      "rank": 5,
      "cve_id": "CVE-2026-18614",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.02011,
      "epss_percentile": 0.79297,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL-iNet",
      "product": "GL-MT3000",
      "cwe": "CWE-74",
      "title": "GL-iNet GL-MT3000 s2s.so Native Plugin glc s2s.enable_echo_server command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18614"
    },
    {
      "rank": 6,
      "cve_id": "CVE-2026-18602",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.01989,
      "epss_percentile": 0.79025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL.iNet",
      "product": "GL-MT3000",
      "cwe": "CWE-74",
      "title": "GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.get_recommend_config command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18602"
    },
    {
      "rank": 7,
      "cve_id": "CVE-2026-18615",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.01989,
      "epss_percentile": 0.79026,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL-iNet",
      "product": "GL-MT3000",
      "cwe": "CWE-74",
      "title": "GL-iNet GL-MT3000 wg-server.so Native Plugin glc wg-server.generate_publickey command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18615"
    },
    {
      "rank": 8,
      "cve_id": "CVE-2026-18616",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.01989,
      "epss_percentile": 0.79025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL-iNet",
      "product": "GL-MT3000",
      "cwe": "CWE-74",
      "title": "GL-iNet GL-MT3000 wg-server.so Native Plugin glc server.set_peer command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18616"
    },
    {
      "rank": 9,
      "cve_id": "CVE-2026-18685",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.01989,
      "epss_percentile": 0.79025,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL.iNet",
      "product": "GL-MT3000",
      "cwe": "CWE-74",
      "title": "GL.iNet GL-MT3000 modem.so glc set_upgrade command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18685"
    },
    {
      "rank": 10,
      "cve_id": "CVE-2026-18600",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.01977,
      "epss_percentile": 0.78898,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL.iNet",
      "product": "GL-MT3000",
      "cwe": "CWE-74",
      "title": "GL.iNet GL-MT3000 Network Lua RPC Plugin network network.switch_status command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18600"
    },
    {
      "rank": 11,
      "cve_id": "CVE-2026-67599",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01912,
      "epss_percentile": 0.78155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ClearFoundation",
      "product": "ClearOS",
      "cwe": "CWE-78",
      "title": "ClearOS 7.9 OS Command Injection via Log Viewer filter parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67599"
    },
    {
      "rank": 12,
      "cve_id": "CVE-2026-18641",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01689,
      "epss_percentile": 0.75207,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sangfor",
      "product": "Operation and Maintenance Security Management System",
      "cwe": "CWE-77",
      "title": "Sangfor Operation and Maintenance Security Management System Login Endpoint portal_login com.sbr.fort.foreignDP.DpLoginController os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18641"
    },
    {
      "rank": 13,
      "cve_id": "CVE-2026-69096",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.01673,
      "epss_percentile": 0.74945,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openwrt",
      "product": "luci",
      "cwe": "CWE-78",
      "title": "OpenWrt luci-app-dockerman Read ACL Remote Code Execution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69096"
    },
    {
      "rank": 14,
      "cve_id": "CVE-2026-18598",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.01652,
      "epss_percentile": 0.74635,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL.iNet",
      "product": "GL-MT3000",
      "cwe": "CWE-74",
      "title": "GL.iNet GL-MT3000 Logread Lua RPC plugin logread logread.get_system_log command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18598"
    },
    {
      "rank": 15,
      "cve_id": "CVE-2026-67608",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.01522,
      "epss_percentile": 0.72575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Telenia Software",
      "product": "TVox",
      "cwe": "CWE-78",
      "title": "Telenia TVox 26.5.3 OS Command Injection via action_audio.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67608"
    },
    {
      "rank": 16,
      "cve_id": "CVE-2026-52102",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0144,
      "epss_percentile": 0.71076,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as root via injecting shell metacharacters.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52102"
    },
    {
      "rank": 17,
      "cve_id": "CVE-2026-18599",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.01397,
      "epss_percentile": 0.70256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL.iNet",
      "product": "GL-MT3000",
      "cwe": "CWE-74",
      "title": "GL.iNet GL-MT3000 Logread Lua RPC Plugin logread logread.set_config command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18599"
    },
    {
      "rank": 18,
      "cve_id": "CVE-2026-18587",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.01256,
      "epss_percentile": 0.67141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wavlink",
      "product": "WL-NU516U1",
      "cwe": "CWE-77",
      "title": "Wavlink WL-NU516U1 Config Import os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18587"
    },
    {
      "rank": 19,
      "cve_id": "CVE-2026-66312",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.011,
      "epss_percentile": 0.63063,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-126",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66312"
    },
    {
      "rank": 20,
      "cve_id": "CVE-2026-66321",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01067,
      "epss_percentile": 0.62133,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-843",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66321"
    },
    {
      "rank": 21,
      "cve_id": "CVE-2026-18590",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.01067,
      "epss_percentile": 0.62115,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wavlink",
      "product": "WL-NU516U1",
      "cwe": "CWE-77",
      "title": "Wavlink WL-NU516U1 Admin Password adm.cgi set_sys_adm os command injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18590"
    },
    {
      "rank": 22,
      "cve_id": "CVE-2026-51190",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.01045,
      "epss_percentile": 0.61461,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-78",
      "title": "The \"s init\" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spawn() with shell: true. A URL ending in \".git\" bypasses the only input check, allowing OS command injection when a user runs \"s init\" with an attacker-controlled argument.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51190"
    },
    {
      "rank": 23,
      "cve_id": "CVE-2026-18574",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00991,
      "epss_percentile": 0.59784,
      "kev": false,
      "kev_due_at": null,
      "vendor": "checkpoint",
      "product": "Security Management Server",
      "cwe": "CWE-288",
      "title": "Authentication Bypass in Check Point Security Management Server",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18574"
    },
    {
      "rank": 24,
      "cve_id": "CVE-2026-65802",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00922,
      "epss_percentile": 0.57547,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-73",
      "title": "Microsoft Edge for Android Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65802"
    },
    {
      "rank": 25,
      "cve_id": "CVE-2026-69084",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00913,
      "epss_percentile": 0.57303,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-89",
      "title": "SiYuan before v3.7.3 SQL Injection via searchEmbedBlock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69084"
    },
    {
      "rank": 26,
      "cve_id": "CVE-2026-62870",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00819,
      "epss_percentile": 0.54385,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft 365 Apps for Enterprise",
      "cwe": "CWE-416",
      "title": "Microsoft Excel Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62870"
    },
    {
      "rank": 27,
      "cve_id": "CVE-2026-39932",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00773,
      "epss_percentile": 0.52892,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openemr",
      "product": "openemr",
      "cwe": "CWE-95",
      "title": "OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39932"
    },
    {
      "rank": 28,
      "cve_id": "CVE-2026-66326",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00769,
      "epss_percentile": 0.52772,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-862",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66326"
    },
    {
      "rank": 29,
      "cve_id": "CVE-2026-12872",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0069,
      "epss_percentile": 0.4998,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Webinfos",
      "cwe": "CWE-434",
      "title": "Webinfos <= 1.2 - Unauthenticated Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12872"
    },
    {
      "rank": 30,
      "cve_id": "CVE-2026-8793",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00683,
      "epss_percentile": 0.49717,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PaperCut",
      "product": "PaperCut NG/MF",
      "cwe": "CWE-307",
      "title": "PaperCut NG/MF: Insufficient brute-force protection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8793"
    },
    {
      "rank": 31,
      "cve_id": "CVE-2026-48330",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00679,
      "epss_percentile": 0.49568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-89",
      "title": "Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48330"
    },
    {
      "rank": 32,
      "cve_id": "CVE-2026-8794",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00676,
      "epss_percentile": 0.49462,
      "kev": false,
      "kev_due_at": null,
      "vendor": "PaperCut",
      "product": "PaperCut NG/MF",
      "cwe": "CWE-208",
      "title": "PaperCut NG/MF: User enumeration via timing attack",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8794"
    },
    {
      "rank": 33,
      "cve_id": "CVE-2026-41452",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00658,
      "epss_percentile": 0.48752,
      "kev": false,
      "kev_due_at": null,
      "vendor": "krayin",
      "product": "laravel-crm",
      "cwe": "CWE-306",
      "title": "Krayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41452"
    },
    {
      "rank": 34,
      "cve_id": "CVE-2026-61523",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00644,
      "epss_percentile": 0.48113,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebsiteBaker Org e.V.",
      "product": "WebsiteBaker CMS",
      "cwe": "CWE-94",
      "title": "WebsiteBaker CMS < 2.13.10 Code Injection via Droplets Editor",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61523"
    },
    {
      "rank": 35,
      "cve_id": "CVE-2026-48323",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00624,
      "epss_percentile": 0.47251,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-1336",
      "title": "Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements Used in a Template Engine (CWE-1336)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48323"
    },
    {
      "rank": 36,
      "cve_id": "CVE-2026-69095",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00619,
      "epss_percentile": 0.46995,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openwrt",
      "product": "luci",
      "cwe": "CWE-22",
      "title": "OpenWrt luci-app-bmx7 Path Traversal via bmx7-info",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69095"
    },
    {
      "rank": 37,
      "cve_id": "CVE-2026-18588",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00609,
      "epss_percentile": 0.46483,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wavlink",
      "product": "WL-NU516U1",
      "cwe": "CWE-119",
      "title": "Wavlink WL-NU516U1 nas.cgi fgets stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18588"
    },
    {
      "rank": 38,
      "cve_id": "CVE-2026-18589",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00609,
      "epss_percentile": 0.46482,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wavlink",
      "product": "WL-NU516U1",
      "cwe": "CWE-119",
      "title": "Wavlink WL-NU516U1 nas.cgi change_password stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18589"
    },
    {
      "rank": 39,
      "cve_id": "CVE-2026-66315",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00608,
      "epss_percentile": 0.46452,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-416",
      "title": "Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66315"
    },
    {
      "rank": 40,
      "cve_id": "CVE-2026-66314",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00575,
      "epss_percentile": 0.44922,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-367",
      "title": "Microsoft Edge (Chromium-based) Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66314"
    },
    {
      "rank": 41,
      "cve_id": "CVE-2026-61372",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00568,
      "epss_percentile": 0.44586,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache Jena Fuseki",
      "cwe": "CWE-22",
      "title": "Apache Jena Fuseki: Web requests using SPARQL Update can escape file restrictions",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61372"
    },
    {
      "rank": 42,
      "cve_id": "CVE-2026-61524",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00555,
      "epss_percentile": 0.4391,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WebsiteBaker Org e.V.",
      "product": "WebsiteBaker CMS",
      "cwe": "CWE-434",
      "title": "WebsiteBaker CMS < 2.13.10 File Upload RCE via Module Installation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-61524"
    },
    {
      "rank": 43,
      "cve_id": "CVE-2026-18613",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00548,
      "epss_percentile": 0.43535,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL-iNet",
      "product": "GL-MT3000",
      "cwe": "CWE-74",
      "title": "GL-iNet GL-MT3000 plugins.so Native Plugin glc plugins.set_config injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18613"
    },
    {
      "rank": 44,
      "cve_id": "CVE-2026-18646",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00539,
      "epss_percentile": 0.4307,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danpros",
      "product": "HTMLy",
      "cwe": "CWE-22",
      "title": "danpros HTMLy Author Name htmly.php path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18646"
    },
    {
      "rank": 45,
      "cve_id": "CVE-2026-33591",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00523,
      "epss_percentile": 0.42221,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tranquil IT Systems",
      "product": "WAPT Server",
      "cwe": "CWE-288",
      "title": "Authentication bypass on WaptServer",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-33591"
    },
    {
      "rank": 46,
      "cve_id": "CVE-2026-68979",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00522,
      "epss_percentile": 0.42091,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache NiFi",
      "cwe": "CWE-862",
      "title": "Apache NiFi: Missing Authorization for Components Referenced by Parameter Context Updates",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68979"
    },
    {
      "rank": 47,
      "cve_id": "CVE-2026-68981",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00517,
      "epss_percentile": 0.41831,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache NiFi",
      "cwe": "CWE-409",
      "title": "Apache NiFi: Uncontrolled Resource Consumption through Decompression of HTTP Requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68981"
    },
    {
      "rank": 48,
      "cve_id": "CVE-2026-16250",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00505,
      "epss_percentile": 0.41069,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Personal QR Message",
      "cwe": "CWE-434",
      "title": "Personal QR Message <= 1.0 - Unauthenticated Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16250"
    },
    {
      "rank": 49,
      "cve_id": "CVE-2026-20479",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00497,
      "epss_percentile": 0.40618,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-125",
      "title": "In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00741071; Issue ID: MSV-7620.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20479"
    },
    {
      "rank": 50,
      "cve_id": "CVE-2026-18582",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00496,
      "epss_percentile": 0.40574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mz-automation",
      "product": "libiec61850",
      "cwe": "CWE-590",
      "title": "mz-automation libiec61850 Report Sending Path reporting.c Reporting_RCBWriteAccessHandler free of memory not on the heap",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18582"
    },
    {
      "rank": 51,
      "cve_id": "CVE-2026-18583",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00496,
      "epss_percentile": 0.40574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "mz-automation",
      "product": "libiec61850",
      "cwe": "CWE-119",
      "title": "mz-automation libiec61850 MMS Request mms_mapping.c checkDataSetAccess out-of-bounds",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18583"
    },
    {
      "rank": 52,
      "cve_id": "CVE-2026-48326",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39929,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-89",
      "title": "Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48326"
    },
    {
      "rank": 53,
      "cve_id": "CVE-2026-48317",
      "cvss_base": 9.6,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00486,
      "epss_percentile": 0.39928,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-95",
      "title": "Adobe Campaign Classic (ACC) | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48317"
    },
    {
      "rank": 54,
      "cve_id": "CVE-2026-48331",
      "cvss_base": 10,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39109,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-918",
      "title": "Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48331"
    },
    {
      "rank": 55,
      "cve_id": "CVE-2026-48333",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00473,
      "epss_percentile": 0.39108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-863",
      "title": "Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48333"
    },
    {
      "rank": 56,
      "cve_id": "CVE-2025-15672",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0047,
      "epss_percentile": 0.38845,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ChamaWP",
      "cwe": "CWE-502",
      "title": "Chama < 1.0.13 - Unauthenticated PHP Object Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15672"
    },
    {
      "rank": 57,
      "cve_id": "CVE-2026-16060",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00469,
      "epss_percentile": 0.38805,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Insert or Embed Articulate Content into WordPress",
      "cwe": "CWE-434",
      "title": "Insert or Embed Articulate Content into WordPress <= 4.3000000027 - Editor+ Arbitrary File Upload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16060"
    },
    {
      "rank": 58,
      "cve_id": "CVE-2026-48399",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00464,
      "epss_percentile": 0.38476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Adobe",
      "product": "Adobe Campaign Classic",
      "cwe": "CWE-657",
      "title": "Adobe Campaign Classic (ACC) | Violation of Secure Design Principles (CWE-657)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48399"
    },
    {
      "rank": 59,
      "cve_id": "CVE-2026-38447",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00455,
      "epss_percentile": 0.37942,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-331",
      "title": "osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as the current timestamp and client IP address, significantly reduces entropy. An attacker can approximate the key generation time and brute-force the key space within a feasible time window.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38447"
    },
    {
      "rank": 60,
      "cve_id": "CVE-2026-18607",
      "cvss_base": 7.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00438,
      "epss_percentile": 0.36638,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wavlink",
      "product": "WN572",
      "cwe": "CWE-119",
      "title": "Wavlink NU516 lighttpd upload.cgi strcpy stack-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18607"
    },
    {
      "rank": 61,
      "cve_id": "CVE-2026-64827",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00435,
      "epss_percentile": 0.36447,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Telenia Software",
      "product": "TVox",
      "cwe": "CWE-807",
      "title": "Telenia TVox 26.5.3 Authentication Bypass via set_env.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-64827"
    },
    {
      "rank": 62,
      "cve_id": "CVE-2026-63563",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0043,
      "epss_percentile": 0.36045,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sharp Corporation",
      "product": "Sharp MFPs",
      "cwe": "CWE-1188",
      "title": "Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initial configuration. When used with the initial configuration, the address book editing and a range of features related to Document Filing can be accessed without user authentication. Products intended for the Japanese market are not affected.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63563"
    },
    {
      "rank": 63,
      "cve_id": "CVE-2026-18645",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00427,
      "epss_percentile": 0.35761,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danpros",
      "product": "HTMLy",
      "cwe": "CWE-22",
      "title": "danpros HTMLy Admin Content Endpoint admin.php add_content path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18645"
    },
    {
      "rank": 64,
      "cve_id": "CVE-2026-65804",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00414,
      "epss_percentile": 0.34681,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-94",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65804"
    },
    {
      "rank": 65,
      "cve_id": "CVE-2026-69152",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00411,
      "epss_percentile": 0.34387,
      "kev": false,
      "kev_due_at": null,
      "vendor": "juliangruber",
      "product": "brace-expansion",
      "cwe": "CWE-400",
      "title": "brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69152"
    },
    {
      "rank": 66,
      "cve_id": "CVE-2026-66311",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00405,
      "epss_percentile": 0.33933,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-862",
      "title": "Microsoft Edge (Chromium-based) Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66311"
    },
    {
      "rank": 67,
      "cve_id": "CVE-2026-21548",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unisoc (Shanghai) Technologies Co., Ltd.",
      "product": "T8100/T9100/T8200/T8300",
      "cwe": "CWE-20",
      "title": "In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21548"
    },
    {
      "rank": 68,
      "cve_id": "CVE-2026-21549",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unisoc (Shanghai) Technologies Co., Ltd.",
      "product": "T8100/T9100/T8200/T8300",
      "cwe": "CWE-20",
      "title": "In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21549"
    },
    {
      "rank": 69,
      "cve_id": "CVE-2026-21550",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unisoc (Shanghai) Technologies Co., Ltd.",
      "product": "T8100/T9100/T8200/T8300",
      "cwe": "CWE-20",
      "title": "In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21550"
    },
    {
      "rank": 70,
      "cve_id": "CVE-2026-21551",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unisoc (Shanghai) Technologies Co., Ltd.",
      "product": "T8100/T9100/T8200/T8300",
      "cwe": "CWE-20",
      "title": "In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21551"
    },
    {
      "rank": 71,
      "cve_id": "CVE-2026-21552",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33766,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unisoc (Shanghai) Technologies Co., Ltd.",
      "product": "T8100/T9100/T8200/T8300",
      "cwe": "CWE-20",
      "title": "In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21552"
    },
    {
      "rank": 72,
      "cve_id": "CVE-2026-21553",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unisoc (Shanghai) Technologies Co., Ltd.",
      "product": "T8100/T9100/T8200/T8300",
      "cwe": "CWE-20",
      "title": "In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21553"
    },
    {
      "rank": 73,
      "cve_id": "CVE-2026-21554",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33764,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unisoc (Shanghai) Technologies Co., Ltd.",
      "product": "UDX710",
      "cwe": "CWE-20",
      "title": "In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21554"
    },
    {
      "rank": 74,
      "cve_id": "CVE-2026-21555",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00403,
      "epss_percentile": 0.33765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unisoc (Shanghai) Technologies Co., Ltd.",
      "product": "UDX710",
      "cwe": "CWE-20",
      "title": "In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-21555"
    },
    {
      "rank": 75,
      "cve_id": "CVE-2026-18610",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00397,
      "epss_percentile": 0.33021,
      "kev": false,
      "kev_due_at": null,
      "vendor": "NewType",
      "product": "WebEIP",
      "cwe": "CWE-287",
      "title": "NewType WebEIP EIP_Com_FileList.aspx improper authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18610"
    },
    {
      "rank": 76,
      "cve_id": "CVE-2026-69079",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00396,
      "epss_percentile": 0.33012,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "cti-transmute",
      "cwe": "CWE-770",
      "title": "Unauthenticated Denial of Service via Unbounded Activity-Timeline Range in CTI-Transmute",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69079"
    },
    {
      "rank": 77,
      "cve_id": "CVE-2026-18667",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00392,
      "epss_percentile": 0.32559,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Tenable, Inc.",
      "product": "Sensor Proxy",
      "cwe": "CWE-94",
      "title": "Sensor Proxy Version 1.4.2 Fixes One Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18667"
    },
    {
      "rank": 78,
      "cve_id": "CVE-2026-66325",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00392,
      "epss_percentile": 0.32539,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-918",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66325"
    },
    {
      "rank": 79,
      "cve_id": "CVE-2026-18738",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00381,
      "epss_percentile": 0.31448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shlinkio",
      "product": "Shlink",
      "cwe": "CWE-1236",
      "title": "Shlink CSV Formula Injection via Visit Export CLI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18738"
    },
    {
      "rank": 80,
      "cve_id": "CVE-2026-18631",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.0038,
      "epss_percentile": 0.3129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jeequan",
      "product": "jeepay",
      "cwe": "CWE-285",
      "title": "jeequan jeepay PreAuthorize SysLogController.java WebSecurityConfig authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18631"
    },
    {
      "rank": 81,
      "cve_id": "CVE-2026-18632",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00376,
      "epss_percentile": 0.30886,
      "kev": false,
      "kev_due_at": null,
      "vendor": "langgenius",
      "product": "dify",
      "cwe": "CWE-791",
      "title": "langgenius dify Jinja2 jinja2_transformer.py jinja2.Template special elements used in a template engine",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18632"
    },
    {
      "rank": 82,
      "cve_id": "CVE-2026-69089",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00373,
      "epss_percentile": 0.3056,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-22",
      "title": "Grav CMS before 2.0.11 Path Traversal via watermark",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69089"
    },
    {
      "rank": 83,
      "cve_id": "CVE-2026-18644",
      "cvss_base": 2.1,
      "cvss_severity": "LOW",
      "epss_score": 0.00372,
      "epss_percentile": 0.30486,
      "kev": false,
      "kev_due_at": null,
      "vendor": "danpros",
      "product": "HTMLy",
      "cwe": "CWE-22",
      "title": "danpros HTMLy Delete Username Endpoint htmly.php unlink path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18644"
    },
    {
      "rank": 84,
      "cve_id": "CVE-2026-58060",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00365,
      "epss_percentile": 0.29734,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-789",
      "title": "HSS public-key level count unbounded, enabling huge allocation on verify",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58060"
    },
    {
      "rank": 85,
      "cve_id": "CVE-2026-66310",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00364,
      "epss_percentile": 0.29646,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge for Android",
      "cwe": "CWE-73",
      "title": "Microsoft Edge for Android Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66310"
    },
    {
      "rank": 86,
      "cve_id": "CVE-2026-66318",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0036,
      "epss_percentile": 0.29275,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-346",
      "title": "Microsoft Edge (Chromium-based) Information Disclosure Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66318"
    },
    {
      "rank": 87,
      "cve_id": "CVE-2026-69091",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00356,
      "epss_percentile": 0.28882,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admidio",
      "product": "admidio",
      "cwe": "CWE-306",
      "title": "Admidio before 5.0.11 Authentication Bypass via forum.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69091"
    },
    {
      "rank": 88,
      "cve_id": "CVE-2026-62416",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00356,
      "epss_percentile": 0.28803,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sharp Corporation",
      "product": "Network Scanner Tool Lite",
      "cwe": "CWE-1188",
      "title": "Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accept files unlimitedly. When the affected products are used with the initial configuration, anyone can connect to them without authentication and upload files unlimitedly. This may cause a denial-of-service (DoS) condition on the PC. Furthermore, if a malicious file is uploaded, a PC user may be tricked to execute the file to attack other entities from that PC.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62416"
    },
    {
      "rank": 89,
      "cve_id": "CVE-2026-14557",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00354,
      "epss_percentile": 0.28693,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "SoftMarket — Digital Marketplace",
      "cwe": "CWE-287",
      "title": "SoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14557"
    },
    {
      "rank": 90,
      "cve_id": "CVE-2026-18647",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00354,
      "epss_percentile": 0.28679,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jina-ai",
      "product": "reader",
      "cwe": "CWE-918",
      "title": "jina-ai reader Crawler/Puppeteer crawler.ts isValidTLD server-side request forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18647"
    },
    {
      "rank": 91,
      "cve_id": "CVE-2026-20464",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00353,
      "epss_percentile": 0.28468,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11104718; Issue ID: MSV-8297.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20464"
    },
    {
      "rank": 92,
      "cve_id": "CVE-2025-15673",
      "cvss_base": 4.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00352,
      "epss_percentile": 0.28383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Import and export users and customers",
      "cwe": "CWE-22",
      "title": "Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15673"
    },
    {
      "rank": 93,
      "cve_id": "CVE-2026-69083",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0035,
      "epss_percentile": 0.2823,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-89",
      "title": "SiYuan before v3.7.3 SQL Injection via fullTextSearchAssetContent",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69083"
    },
    {
      "rank": 94,
      "cve_id": "CVE-2026-41453",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.28188,
      "kev": false,
      "kev_due_at": null,
      "vendor": "krayin",
      "product": "laravel-crm",
      "cwe": "CWE-89",
      "title": "Krayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41453"
    },
    {
      "rank": 95,
      "cve_id": "CVE-2026-69086",
      "cvss_base": 8.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.0035,
      "epss_percentile": 0.28189,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-22",
      "title": "SiYuan before v3.7.3 Path Traversal via unvalidated avID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69086"
    },
    {
      "rank": 96,
      "cve_id": "CVE-2025-15627",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00348,
      "epss_percentile": 0.28001,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Omada Gateways",
      "cwe": "CWE-321",
      "title": "Hardcoded Cryptographic Keys in TP-Link Omada Adoption Protocol Authentication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15627"
    },
    {
      "rank": 97,
      "cve_id": "CVE-2026-69185",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00346,
      "epss_percentile": 0.27744,
      "kev": false,
      "kev_due_at": null,
      "vendor": "socketio",
      "product": "socket.io",
      "cwe": "CWE-20",
      "title": "Socket.IO: Zero-attachment Memory Exhaustion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69185"
    },
    {
      "rank": 98,
      "cve_id": "CVE-2026-48031",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00345,
      "epss_percentile": 0.27671,
      "kev": false,
      "kev_due_at": null,
      "vendor": "dhax",
      "product": "go-base",
      "cwe": "CWE-798",
      "title": "Go Restful API Boilerplate: Hardcoded JWT Secret \"random\" Allows Token Forgery",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48031"
    },
    {
      "rank": 99,
      "cve_id": "CVE-2026-59652",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00341,
      "epss_percentile": 0.27232,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-90",
      "title": "LDAP filter injection in legacy jdk1.4 LDAPStoreHelper",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59652"
    },
    {
      "rank": 100,
      "cve_id": "CVE-2026-8763",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00331,
      "epss_percentile": 0.26077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-295",
      "title": "Name Constraints bypass via trailing dot in rfc822Name and URI",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-8763"
    },
    {
      "rank": 101,
      "cve_id": "CVE-2026-58059",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-407",
      "title": "Quadratic-time escaping when stringifying X.500 distinguished names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58059"
    },
    {
      "rank": 102,
      "cve_id": "CVE-2026-67611",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00329,
      "epss_percentile": 0.25906,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openemr",
      "product": "openemr",
      "cwe": "CWE-308",
      "title": "OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67611"
    },
    {
      "rank": 103,
      "cve_id": "CVE-2026-58063",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00329,
      "epss_percentile": 0.25879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-770",
      "title": "BCFKS keystore load honours unbounded KDF cost from untrusted file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58063"
    },
    {
      "rank": 104,
      "cve_id": "CVE-2026-39931",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00327,
      "epss_percentile": 0.25652,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openemr",
      "product": "openemr",
      "cwe": "CWE-434",
      "title": "OpenEMR Authenticated SQL Injection via backup.php Import Feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-39931"
    },
    {
      "rank": 105,
      "cve_id": "CVE-2026-67610",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00326,
      "epss_percentile": 0.2555,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openemr",
      "product": "openemr",
      "cwe": "CWE-306",
      "title": "OpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR Access",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67610"
    },
    {
      "rank": 106,
      "cve_id": "CVE-2026-12965",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00324,
      "epss_percentile": 0.25346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Super Store Finder WordPress",
      "cwe": "CWE-89",
      "title": "Super Store Finder <= 7.8 - Unauthenticated SQL Injection via ssf_tracking",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12965"
    },
    {
      "rank": 107,
      "cve_id": "CVE-2026-18733",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00322,
      "epss_percentile": 0.25129,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "strands-agents-tools",
      "cwe": "CWE-1427",
      "title": "Prompt injection bypasses shell tool consent gate in Strands Agents Tools",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18733"
    },
    {
      "rank": 108,
      "cve_id": "CVE-2026-69240",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0032,
      "epss_percentile": 0.24915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "sequelize",
      "product": "sequelize",
      "cwe": "CWE-89",
      "title": "Sequelize: SQL Injection (Oracle DB)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69240"
    },
    {
      "rank": 109,
      "cve_id": "CVE-2026-68980",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00318,
      "epss_percentile": 0.24675,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache NiFi",
      "cwe": "CWE-863",
      "title": "Apache NiFi: Authorization Bypass for Parameter Context Asset Deletion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68980"
    },
    {
      "rank": 110,
      "cve_id": "CVE-2026-69153",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00313,
      "epss_percentile": 0.24101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "postcss",
      "product": "postcss",
      "cwe": "CWE-22",
      "title": "PostCSS: incomplete fix of CVE-2026-45623 — attacker-controlled sourceMappingURL reads arbitrary .map files when `from` is unset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69153"
    },
    {
      "rank": 111,
      "cve_id": "CVE-2026-68584",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00311,
      "epss_percentile": 0.2388,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-288",
      "title": "SiYuan before v3.7.3 Authentication Bypass via Content Endpoints",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68584"
    },
    {
      "rank": 112,
      "cve_id": "CVE-2026-62354",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00311,
      "epss_percentile": 0.23915,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Apache Software Foundation",
      "product": "Apache NiFi",
      "cwe": "CWE-863",
      "title": "Apache NiFi: Incorrect Authorization for Parameter Context Validation Requests",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-62354"
    },
    {
      "rank": 113,
      "cve_id": "CVE-2026-38444",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00305,
      "epss_percentile": 0.23161,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitization in include/class.mailparse.php and stored raw in the poster field of ost_thread_entry. When an unauthenticated attacker sends a reply email to an existing ticket from an unregistered address with an XSS payload in the From display name.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38444"
    },
    {
      "rank": 114,
      "cve_id": "CVE-2026-16300",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00303,
      "epss_percentile": 0.22971,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ChamaWP",
      "cwe": "CWE-862",
      "title": "Chama < 1.0.13 - Unauthenticated Arbitrary User Password Reset",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16300"
    },
    {
      "rank": 115,
      "cve_id": "CVE-2026-69078",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "cti-transmute",
      "cwe": "CWE-918",
      "title": "Server-Side Request Forgery and Local File Disclosure in CTI-Transmute Evaluation PDF Rendering",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69078"
    },
    {
      "rank": 116,
      "cve_id": "CVE-2026-67974",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00301,
      "epss_percentile": 0.22708,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-20",
      "title": "A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via sending a crafted packet.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67974"
    },
    {
      "rank": 117,
      "cve_id": "CVE-2026-69244",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.003,
      "epss_percentile": 0.22595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aio-libs",
      "product": "aiohttp",
      "cwe": "CWE-125",
      "title": "AIOHTTP: Out-of-bounds heap read in C HTTP response parser error path (malformed chunked response)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69244"
    },
    {
      "rank": 118,
      "cve_id": "CVE-2026-18585",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00299,
      "epss_percentile": 0.2256,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL.iNet",
      "product": "MT3000",
      "cwe": "CWE-119",
      "title": "GL.iNet MT2500 APPS-NAS nas-web.get_file_list heap-based overflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18585"
    },
    {
      "rank": 119,
      "cve_id": "CVE-2026-66065",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00297,
      "epss_percentile": 0.22319,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Q00",
      "product": "ouroboros",
      "cwe": "CWE-15",
      "title": "Ouroboros: Untrusted project .env can still reach RCE via omitted execution-routing keys (Incomplete fix of CVE-2026-47211)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66065"
    },
    {
      "rank": 120,
      "cve_id": "CVE-2026-13586",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00294,
      "epss_percentile": 0.21978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-770",
      "title": "PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13586"
    },
    {
      "rank": 121,
      "cve_id": "CVE-2026-69192",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00292,
      "epss_percentile": 0.21828,
      "kev": false,
      "kev_due_at": null,
      "vendor": "beaugunderson",
      "product": "ip-address",
      "cwe": "CWE-20",
      "title": "ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, allowing SSRF and trust-boundary bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69192"
    },
    {
      "rank": 122,
      "cve_id": "CVE-2026-58139",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00292,
      "epss_percentile": 0.21817,
      "kev": false,
      "kev_due_at": null,
      "vendor": "duckdb",
      "product": "duckdb-aws",
      "cwe": "CWE-863",
      "title": "DuckDB AWS Extension Security Policy Bypass via load_aws_credentials Procedure",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58139"
    },
    {
      "rank": 123,
      "cve_id": "CVE-2026-59646",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00291,
      "epss_percentile": 0.21729,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-789",
      "title": "DTLS handshake reassembler allocates buffer from unchecked 24-bit length",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59646"
    },
    {
      "rank": 124,
      "cve_id": "CVE-2026-69075",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00291,
      "epss_percentile": 0.21624,
      "kev": false,
      "kev_due_at": null,
      "vendor": "flowintel",
      "product": "flowintel",
      "cwe": "CWE-79",
      "title": "Stored Cross-Site Scripting via Vue Template Injection in FlowIntel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69075"
    },
    {
      "rank": 125,
      "cve_id": "CVE-2026-18654",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0029,
      "epss_percentile": 0.21619,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "aws-cli",
      "cwe": "CWE-322",
      "title": "Disabled SSH host key verification in Amazon AWS CLI EMR helper commands",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18654"
    },
    {
      "rank": 126,
      "cve_id": "CVE-2026-2346",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00285,
      "epss_percentile": 0.21051,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Menulux Software Inc.",
      "product": "Mobile App",
      "cwe": "CWE-639",
      "title": "IDOR in Menulux Software's Mobile App",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-2346"
    },
    {
      "rank": 127,
      "cve_id": "CVE-2026-9390",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00282,
      "epss_percentile": 0.20812,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TIMLEGGE",
      "product": "XML::Sig",
      "cwe": "CWE-643",
      "title": "XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9390"
    },
    {
      "rank": 128,
      "cve_id": "CVE-2026-16572",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00282,
      "epss_percentile": 0.20718,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "LogMyTrip",
      "cwe": "CWE-89",
      "title": "LogMyTrip <= 1.9 - Unauthenticated SQL Injection via 'tid' Cookie",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16572"
    },
    {
      "rank": 129,
      "cve_id": "CVE-2026-48061",
      "cvss_base": 5.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00282,
      "epss_percentile": 0.20802,
      "kev": false,
      "kev_due_at": null,
      "vendor": "litestar-org",
      "product": "litestar",
      "cwe": "CWE-644",
      "title": "Litestar: AllowedHostsMiddleware bypasses host validation via client-controlled X-Forwarded-Host header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48061"
    },
    {
      "rank": 130,
      "cve_id": "CVE-2026-10849",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0028,
      "epss_percentile": 0.20574,
      "kev": false,
      "kev_due_at": null,
      "vendor": "zephyrproject",
      "product": "zephyr",
      "cwe": "CWE-122",
      "title": "Heap out-of-bounds write in Zephyr hawkBit OTA client when terminating server response body",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-10849"
    },
    {
      "rank": 131,
      "cve_id": "CVE-2026-67973",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67973"
    },
    {
      "rank": 132,
      "cve_id": "CVE-2026-67976",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20393,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Denial of Service (DoS) via inputting unsafe parameters.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67976"
    },
    {
      "rank": 133,
      "cve_id": "CVE-2026-67977",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00278,
      "epss_percentile": 0.20394,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-400",
      "title": "An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) via a crafted input.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67977"
    },
    {
      "rank": 134,
      "cve_id": "CVE-2026-59638",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00276,
      "epss_percentile": 0.20135,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-297",
      "title": "JSSE hostname verifier CN-fallback enabled by default despite documented opt-in",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59638"
    },
    {
      "rank": 135,
      "cve_id": "CVE-2026-69198",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00276,
      "epss_percentile": 0.20159,
      "kev": false,
      "kev_due_at": null,
      "vendor": "beaugunderson",
      "product": "ip-address",
      "cwe": "CWE-20",
      "title": "ip-address: a CIDR suffix on the parsed address suppresses special-use classification and can bypass SSRF and trust-boundary checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69198"
    },
    {
      "rank": 136,
      "cve_id": "CVE-2026-69243",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00275,
      "epss_percentile": 0.19975,
      "kev": false,
      "kev_due_at": null,
      "vendor": "aio-libs",
      "product": "aiohttp",
      "cwe": "CWE-444",
      "title": "AIOHTTP: HTTP request smuggling via WebSocket upgrade",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69243"
    },
    {
      "rank": 137,
      "cve_id": "CVE-2026-18593",
      "cvss_base": 2.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00266,
      "epss_percentile": 0.18661,
      "kev": false,
      "kev_due_at": null,
      "vendor": "vxcontrol",
      "product": "PentAGI",
      "cwe": "CWE-264",
      "title": "vxcontrol PentAGI Tool Management Protocol pentester.tmpl sandbox",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18593"
    },
    {
      "rank": 138,
      "cve_id": "CVE-2026-59650",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00263,
      "epss_percentile": 0.18222,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-20",
      "title": "MTI/A0 DH agreement exponentiates unvalidated peer value",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59650"
    },
    {
      "rank": 139,
      "cve_id": "CVE-2026-12852",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-789",
      "title": "MLS wire decoder allocates attacker-declared opaque length before bounds check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12852"
    },
    {
      "rank": 140,
      "cve_id": "CVE-2026-13506",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-674",
      "title": "Lazy ASN.1 sequence forcing resets nesting-depth guard",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13506"
    },
    {
      "rank": 141,
      "cve_id": "CVE-2026-14682",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-789",
      "title": "Possible OOM from unbounded up-front allocation on a definite-length read",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-14682"
    },
    {
      "rank": 142,
      "cve_id": "CVE-2026-59640",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18227,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-203",
      "title": "OpenPGP CFB quick-check oracle active on symmetric/session-key paths",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59640"
    },
    {
      "rank": 143,
      "cve_id": "CVE-2026-59644",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18228,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-834",
      "title": "MLS hash-ratchet honours arbitrary 32-bit generation counter from sender",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59644"
    },
    {
      "rank": 144,
      "cve_id": "CVE-2026-59645",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18223,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-674",
      "title": "OER parser recurses without depth limit on self-referential IEEE 1609.2 schema",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59645"
    },
    {
      "rank": 145,
      "cve_id": "CVE-2026-59649",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-789",
      "title": "OpenPGP user-attribute subpacket length bounded only by JVM max memory",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59649"
    },
    {
      "rank": 146,
      "cve_id": "CVE-2026-67978",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.1824,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-20",
      "title": "An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67978"
    },
    {
      "rank": 147,
      "cve_id": "CVE-2026-12185",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00263,
      "epss_percentile": 0.18225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-789",
      "title": "BKS/UBER keystore allocates from untrusted lengths before integrity check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12185"
    },
    {
      "rank": 148,
      "cve_id": "CVE-2026-59647",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18226,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-770",
      "title": "CRMF/CMP password-MAC honours unbounded iteration count",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59647"
    },
    {
      "rank": 149,
      "cve_id": "CVE-2026-59648",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18225,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-770",
      "title": "OpenPGP Argon2 S2K honours attacker-chosen memory and passes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59648"
    },
    {
      "rank": 150,
      "cve_id": "CVE-2026-15055",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-770",
      "title": "PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15055"
    },
    {
      "rank": 151,
      "cve_id": "CVE-2026-46714",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00263,
      "epss_percentile": 0.18224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misskey-dev",
      "product": "misskey",
      "cwe": "CWE-674",
      "title": "Misskey: Denial of Service via Uncontrolled Recursion in Theme Compilation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46714"
    },
    {
      "rank": 152,
      "cve_id": "CVE-2026-16532",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00262,
      "epss_percentile": 0.18201,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Link Library",
      "cwe": "CWE-89",
      "title": "Link Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission Form",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16532"
    },
    {
      "rank": 153,
      "cve_id": "CVE-2026-51775",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0026,
      "epss_percentile": 0.17936,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the application/common/controller/Backend.php component",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-51775"
    },
    {
      "rank": 154,
      "cve_id": "CVE-2026-67972",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00259,
      "epss_percentile": 0.17767,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-200",
      "title": "An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data is stored, possibly leading to an information disclosure.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67972"
    },
    {
      "rank": 155,
      "cve_id": "CVE-2026-67616",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00253,
      "epss_percentile": 0.1706,
      "kev": false,
      "kev_due_at": null,
      "vendor": "owen2345",
      "product": "camaleon-cms",
      "cwe": "CWE-862",
      "title": "Camaleon CMS 2.9.2 Missing Authorization via /admin/post_type drafts endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67616"
    },
    {
      "rank": 156,
      "cve_id": "CVE-2026-18655",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00252,
      "epss_percentile": 0.16955,
      "kev": false,
      "kev_due_at": null,
      "vendor": "AWS",
      "product": "amazon-mq-mcp-server",
      "cwe": "CWE-923",
      "title": "Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18655"
    },
    {
      "rank": 157,
      "cve_id": "CVE-2026-69085",
      "cvss_base": 9.9,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0025,
      "epss_percentile": 0.16727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-89",
      "title": "SiYuan before v3.7.3 SQL Injection via searchDocs",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69085"
    },
    {
      "rank": 158,
      "cve_id": "CVE-2026-48115",
      "cvss_base": 6.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00249,
      "epss_percentile": 0.16533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misskey-dev",
      "product": "misskey",
      "cwe": "CWE-285",
      "title": "Misskey: Improper Authorization in the Announcements API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48115"
    },
    {
      "rank": 159,
      "cve_id": "CVE-2026-38446",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00248,
      "epss_percentile": 0.16354,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread entry title field. User-controlled input in the title is stored without adequate HTML escaping and later rendered in multiple staff-facing templates without proper output encoding. An attacker can inject arbitrary JavaScript by submitting a crafted ticket reply or email with a malicious subject line.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-38446"
    },
    {
      "rank": 160,
      "cve_id": "CVE-2026-18682",
      "cvss_base": 1.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00247,
      "epss_percentile": 0.1628,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "OpenAkita",
      "cwe": "CWE-79",
      "title": "OpenAkita File Upload API upload cross site scripting",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18682"
    },
    {
      "rank": 161,
      "cve_id": "CVE-2026-68587",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00245,
      "epss_percentile": 0.16082,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.3 Information Disclosure via getHeading*Transaction",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68587"
    },
    {
      "rank": 162,
      "cve_id": "CVE-2026-18736",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00243,
      "epss_percentile": 0.15709,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shlinkio",
      "product": "Shlink",
      "cwe": "CWE-918",
      "title": "Shlink Server-Side Request Forgery via Short URL Title Auto-Resolution",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18736"
    },
    {
      "rank": 163,
      "cve_id": "CVE-2026-68586",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00241,
      "epss_percentile": 0.15558,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.3 Content Disclosure via getBacklinkDoc",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68586"
    },
    {
      "rank": 164,
      "cve_id": "CVE-2026-18737",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00241,
      "epss_percentile": 0.15474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "shlinkio",
      "product": "Shlink",
      "cwe": "CWE-89",
      "title": "Shlink Blind SQL Injection via tags/stats orderBy Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18737"
    },
    {
      "rank": 165,
      "cve_id": "CVE-2026-69088",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00234,
      "epss_percentile": 0.14532,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav",
      "cwe": "CWE-94",
      "title": "Grav CMS 2.0.7 through 2.0.10 Arbitrary Method Invocation via Blueprint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69088"
    },
    {
      "rank": 166,
      "cve_id": "CVE-2026-66313",
      "cvss_base": 6.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00234,
      "epss_percentile": 0.14537,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-346",
      "title": "Microsoft Edge (Chromium-based) Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66313"
    },
    {
      "rank": 167,
      "cve_id": "CVE-2026-15930",
      "cvss_base": 9.4,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00233,
      "epss_percentile": 0.144,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Simple Membership",
      "cwe": "CWE-862",
      "title": "Simple Membership < 4.7.8 - Unauthenticated Administrator Account Takeover via Registration Username Collision",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15930"
    },
    {
      "rank": 168,
      "cve_id": "CVE-2026-16534",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00232,
      "epss_percentile": 0.14348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Import and export users and customers",
      "cwe": "CWE-269",
      "title": "Import and export users and customers < 2.4.2 - Custom Role Privilege Escalation to Administrator via CSV Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16534"
    },
    {
      "rank": 169,
      "cve_id": "CVE-2026-67970",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00232,
      "epss_percentile": 0.14345,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67970"
    },
    {
      "rank": 170,
      "cve_id": "CVE-2026-16057",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00232,
      "epss_percentile": 0.14396,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Contest Gallery",
      "cwe": "CWE-862",
      "title": "Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from_library",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16057"
    },
    {
      "rank": 171,
      "cve_id": "CVE-2026-60011",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00231,
      "epss_percentile": 0.14267,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sharp Corporation",
      "product": "Sharp MFPs",
      "cwe": "CWE-425",
      "title": "Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected product.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-60011"
    },
    {
      "rank": 172,
      "cve_id": "CVE-2026-52521",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0023,
      "epss_percentile": 0.14078,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-89",
      "title": "A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the CommentBat feature.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52521"
    },
    {
      "rank": 173,
      "cve_id": "CVE-2026-18584",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14106,
      "kev": false,
      "kev_due_at": null,
      "vendor": "GL.iNet",
      "product": "E5800",
      "cwe": "CWE-266",
      "title": "GL.iNet E5800/E750/X2000/X3000/XE3000/XE300 eSIM LPA API v1 improper authorization",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18584"
    },
    {
      "rank": 174,
      "cve_id": "CVE-2026-16297",
      "cvss_base": 4.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0023,
      "epss_percentile": 0.14093,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Clearfy Cache",
      "cwe": "CWE-502",
      "title": "Clearfy < 2.4.3 - Admin+ PHP Object Injection via Settings Import",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16297"
    },
    {
      "rank": 175,
      "cve_id": "CVE-2026-48113",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00228,
      "epss_percentile": 0.13884,
      "kev": false,
      "kev_due_at": null,
      "vendor": "jpillora",
      "product": "chisel",
      "cwe": "CWE-863",
      "title": "Chisel: ACL Bypass via Post-Handshake SSH Channel ExtraData Injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48113"
    },
    {
      "rank": 176,
      "cve_id": "CVE-2026-66322",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00226,
      "epss_percentile": 0.13583,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-346",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66322"
    },
    {
      "rank": 177,
      "cve_id": "CVE-2026-69092",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00225,
      "epss_percentile": 0.13383,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admidio",
      "product": "admidio",
      "cwe": "CWE-79",
      "title": "Admidio before 5.0.11 Reflected XSS via SSO/SAML Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69092"
    },
    {
      "rank": 178,
      "cve_id": "CVE-2025-15628",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00222,
      "epss_percentile": 0.13087,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Omada Gateways",
      "cwe": "CWE-798",
      "title": "Hardcoded Certificates in TP-Link Omada Device Communications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15628"
    },
    {
      "rank": 179,
      "cve_id": "CVE-2026-16539",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12959,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "sm page duplicator",
      "cwe": "CWE-89",
      "title": "SM Page Duplicator <= 1.0.0 - Editor+ SQL Injection via Page Duplication",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16539"
    },
    {
      "rank": 180,
      "cve_id": "CVE-2026-67969",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00221,
      "epss_percentile": 0.12952,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-20",
      "title": "An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.AppMon_Tbl entry.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67969"
    },
    {
      "rank": 181,
      "cve_id": "CVE-2026-18108",
      "cvss_base": 9.8,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.0022,
      "epss_percentile": 0.12816,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TIMLEGGE",
      "product": "Net::SAML2",
      "cwe": "CWE-347",
      "title": "Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18108"
    },
    {
      "rank": 182,
      "cve_id": "CVE-2026-18248",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00218,
      "epss_percentile": 0.12497,
      "kev": false,
      "kev_due_at": null,
      "vendor": "@fastify/aws-lambda",
      "product": "@fastify/aws-lambda",
      "cwe": "CWE-345",
      "title": "@fastify/aws-lambda vulnerable to Lambda event spoofing via client-controlled x-apigateway-event header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18248"
    },
    {
      "rank": 183,
      "cve_id": "CVE-2026-15231",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00218,
      "epss_percentile": 0.12527,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Tag, Category, and Taxonomy Manager",
      "cwe": "CWE-639",
      "title": "TaxoPress < 3.51.0 - Contributor+ Private Post Disclosure via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15231"
    },
    {
      "rank": 184,
      "cve_id": "CVE-2026-46712",
      "cvss_base": 2.3,
      "cvss_severity": "LOW",
      "epss_score": 0.00215,
      "epss_percentile": 0.12211,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misskey-dev",
      "product": "misskey",
      "cwe": "CWE-639",
      "title": "Misskey: Lack of proper permission checks in Direct Messaging feature",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46712"
    },
    {
      "rank": 185,
      "cve_id": "CVE-2026-69246",
      "cvss_base": 7.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.11951,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guzzle",
      "product": "guzzle",
      "cwe": "CWE-180",
      "title": "Guzzle: Noncanonical host can bypass host-based checks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69246"
    },
    {
      "rank": 186,
      "cve_id": "CVE-2026-69087",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00213,
      "epss_percentile": 0.11962,
      "kev": false,
      "kev_due_at": null,
      "vendor": "getgrav",
      "product": "grav-plugin-form",
      "cwe": "CWE-601",
      "title": "Grav Form Plugin before 9.1.13 Open Redirect via form.value() Twig",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69087"
    },
    {
      "rank": 187,
      "cve_id": "CVE-2026-68930",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00213,
      "epss_percentile": 0.11948,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Eugeny",
      "product": "russh",
      "cwe": "CWE-666",
      "title": "Russh: Channel-scoped server callbacks can be reached without an open channel",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68930"
    },
    {
      "rank": 188,
      "cve_id": "CVE-2026-69082",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11765,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misp",
      "product": "cti-transmute",
      "cwe": "CWE-352",
      "title": "Cross-Site Request Forgery in the Administrative User Deletion Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69082"
    },
    {
      "rank": 189,
      "cve_id": "CVE-2026-58061",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00212,
      "epss_percentile": 0.11819,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-354",
      "title": "CCM-family modes write plaintext to caller buffer before tag check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58061"
    },
    {
      "rank": 190,
      "cve_id": "CVE-2026-66316",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11776,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-346",
      "title": "Microsoft Edge (Chromium-based) Spoofing Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66316"
    },
    {
      "rank": 191,
      "cve_id": "CVE-2026-66317",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00212,
      "epss_percentile": 0.11777,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Microsoft",
      "product": "Microsoft Edge (Chromium-based)",
      "cwe": "CWE-346",
      "title": "Microsoft Edge (Chromium-based) Tampering Vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66317"
    },
    {
      "rank": 192,
      "cve_id": "CVE-2026-67975",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.0021,
      "epss_percentile": 0.11476,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-284",
      "title": "Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add/remove subscription commands.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67975"
    },
    {
      "rank": 193,
      "cve_id": "CVE-2026-66296",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00208,
      "epss_percentile": 0.11244,
      "kev": false,
      "kev_due_at": null,
      "vendor": "lud",
      "product": "oaskit",
      "cwe": "CWE-79",
      "title": "Reflected XSS in oaskit's default HTML error handler",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-66296"
    },
    {
      "rank": 194,
      "cve_id": "CVE-2026-18718",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00206,
      "epss_percentile": 0.10978,
      "kev": false,
      "kev_due_at": null,
      "vendor": "National Security Agency",
      "product": "Ghidra",
      "cwe": "CWE-427",
      "title": "Ghidra Swift Demangler Analyzer Arbitrary Code Execution via Project State",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18718"
    },
    {
      "rank": 195,
      "cve_id": "CVE-2026-58062",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00203,
      "epss_percentile": 0.10584,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-295",
      "title": "Stapled OCSP response accepted without binding to the checked certificate",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-58062"
    },
    {
      "rank": 196,
      "cve_id": "CVE-2026-20465",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00203,
      "epss_percentile": 0.1066,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-122",
      "title": "In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00489200; Issue ID: MSV-7834.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20465"
    },
    {
      "rank": 197,
      "cve_id": "CVE-2026-18592",
      "cvss_base": 2,
      "cvss_severity": "LOW",
      "epss_score": 0.00202,
      "epss_percentile": 0.10448,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "osCommerce",
      "cwe": "CWE-74",
      "title": "osCommerce Email Template Configuration EmailController.php EmailController sql injection",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18592"
    },
    {
      "rank": 198,
      "cve_id": "CVE-2025-15544",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10357,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Omada Gateways",
      "cwe": "CWE-759",
      "title": "Weak Credential Protection During TP-Link Omada Device Adoption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15544"
    },
    {
      "rank": 199,
      "cve_id": "CVE-2026-69090",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admidio",
      "product": "admidio",
      "cwe": "CWE-862",
      "title": "Admidio before 5.0.11 Cross-Organization Role Modification",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69090"
    },
    {
      "rank": 200,
      "cve_id": "CVE-2026-15254",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10305,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Simply Schedule Appointments",
      "cwe": "CWE-863",
      "title": "Simply Schedule Appointments < 1.6.12.11 - Contributor+ Sensitive Data Disclosure via Admin Shortcode",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15254"
    },
    {
      "rank": 201,
      "cve_id": "CVE-2026-16563",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00201,
      "epss_percentile": 0.10306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Academy LMS",
      "cwe": "CWE-284",
      "title": "Academy LMS < 3.8.3 - Subscriber+ Arbitrary Lesson Content Disclosure via lessons REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16563"
    },
    {
      "rank": 202,
      "cve_id": "CVE-2026-69151",
      "cvss_base": 7.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00199,
      "epss_percentile": 0.10048,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-79",
      "title": "Angular i18n: Cross-Site Scripting (XSS) via event-handler attributes",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69151"
    },
    {
      "rank": 203,
      "cve_id": "CVE-2025-15630",
      "cvss_base": 5.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00199,
      "epss_percentile": 0.10118,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Omada Gateways",
      "cwe": "CWE-362",
      "title": "Device Provisioning Race Condition in TP-Link Omada Adoption Workflow",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15630"
    },
    {
      "rank": 204,
      "cve_id": "CVE-2026-18092",
      "cvss_base": 8.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00196,
      "epss_percentile": 0.09663,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TIMLEGGE",
      "product": "Net::SAML2",
      "cwe": "CWE-347",
      "title": "Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity with document-wide XPath instead of the signed subtree",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18092"
    },
    {
      "rank": 205,
      "cve_id": "CVE-2026-69149",
      "cvss_base": 8.6,
      "cvss_severity": "HIGH",
      "epss_score": 0.00195,
      "epss_percentile": 0.09554,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-79",
      "title": "Angular SSR: Missing Fallback Raw-Content Serialization Escaping leads to Cross-Site Scripting (XSS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69149"
    },
    {
      "rank": 206,
      "cve_id": "CVE-2026-68585",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00194,
      "epss_percentile": 0.09508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "siyuan-note",
      "product": "siyuan",
      "cwe": "CWE-862",
      "title": "SiYuan before v3.7.3 Metadata Disclosure via getBlockInfo",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68585"
    },
    {
      "rank": 207,
      "cve_id": "CVE-2026-69249",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00192,
      "epss_percentile": 0.09239,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pyca",
      "product": "cryptography",
      "cwe": "CWE-400",
      "title": "python-cryptography: Duplicate self-signed intermediates can cause exponential path-building",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69249"
    },
    {
      "rank": 208,
      "cve_id": "CVE-2026-18568",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00191,
      "epss_percentile": 0.09079,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TIMLEGGE",
      "product": "XML::Sig",
      "cwe": "CWE-347",
      "title": "XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped before any cryptographic check",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18568"
    },
    {
      "rank": 209,
      "cve_id": "CVE-2026-69097",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00187,
      "epss_percentile": 0.08686,
      "kev": false,
      "kev_due_at": null,
      "vendor": "gitpython-developers",
      "product": "GitPython",
      "cwe": "CWE-74",
      "title": "GitPython before 3.1.53 Config Injection via Submodule Names",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69097"
    },
    {
      "rank": 210,
      "cve_id": "CVE-2026-69248",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00185,
      "epss_percentile": 0.08413,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pyca",
      "product": "cryptography",
      "cwe": "CWE-295",
      "title": "python-cryptography verifier accepts wildcard DNS names allowing escape from permittedSubtrees",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69248"
    },
    {
      "rank": 211,
      "cve_id": "CVE-2026-47746",
      "cvss_base": 8.9,
      "cvss_severity": "HIGH",
      "epss_score": 0.00182,
      "epss_percentile": 0.08143,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misskey-dev",
      "product": "misskey",
      "cwe": "CWE-367",
      "title": "Misskey: JSON-LD signature validation + compaction is vulnerable to timing attacks",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47746"
    },
    {
      "rank": 212,
      "cve_id": "CVE-2026-18243",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08141,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HP Inc",
      "product": "HP DesignJet T3500",
      "cwe": "CWE-79",
      "title": "HP DesignJet T3500 - Potential Cross-Site Scripting (XSS)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18243"
    },
    {
      "rank": 213,
      "cve_id": "CVE-2026-20482",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00182,
      "epss_percentile": 0.08053,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-770",
      "title": "In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00486814; Issue ID: MSV-6824.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20482"
    },
    {
      "rank": 214,
      "cve_id": "CVE-2025-15629",
      "cvss_base": 6.9,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Omada Gateways",
      "cwe": "CWE-331",
      "title": "Weak Session Key Generation in TP-Link Omada Adoption Protocol",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15629"
    },
    {
      "rank": 215,
      "cve_id": "CVE-2026-13340",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00181,
      "epss_percentile": 0.07991,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "SVG Support",
      "cwe": "CWE-79",
      "title": "SVG Support < 2.5.17 - Author+ Stored XSS via .svgz Sanitization Bypass",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-13340"
    },
    {
      "rank": 216,
      "cve_id": "CVE-2026-16274",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00179,
      "epss_percentile": 0.07747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Classified Listing",
      "cwe": "CWE-862",
      "title": "Classified Listing < 5.4.4 - Contributor+ Unpublished Post Content Disclosure via rtcl_block_css_get_posts",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16274"
    },
    {
      "rank": 217,
      "cve_id": "CVE-2026-16276",
      "cvss_base": 2.7,
      "cvss_severity": "LOW",
      "epss_score": 0.00179,
      "epss_percentile": 0.07747,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Classified Listing",
      "cwe": "CWE-862",
      "title": "Classified Listing < 5.4.4 - Contributor+ Store Revenue Total Disclosure via rtcl_revenue_order_search",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16276"
    },
    {
      "rank": 218,
      "cve_id": "CVE-2025-15631",
      "cvss_base": 5.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00177,
      "epss_percentile": 0.07512,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Omada Gateways",
      "cwe": "CWE-759",
      "title": "Weak Credential Storage in TP-Link Omada Devices",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-15631"
    },
    {
      "rank": 219,
      "cve_id": "CVE-2026-69247",
      "cvss_base": 8.2,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07352,
      "kev": false,
      "kev_due_at": null,
      "vendor": "pyca",
      "product": "cryptography",
      "cwe": "CWE-208",
      "title": "cryptography: PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69247"
    },
    {
      "rank": 220,
      "cve_id": "CVE-2026-18089",
      "cvss_base": 7.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00175,
      "epss_percentile": 0.07327,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TIMLEGGE",
      "product": "Net::SAML2",
      "cwe": "CWE-295",
      "title": "Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_xml when no trust anchor is configured",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18089"
    },
    {
      "rank": 221,
      "cve_id": "CVE-2026-46713",
      "cvss_base": 9.2,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00174,
      "epss_percentile": 0.072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "misskey-dev",
      "product": "misskey",
      "cwe": "CWE-347",
      "title": "Misskey: JSON-LD signature validation + compaction may lead to improper activity handling",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-46713"
    },
    {
      "rank": 222,
      "cve_id": "CVE-2026-12803",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.07155,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-354",
      "title": "KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery)",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12803"
    },
    {
      "rank": 223,
      "cve_id": "CVE-2026-12860",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-347",
      "title": "RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12860"
    },
    {
      "rank": 224,
      "cve_id": "CVE-2026-59639",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.07199,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-347",
      "title": "CMS verifySignatures returns true for SignedData with zero signers",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59639"
    },
    {
      "rank": 225,
      "cve_id": "CVE-2026-59641",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.07156,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-345",
      "title": "S/MIME validator trusts signer-asserted signingTime for path validation",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59641"
    },
    {
      "rank": 226,
      "cve_id": "CVE-2026-59643",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-347",
      "title": "OpenPGP inline-signature policy failures silently ignored",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59643"
    },
    {
      "rank": 227,
      "cve_id": "CVE-2026-59651",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00174,
      "epss_percentile": 0.072,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-326",
      "title": "BKS keystore accepts legacy version with 16-bit integrity MAC key",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59651"
    },
    {
      "rank": 228,
      "cve_id": "CVE-2026-47211",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00173,
      "epss_percentile": 0.07127,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Q00",
      "product": "ouroboros",
      "cwe": "CWE-426",
      "title": "Ouroboros: Remote Code Execution via Untrusted Project-Directory .env",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-47211"
    },
    {
      "rank": 229,
      "cve_id": "CVE-2026-12802",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00172,
      "epss_percentile": 0.06938,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-354",
      "title": "CMS AuthEnvelopedData fails to enforce tag-length on decryption",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12802"
    },
    {
      "rank": 230,
      "cve_id": "CVE-2026-28147",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0017,
      "epss_percentile": 0.06739,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unlimited Elements",
      "product": "Unlimited Elements For Elementor (Free Widgets, Addons, Templates)",
      "cwe": "CWE-862",
      "title": "WordPress Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin <= 2.0.15 - Broken Access Control vulnerability",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-28147"
    },
    {
      "rank": 231,
      "cve_id": "CVE-2026-18648",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.0017,
      "epss_percentile": 0.06782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Blix",
      "product": "Email Blue Mail Calendar App",
      "cwe": "CWE-22",
      "title": "Blix Email Blue Mail Calendar App react-native-receive-sharing-intent FileDirectory.getFileFromUri path traversal",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18648"
    },
    {
      "rank": 232,
      "cve_id": "CVE-2026-9487",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00167,
      "epss_percentile": 0.0642,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TIMLEGGE",
      "product": "XML::Sig",
      "cwe": "CWE-347",
      "title": "XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9487"
    },
    {
      "rank": 233,
      "cve_id": "CVE-2026-18651",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00167,
      "epss_percentile": 0.06407,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Directory Server 11",
      "cwe": "CWE-287",
      "title": "389-ds-base: 389-ds-base: sasl plain bind installs connection credentials before account-lock check, allowing continued access as a locked account",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18651"
    },
    {
      "rank": 234,
      "cve_id": "CVE-2026-20466",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00166,
      "epss_percentile": 0.06293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: AUTO00845351 (Note: For MT2737) / ALPS11072643 (Note: For MT6880, MT6890, MT6990); Issue ID: MSV-6929.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20466"
    },
    {
      "rank": 235,
      "cve_id": "CVE-2026-52520",
      "cvss_base": 5.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06177,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-79",
      "title": "Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/article.php). A remote authenticated attacker can inject arbitrary JavaScript code via the article content. When an administrator reviews or previews the submitted article in the backend, the malicious script executes in the admin's browser session, allowing the attacker to perform administrative actions such as creating a backdoor administrator account.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-52520"
    },
    {
      "rank": 236,
      "cve_id": "CVE-2026-49131",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Deciso B.V.",
      "product": "OPNsense",
      "cwe": "CWE-79",
      "title": "OPNsense < 26.1.9 Stored XSS via Firewall Rule Description Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49131"
    },
    {
      "rank": 237,
      "cve_id": "CVE-2026-20471",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00165,
      "epss_percentile": 0.06175,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10991588 (Note: For MT6880, MT6890, MT6990, MT6988, MT6986, MT6813) / AUTO00851171 (Note: For MT2735, MT2737); Issue ID: MSV-7790.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20471"
    },
    {
      "rank": 238,
      "cve_id": "CVE-2026-56608",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00163,
      "epss_percentile": 0.06004,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL iControl",
      "cwe": "CWE-284",
      "title": "HCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 and CVE-2026-56609).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56608"
    },
    {
      "rank": 239,
      "cve_id": "CVE-2026-67598",
      "cvss_base": 9.1,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00162,
      "epss_percentile": 0.05949,
      "kev": false,
      "kev_due_at": null,
      "vendor": "emlog",
      "product": "emlog",
      "cwe": "CWE-295",
      "title": "Emlog Pro 2.6.23 TLS Certificate Validation Disabled in ai.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67598"
    },
    {
      "rank": 240,
      "cve_id": "CVE-2026-15383",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Blog Floating Button",
      "cwe": "CWE-79",
      "title": "Blog Floating Button <= 1.4.20 - Unauthenticated Stored XSS via User-Agent Header",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15383"
    },
    {
      "rank": 241,
      "cve_id": "CVE-2026-15931",
      "cvss_base": 6.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05913,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Simple Membership",
      "cwe": "CWE-79",
      "title": "Simple Membership < 4.7.8 - Unauthenticated Stored XSS via PayPal Subscription Subscriber Name",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15931"
    },
    {
      "rank": 242,
      "cve_id": "CVE-2026-16289",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00162,
      "epss_percentile": 0.05876,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "ProfileGrid",
      "cwe": "CWE-862",
      "title": "ProfileGrid < 6.0.0.0 - Subscriber+ Group Join Request Disclosure via pm_get_all_requests_from_group",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16289"
    },
    {
      "rank": 243,
      "cve_id": "CVE-2026-67617",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00161,
      "epss_percentile": 0.0575,
      "kev": false,
      "kev_due_at": null,
      "vendor": "microweber",
      "product": "microweber",
      "cwe": "CWE-79",
      "title": "Microweber CMS 2.0.20 Stored XSS via tag_names Parameter",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67617"
    },
    {
      "rank": 244,
      "cve_id": "CVE-2026-69094",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00158,
      "epss_percentile": 0.05489,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admidio",
      "product": "admidio",
      "cwe": "CWE-639",
      "title": "Admidio before 5.0.11 IDOR via save_temporary mylist_function.php",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69094"
    },
    {
      "rank": 245,
      "cve_id": "CVE-2026-48063",
      "cvss_base": 9.3,
      "cvss_severity": "CRITICAL",
      "epss_score": 0.00157,
      "epss_percentile": 0.05359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "WhiskeySockets",
      "product": "Baileys",
      "cwe": "CWE-290",
      "title": "Baileys has message upsert / hist sync spoofing and app state corruption when using maliciously crafted protocolMessage payload",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-48063"
    },
    {
      "rank": 246,
      "cve_id": "CVE-2026-12816",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.05358,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-354",
      "title": "IESEngine stream-mode MAC forgery via length-dependent KDF split",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12816"
    },
    {
      "rank": 247,
      "cve_id": "CVE-2026-12817",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.05359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-354",
      "title": "OpenPGP AEAD decryption skips final tag on chunk-aligned data",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12817"
    },
    {
      "rank": 248,
      "cve_id": "CVE-2026-59642",
      "cvss_base": 8.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00157,
      "epss_percentile": 0.05359,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Legion of the Bouncy Castle Inc.",
      "product": "BC-JAVA",
      "cwe": "CWE-354",
      "title": "CMS AuthenticatedData content not bound to MAC when authAttrs present",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59642"
    },
    {
      "rank": 249,
      "cve_id": "CVE-2026-6695",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04849,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-805",
      "title": "Gimp: gimp: remote code execution via crafted paa file",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6695"
    },
    {
      "rank": 250,
      "cve_id": "CVE-2026-65875",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04866,
      "kev": false,
      "kev_due_at": null,
      "vendor": "baserCMS Users Community",
      "product": "BaserCMS",
      "cwe": "CWE-1236",
      "title": "BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malicious code injected by an attacker, the malicious code may be executed.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-65875"
    },
    {
      "rank": 251,
      "cve_id": "CVE-2026-67673",
      "cvss_base": 4.6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04879,
      "kev": false,
      "kev_due_at": null,
      "vendor": "n/a",
      "product": "n/a",
      "cwe": "CWE-121",
      "title": "A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is triggered when processing the edl fw_flash command, where the <filename> argument is copied to a 64-byte stack buffer via memcpy without proper length validation. An attacker with physical access to the UART3 serial interface can exploit this vulnerability by sending a maliciously crafted command with an oversized filename parameter,",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67673"
    },
    {
      "rank": 252,
      "cve_id": "CVE-2026-15260",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04903,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "GEO my WP",
      "cwe": "CWE-639",
      "title": "Geo My WP < 4.5.5.3 - Subscriber+ Arbitrary Geolocation Record Modification and Deletion via IDOR",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15260"
    },
    {
      "rank": 253,
      "cve_id": "CVE-2026-16564",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04905,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Dokan: AI Powered WooCommerce Multivendor Marketplace Solution",
      "cwe": "CWE-639",
      "title": "Dokan < 5.0.9 - Vendor+ Arbitrary Order Status Modification via orders/bulk-actions REST Endpoint",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16564"
    },
    {
      "rank": 254,
      "cve_id": "CVE-2026-16565",
      "cvss_base": 4.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00152,
      "epss_percentile": 0.04904,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Unknown",
      "product": "Dokan: AI Powered WooCommerce Multivendor Marketplace Solution",
      "cwe": "CWE-639",
      "title": "Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute REST API",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-16565"
    },
    {
      "rank": 255,
      "cve_id": "CVE-2026-63545",
      "cvss_base": 2.4,
      "cvss_severity": "LOW",
      "epss_score": 0.00152,
      "epss_percentile": 0.0486,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Sharp Corporation",
      "product": "Sharp MFPs",
      "cwe": "CWE-459",
      "title": "Sharp and Toshiba Tec MFPs (multifunction printers) caches data internally when printing, and leave them uncleared. They may be accessed later by other users.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-63545"
    },
    {
      "rank": 256,
      "cve_id": "CVE-2026-6694",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00149,
      "epss_percentile": 0.04658,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 6",
      "cwe": "CWE-120",
      "title": "Gimp: gimp file-png plugin: denial of service via oversized apng trns chunk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-6694"
    },
    {
      "rank": 257,
      "cve_id": "CVE-2026-67612",
      "cvss_base": 4.8,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00148,
      "epss_percentile": 0.04533,
      "kev": false,
      "kev_due_at": null,
      "vendor": "openemr",
      "product": "openemr",
      "cwe": "CWE-79",
      "title": "OpenEMR 8.2.0 Stored XSS via import_template.php Template Management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67612"
    },
    {
      "rank": 258,
      "cve_id": "CVE-2026-67609",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00141,
      "epss_percentile": 0.03926,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Telenia Software",
      "product": "TVox",
      "cwe": "CWE-250",
      "title": "Telenia TVox 26.5.3 Privilege Escalation via Insecure sudoers Configuration",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-67609"
    },
    {
      "rank": 259,
      "cve_id": "CVE-2026-69245",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00137,
      "epss_percentile": 0.03568,
      "kev": false,
      "kev_due_at": null,
      "vendor": "guzzle",
      "product": "guzzle",
      "cwe": "CWE-180",
      "title": "Guzzle: Noncanonical cookie domain keeps subdomain scope",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69245"
    },
    {
      "rank": 260,
      "cve_id": "CVE-2026-18508",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00136,
      "epss_percentile": 0.03474,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-59",
      "title": "Tar: tar: --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18508"
    },
    {
      "rank": 261,
      "cve_id": "CVE-2026-18642",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03365,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TUBITAK BILGEM Software Technologies Research Institute",
      "product": "eta-otp-lock",
      "cwe": "CWE-502",
      "title": "Remote Code Execution via Insecure Deserialization in TÜBİTAK BİLGEM's eta-otp-lock",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18642"
    },
    {
      "rank": 262,
      "cve_id": "CVE-2026-4793",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00134,
      "epss_percentile": 0.03348,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Synology",
      "product": "Synology Assistant",
      "cwe": "CWE-276",
      "title": "An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and conduct denial-of-service during installation.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-4793"
    },
    {
      "rank": 263,
      "cve_id": "CVE-2025-9291",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00131,
      "epss_percentile": 0.03154,
      "kev": false,
      "kev_due_at": null,
      "vendor": "TP-Link Systems Inc.",
      "product": "Omada Gateways",
      "cwe": "CWE-295",
      "title": "Improper Certificate Validation in TP-Link Omada Cloud Communications",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-9291"
    },
    {
      "rank": 264,
      "cve_id": "CVE-2026-20470",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00131,
      "epss_percentile": 0.03114,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-926",
      "title": "In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11086431; Issue ID: MSV-8189.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20470"
    },
    {
      "rank": 265,
      "cve_id": "CVE-2026-68742",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0013,
      "epss_percentile": 0.03075,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Enterprise Linux 10",
      "cwe": "CWE-125",
      "title": "Sssd: sssd: nss responder out-of-bounds read via unchecked addrlen in gethostbyaddr",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68742"
    },
    {
      "rank": 266,
      "cve_id": "CVE-2026-20483",
      "cvss_base": 7.7,
      "cvss_severity": "HIGH",
      "epss_score": 0.00126,
      "epss_percentile": 0.02688,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-862",
      "title": "In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20483"
    },
    {
      "rank": 267,
      "cve_id": "CVE-2026-20488",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-125",
      "title": "In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7757.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20488"
    },
    {
      "rank": 268,
      "cve_id": "CVE-2026-20489",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00123,
      "epss_percentile": 0.02484,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-125",
      "title": "In display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004274; Issue ID: MSV-7749.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20489"
    },
    {
      "rank": 269,
      "cve_id": "CVE-2026-20467",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02269,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-749",
      "title": "In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00837766; Issue ID: MSV-6767.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20467"
    },
    {
      "rank": 270,
      "cve_id": "CVE-2026-20473",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-416",
      "title": "In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019722; Issue ID: MSV-7759.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20473"
    },
    {
      "rank": 271,
      "cve_id": "CVE-2026-20475",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11004276; Issue ID: MSV-7748.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20475"
    },
    {
      "rank": 272,
      "cve_id": "CVE-2026-20477",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00121,
      "epss_percentile": 0.02268,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11009963; Issue ID: MSV-7658.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20477"
    },
    {
      "rank": 273,
      "cve_id": "CVE-2026-68945",
      "cvss_base": 8.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00119,
      "epss_percentile": 0.02096,
      "kev": false,
      "kev_due_at": null,
      "vendor": "angular",
      "product": "angular",
      "cwe": "CWE-345",
      "title": "Angular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State Poisoning",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-68945"
    },
    {
      "rank": 274,
      "cve_id": "CVE-2026-20484",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00117,
      "epss_percentile": 0.01972,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-201",
      "title": "In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20484"
    },
    {
      "rank": 275,
      "cve_id": "CVE-2026-18605",
      "cvss_base": 6.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00116,
      "epss_percentile": 0.01907,
      "kev": false,
      "kev_due_at": null,
      "vendor": "CheckMAL",
      "product": "AppCheck Pro",
      "cwe": "CWE-426",
      "title": "CheckMAL AppCheck Pro Kernel Mini-Filter Driver AppCheckD.sys uncontrolled search path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18605"
    },
    {
      "rank": 276,
      "cve_id": "CVE-2026-9593",
      "cvss_base": 8.4,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.01782,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Endress+Hauser",
      "product": "FDI Package library",
      "cwe": "CWE-427",
      "title": "iDTM FDI Unauthorized Debug Interface Enablement",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-9593"
    },
    {
      "rank": 277,
      "cve_id": "CVE-2026-40717",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00115,
      "epss_percentile": 0.0184,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Monitor driver",
      "cwe": "CWE-59",
      "title": "Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-40717"
    },
    {
      "rank": 278,
      "cve_id": "CVE-2026-20468",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01836,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: AUTO00833804; Issue ID: MSV-6741.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20468"
    },
    {
      "rank": 279,
      "cve_id": "CVE-2026-20469",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00115,
      "epss_percentile": 0.01837,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-123",
      "title": "In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is needed for exploitation. Patch ID: AUTO00834868; Issue ID: MSV-6533.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20469"
    },
    {
      "rank": 280,
      "cve_id": "CVE-2026-41447",
      "cvss_base": 8.5,
      "cvss_severity": "HIGH",
      "epss_score": 0.00114,
      "epss_percentile": 0.01727,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Zucchetti S.p.a.",
      "product": "FirmaCheck",
      "cwe": "CWE-426",
      "title": "FirmaCheck < 1.3.16 DLL Hijacking via Unvalidated OpenSSL Configuration Path",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-41447"
    },
    {
      "rank": 281,
      "cve_id": "CVE-2026-20486",
      "cvss_base": 6.7,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00114,
      "epss_percentile": 0.01723,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-754",
      "title": "In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11012302; Issue ID: MSV-7833.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20486"
    },
    {
      "rank": 282,
      "cve_id": "CVE-2026-20481",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.0162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965373; Issue ID: MSV-6935.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20481"
    },
    {
      "rank": 283,
      "cve_id": "CVE-2026-20497",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.0162,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10965550 / ALPS11393405; Issue ID: MSV-6941.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20497"
    },
    {
      "rank": 284,
      "cve_id": "CVE-2026-20498",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00113,
      "epss_percentile": 0.01651,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-1287",
      "title": "In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10900493; Issue ID: MSV-6765.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20498"
    },
    {
      "rank": 285,
      "cve_id": "CVE-2026-59913",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00112,
      "epss_percentile": 0.01599,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Display and Peripheral Manager (DDPM Mac)",
      "cwe": "CWE-306",
      "title": "Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59913"
    },
    {
      "rank": 286,
      "cve_id": "CVE-2026-20496",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00112,
      "epss_percentile": 0.01585,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-125",
      "title": "In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11036877; Issue ID: MSV-7132.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20496"
    },
    {
      "rank": 287,
      "cve_id": "CVE-2026-18581",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00112,
      "epss_percentile": 0.01595,
      "kev": false,
      "kev_due_at": null,
      "vendor": "ggml-org",
      "product": "llama.cpp",
      "cwe": "CWE-617",
      "title": "ggml-org llama.cpp Jinja Minja Template parser.cpp assertion",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18581"
    },
    {
      "rank": 288,
      "cve_id": "CVE-2026-18606",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.00111,
      "epss_percentile": 0.01508,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Razer",
      "product": "RzUpdateService",
      "cwe": "CWE-266",
      "title": "Razer RzUpdateService Named Pipe RzUpdateService.exe privileges management",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18606"
    },
    {
      "rank": 289,
      "cve_id": "CVE-2026-69093",
      "cvss_base": 7.1,
      "cvss_severity": "HIGH",
      "epss_score": 0.0011,
      "epss_percentile": 0.01449,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Admidio",
      "product": "admidio",
      "cwe": "CWE-352",
      "title": "Admidio before 5.0.11 CSRF via category-report preferences",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-69093"
    },
    {
      "rank": 290,
      "cve_id": "CVE-2026-20476",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0011,
      "epss_percentile": 0.01445,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981532; Issue ID: MSV-7660.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20476"
    },
    {
      "rank": 291,
      "cve_id": "CVE-2026-49132",
      "cvss_base": 5.1,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.0011,
      "epss_percentile": 0.01473,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Deciso B.V.",
      "product": "OPNsense",
      "cwe": "CWE-79",
      "title": "OPNsense < 26.1.9 Stored XSS via Certificate Description Field",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-49132"
    },
    {
      "rank": 292,
      "cve_id": "CVE-2026-20495",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00108,
      "epss_percentile": 0.01353,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-862",
      "title": "In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00488300; Issue ID: MSV-7296.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20495"
    },
    {
      "rank": 293,
      "cve_id": "CVE-2026-15430",
      "cvss_base": 6.2,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01293,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Wellbia",
      "product": "XIGNCODE3",
      "cwe": "CWE-269",
      "title": "CVE-2026-15430",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-15430"
    },
    {
      "rank": 294,
      "cve_id": "CVE-2026-20485",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01346,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In HFRP, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11049569; Issue ID: MSV-7931.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20485"
    },
    {
      "rank": 295,
      "cve_id": "CVE-2026-20472",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00107,
      "epss_percentile": 0.01306,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10991467; Issue ID: MSV-7764.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20472"
    },
    {
      "rank": 296,
      "cve_id": "CVE-2026-20478",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.01152,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981454 (Note: For MT6880, MT6890, MT6988, MT6990) / AUTO00851293 (Note: For MT2735, MT2737); Issue ID: MSV-7638.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20478"
    },
    {
      "rank": 297,
      "cve_id": "CVE-2026-20480",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.01153,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-122",
      "title": "In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960023 (Note: For MT6880, MT6890, MT6980D, MT6988, MT6990) / AUTO00851189 (Note: For MT2735, MT3737); Issue ID: MSV-7586.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20480"
    },
    {
      "rank": 298,
      "cve_id": "CVE-2026-18477",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00104,
      "epss_percentile": 0.01183,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Red Hat",
      "product": "Red Hat Hardened Images",
      "cwe": "CWE-367",
      "title": "Tar: tar: toctou in incremental dumpdir 'x' rename handling allows restore path escape",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18477"
    },
    {
      "rank": 299,
      "cve_id": "CVE-2026-18604",
      "cvss_base": 1.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00103,
      "epss_percentile": 0.01101,
      "kev": false,
      "kev_due_at": null,
      "vendor": "textPlus",
      "product": "Text Message and Call App",
      "cwe": "CWE-926",
      "title": "textPlus Text Message and Call App com.gogii.textplus DialerActivity improper export of android application components",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18604"
    },
    {
      "rank": 300,
      "cve_id": "CVE-2026-59912",
      "cvss_base": 7.8,
      "cvss_severity": "HIGH",
      "epss_score": 0.00102,
      "epss_percentile": 0.01062,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Dell",
      "product": "Display and Peripheral Manager (DDPM Mac)",
      "cwe": "CWE-284",
      "title": "Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and arbitrary code execution.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-59912"
    },
    {
      "rank": 301,
      "cve_id": "CVE-2026-20491",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.0108,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue ID: MSV-7652.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20491"
    },
    {
      "rank": 302,
      "cve_id": "CVE-2026-20494",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00102,
      "epss_percentile": 0.01077,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-125",
      "title": "In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 / BORA00155314, BORA00155001, BORA00154907; Issue ID: MSV-7570.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20494"
    },
    {
      "rank": 303,
      "cve_id": "CVE-2026-12259",
      "cvss_base": 5.3,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.01,
      "kev": false,
      "kev_due_at": null,
      "vendor": "nltk",
      "product": "nltk/nltk",
      "cwe": "CWE-494",
      "title": "Improper Input Validation in nltk/nltk",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-12259"
    },
    {
      "rank": 304,
      "cve_id": "CVE-2026-20490",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-125",
      "title": "In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10981501; Issue ID: MSV-7669.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20490"
    },
    {
      "rank": 305,
      "cve_id": "CVE-2026-20493",
      "cvss_base": 4.4,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.001,
      "epss_percentile": 0.00964,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-787",
      "title": "In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: BORA00154903; Issue ID: MSV-7575.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20493"
    },
    {
      "rank": 306,
      "cve_id": "CVE-2026-56609",
      "cvss_base": 6.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00097,
      "epss_percentile": 0.00861,
      "kev": false,
      "kev_due_at": null,
      "vendor": "HCL Software",
      "product": "HCL iControl",
      "cwe": "CWE-327",
      "title": "HCL iControl is affected by multiple security vulnerabilities(CVE-2026-56608 and CVE-2026-56609).",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-56609"
    },
    {
      "rank": 307,
      "cve_id": "CVE-2026-20474",
      "cvss_base": 6,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00093,
      "epss_percentile": 0.00672,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-367",
      "title": "In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11019183; Issue ID: MSV-7758.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20474"
    },
    {
      "rank": 308,
      "cve_id": "CVE-2026-20492",
      "cvss_base": 5.5,
      "cvss_severity": "MEDIUM",
      "epss_score": 0.00082,
      "epss_percentile": 0.00259,
      "kev": false,
      "kev_due_at": null,
      "vendor": "MediaTek, Inc.",
      "product": "MediaTek chipset",
      "cwe": "CWE-367",
      "title": "In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10960026 (Note: For MT6880, MT6890, MT6990, MT6988) / AUTO00851250 (Note: For MT2735, MT2737); Issue ID: MSV-7583.",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-20492"
    },
    {
      "rank": 309,
      "cve_id": "CVE-2026-18591",
      "cvss_base": 0.9,
      "cvss_severity": "LOW",
      "epss_score": 0.00081,
      "epss_percentile": 0.00224,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Meesho",
      "product": "Online Shopping App",
      "cwe": "CWE-310",
      "title": "Meesho Online Shopping App com.meesho.supply cleartext storage",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-18591"
    },
    {
      "rank": 310,
      "cve_id": "CVE-2026-0392",
      "cvss_base": 7.3,
      "cvss_severity": "HIGH",
      "epss_score": 0.00062,
      "epss_percentile": 0.00011,
      "kev": false,
      "kev_due_at": null,
      "vendor": "Latvijas Valsts radio un televīzijas centrs (LVRTC)",
      "product": "eParakstītājs 3.0",
      "cwe": "CWE-295",
      "title": "eParakstītājs 3.0 for Windows – remote code execution via unauthenticated auto-update",
      "url": "https://www.cve.org/CVERecord?id=CVE-2026-0392"
    }
  ],
  "transactions": [
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2015-2291",
      "detail": "EXPLOIT PUBLISHED — CVE-2015-2291. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2017-6884",
      "detail": "EXPLOIT PUBLISHED — CVE-2017-6884. Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2023-52355",
      "detail": "EXPLOIT PUBLISHED — CVE-2023-52355 (libtiff). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2024-9474",
      "detail": "EXPLOIT PUBLISHED — CVE-2024-9474 (Palo Alto Networks Cloud NGFW). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-0282",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-0282 (Ivanti Connect Secure). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-15675",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-15675 (Unknown Charitable). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2025-61884",
      "detail": "EXPLOIT PUBLISHED — CVE-2025-61884 (Oracle Corporation Oracle Configurator). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-10849",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-10849 (zephyrproject zephyr). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-12586",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-12586 (Unknown Lenxel WP). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-13389",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-13389 (Unknown webtoffee-cookie-consent). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14239",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14239 (Unknown tourmaster). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14817",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14817 (Unknown Element Pack Addons for Elementor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14841",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14841 (Unknown King Addons for Elementor). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14864",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14864 (Unknown JetEngine). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-14920",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-14920 (Unknown AcyMailing). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15151",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15151 (Unknown Five Star Restaurant Reservations). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15206",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15206 (Unknown SMS Alert). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15236",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15236 (Unknown Gallery for Google Photos). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15241",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15241 (Unknown AI ChatBot for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-15385",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-15385 (Unknown RT Mega Menu). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16042",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16042 (Unknown LWS Optimize). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16062",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16062 (Unknown Event Booking Manager for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16063",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16063 (Unknown Event Booking Manager for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16064",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16064 (Unknown Event Booking Manager for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16261",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16261 (Unknown login-social). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16273",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16273 (Unknown Narrative Publisher). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16285",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16285 (Unknown Product Attachment for WooCommerce). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16291",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16291 (Unknown ProfileGrid). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16292",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16292 (Unknown Frontend File Manager Plugin). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-16540",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-16540 (Unknown Simply Schedule Appointments). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-23760",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-23760 (SmarterTools SmarterMail). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-41940",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-41940 (WebPros cPanel). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-66296",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-66296 (lud oaskit). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69152",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69152 (juliangruber brace-expansion). Public exploit reference added."
    },
    {
      "type": "EXPLOIT_PUBLISHED",
      "cve_id": "CVE-2026-69153",
      "detail": "EXPLOIT PUBLISHED — CVE-2026-69153 (postcss). Public exploit reference added."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2024-21539",
      "detail": "RESCORED — CVE-2024-21539 (@eslint/plugin-kit). CVSS 8.7 → 7.7 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2025-14087",
      "detail": "RESCORED — CVE-2025-14087 (GNOME glib). CVSS 5.6 → 9.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-12188",
      "detail": "RESCORED — CVE-2026-12188 (Grit42 Grit). CVSS 5.3 → 2.1 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-44173",
      "detail": "RESCORED — CVE-2026-44173 (MariaDB server). CVSS 5 → 5.3 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-44248",
      "detail": "RESCORED — CVE-2026-44248 (netty). CVSS 5.3 → 7.5 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-48163",
      "detail": "RESCORED — CVE-2026-48163 (MariaDB server). CVSS 8 → 7.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-48165",
      "detail": "RESCORED — CVE-2026-48165 (MariaDB server). CVSS 8 → 7.2 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-53143",
      "detail": "RESCORED — CVE-2026-53143 (Linux). CVSS 7 → 7.8 (NVD)."
    },
    {
      "type": "RESCORED",
      "cve_id": "CVE-2026-6734",
      "detail": "RESCORED — CVE-2026-6734 (undici). CVSS 7.5 → 8.8 (NVD)."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2024-0012",
      "detail": "PATCH SHIPPED — CVE-2024-0012 (Palo Alto Networks Cloud NGFW). Fixed in Cloud NGFW All."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2024-1708",
      "detail": "PATCH SHIPPED — CVE-2024-1708 (ConnectWise ScreenConnect). Fixed in ScreenConnect 23.9.8."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2024-36971",
      "detail": "PATCH SHIPPED — CVE-2024-36971 (Linux). Fixed in Linux 4.19.316."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2024-9474",
      "detail": "PATCH SHIPPED — CVE-2024-9474 (Palo Alto Networks Cloud NGFW). Fixed in Cloud NGFW All."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2025-0282",
      "detail": "PATCH SHIPPED — CVE-2025-0282 (Ivanti Connect Secure). Fixed in Connect Secure 22.7R2.5."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2025-22457",
      "detail": "PATCH SHIPPED — CVE-2025-22457 (Ivanti Connect Secure). Fixed in Connect Secure 22.7R2.6."
    },
    {
      "type": "PATCH_SHIPPED",
      "cve_id": "CVE-2026-41940",
      "detail": "PATCH SHIPPED — CVE-2026-41940 (WebPros cPanel). Fixed in WP Squared 11.136.1.7."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2025-38299",
      "detail": "ENRICHED — CVE-2025-38299 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-45897",
      "detail": "ENRICHED — CVE-2026-45897 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-45901",
      "detail": "ENRICHED — CVE-2026-45901 (Linux). Received CVSS 5.5 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-46130",
      "detail": "ENRICHED — CVE-2026-46130 (Linux). Received CVSS 7.1 and CPE data from NVD."
    },
    {
      "type": "ENRICHED",
      "cve_id": "CVE-2026-53364",
      "detail": "ENRICHED — CVE-2026-53364 (Linux). Received CVSS 5.5 and CPE data from NVD."
    }
  ],
  "attribution": "CVE Program, NVD (NIST), CISA KEV, FIRST EPSS, OSV. See /security/methodology/."
}
